Textpattern CMS support forum
You are not logged in. Register | Login | Help
- Topics: Active | Unanswered
is this an attack or something
in my visitor logs:
/ lists/admin/index.php?_SERVER[ConfigFile]=../../../. ./../../../../../../../../../../../../../../../../../../../etc/passwd
its a bad hen that wont scratch itself.
photogallery
Offline
Re: is this an attack or something
Yeah. It’s probably not targeted directly at you – just a bot or script kiddie. Does it actually work on your site? Most likely it doesn’t, but add this to your httpd.conf if you have access to it, otherwise to your .htaccess to serve a 403 for requests with ..
in them:
<IfModule mod_alias.c>
RedirectMatch 403 \.\.
</IfModule>
Last edited by jm (2009-10-18 16:59:12)
Offline
Offline