Tycoon Talk
Become a Big fish!
The number 1 forum for online business!
Post topics, ask questions, share your knowledge.
Tycoon Talk is part of Freelancer.com - find skilled workers online at a fraction of the cost.

Website and Server Administration Forum


You are currently viewing our Website and Server Administration Forum as a guest. Please register to participate.
Login



Reply
Scanner Bots on Server?
Old 04-22-2009, 05:27 PM Scanner Bots on Server?
Junior Talker

Posts: 2
Location: Midwest
Trades: 0
Could someone please me what the heck these are that I found in my logs?

2009-04-17 16:20:14 xxx.xxx.x.xxx GET /program/js/list.js - 80 - 87.239.14.10 Toata+dragostea+mea+pentru+diavola 401 2 5 1453
2009-04-17 16:20:14 xxx.xxx.x.xxx GET /rc/program/js/list.js - 80 - 87.239.14.10 Toata+dragostea+mea+pentru+diavola 401 2 5 341
2009-04-17 16:20:14 xxx.xxx.x.xxx GET /roundcube/program/js/list.js - 80 - 87.239.14.10 Toata+dragostea+mea+pentru+diavola 401 2 5 373


Thanks in advance
dasmin5 is offline
Reply With Quote
View Public Profile Visit dasmin5's homepage!
 
 
Register now for full access!
Old 04-22-2009, 07:30 PM Re: Scanner Bots on Server?
tripy's Avatar
Do not try this at home!

Posts: 3,621
Name: Thierry
Location: I'm the uber Spaminator !
Trades: 0
Blind tentatives to find an file that is subject to xss, probably.
I have them all the time on my server, don't give them too much attentions.
But check that your applications are up to date all the time.
An exploit is quickly put to an use, if you don't follow the updates.
__________________
Only a biker knows why a dog sticks his head out the window.
tripy is offline
Reply With Quote
View Public Profile Visit tripy's homepage!
 
Old 04-22-2009, 10:42 PM Re: Scanner Bots on Server?
Junior Talker

Posts: 2
Location: Midwest
Trades: 0
Hello Tripy,

I just put it in my block list in IIS 7. Anytime I see something in my IIS 7 Reports under browsers category. I have seen some things like:Toata dragosstea mea pentru diavola, Python urllib, Morfeus F****** Scanner, these IP's I blocked. Then I see the normals in the list like: Firefox, MSIE, Safari; these I don't block. And plus I read my logs everyday and if it looks suspious; they get blocked. I think these are safe too; Googlebot, uberbot, Twingly Recon, AideRSS, Twitturly, and LongURL API? I have a web server I am running from home; so I try to keep my website as safe as possible. I know nothing is fool proof.

Thanks,
DOC
dasmin5 is offline
Reply With Quote
View Public Profile Visit dasmin5's homepage!
 
Reply     « Reply to Scanner Bots on Server?
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off





   
RSS Feed  Feeds: RSS   JS   XML
RSS Feed  Feeds for this forum: RSS   JS   XML



Page generated in 0.12300 seconds with 12 queries