PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
rugbyleaguer
Hangin' Around


Joined: Dec 17, 2007
Posts: 29

PostPosted: Thu Jan 24, 2008 3:32 pm Reply with quote Back to top

Get a few of these on site and wondered what they were trying to do to the site???


Date & Time: 2008-01-24 18:09:58 UTC GMT +0000
Blocked IP: 80.67.27.*
User ID: Anonymous (1)
Reason: Abuse-Filter
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727)
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

Get String:
Only registered users can see links on this board!
Get registered or login to the forums!

Post String:
Only registered users can see links on this board!
Get registered or login to the forums!

Forwarded For: none
Client IP: none
Remote Address: 80.67.27.39
Remote Port: 32913
Request Method: GET
--------------------
Who-Is for IP
View user's profile Send private message
warren-the-ape
Worker
Worker


Joined: Nov 19, 2007
Posts: 196
Location: Netherlands

PostPosted: Thu Jan 24, 2008 4:08 pm Reply with quote Back to top

See:
Only registered users can see links on this board!
Get registered or login to the forums!


Especially the reply from Montego;
(I had the same questions as well Wink)

montego wrote:

They are absolutely NOT "innocent". Anything which attacks phpbb_root_path is far from innocent and I will not go into the explanation of why. phpBB has since plugged this particular hole (yes, RN has that "plug"), so these are old exploits. Just remember too that just because a file has .txt as an extension does not mean that is truly what the nature of the file is. It could even be PHP script or a binary etc. To answer your question, it is very possible that those sites were hacked and now being used to try and attack others.
View user's profile Send private message
rugbyleaguer
Hangin' Around


Joined: Dec 17, 2007
Posts: 29

PostPosted: Thu Jan 24, 2008 4:13 pm Reply with quote Back to top

So where exactly are they inputting these scripts????
View user's profile Send private message
warren-the-ape
Worker
Worker


Joined: Nov 19, 2007
Posts: 196
Location: Netherlands

PostPosted: Thu Jan 24, 2008 4:17 pm Reply with quote Back to top

They are trying to run those queries on your site, like you can see in the strings from your topicstart.

I guess that most of them are automated and are just being send to your website from another server, but please read the other topic cause a lot of it is explained over there Wink
View user's profile Send private message
Gremmie
Former Moderator in Good Standing


Joined: Apr 06, 2006
Posts: 2415
Location: Iowa, USA

PostPosted: Thu Jan 24, 2008 7:39 pm Reply with quote Back to top

This is called a cross site scripting attack. They are trying to trick your PHP code to run a (bad) script on a remote server.
View user's profile Send private message
rugbyleaguer
Hangin' Around


Joined: Dec 17, 2007
Posts: 29

PostPosted: Fri Jan 25, 2008 12:46 pm Reply with quote Back to top

Where is it likely they are inputting these scripts, that is to say I had one hacker from Turkey once chat to me and tell me how he had hacked my site by typing some script into the search topic input field then he manage to retrieve the username and the hash (MD5) of my password which he pasted into a MD5 hash cracking website waited a few days then it told him my admin password. If I know where they are inputting the stuff I can remove it so that they can only do that when they are a registered/verified member.
View user's profile Send private message
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Fri Jan 25, 2008 2:45 pm Reply with quote Back to top

Search module is a previous known exploit. RavenNuke should have it patched already.
If they are still hacking your site and succeeding, please let us know
View user's profile Send private message Visit poster's website
rugbyleaguer
Hangin' Around


Joined: Dec 17, 2007
Posts: 29

PostPosted: Sat Jan 26, 2008 3:30 am Reply with quote Back to top

Well thank god it seems to be blocking em each time but is a tad worrying to think its getting attacked on a regular basis.
View user's profile Send private message
slackervaara
Worker
Worker


Joined: Aug 26, 2007
Posts: 234

PostPosted: Sat Jan 26, 2008 4:25 am Reply with quote Back to top

rugbyleaguer wrote:
Where is it likely they are inputting these scripts, that is to say I had one hacker from Turkey once chat to me and tell me how he had hacked my site by typing some script into the search topic input field then he manage to retrieve the username and the hash (MD5) of my password which he pasted into a MD5 hash cracking website waited a few days then it told him my admin password. If I know where they are inputting the stuff I can remove it so that they can only do that when they are a registered/verified member.


On my site I have added in .htaccess, so only my ip-address can access admin.php. They have no use then of the admin password.

<Files "admin.php">
Order allow,deny
Allow from xxx.xx.x.xx
</Files>

xxx.xx.x.xx is my ip-address
View user's profile Send private message
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum