rejetto forum

Hack attemps...Maybe?

r][m · 6 · 2619

0 Members and 1 Guest are viewing this topic.

Offline r][m

  • Tireless poster
  • ****
    • Posts: 347
    • View Profile
I've been seeing a lot of php and js scripts from various IP's in my log lately.
Don't know if it's really someone's lame hack attempt or someone who's just lost
their server.
My question was just answered when I tried to post here as "code" part of my log.
Definitely. ;)
Of course HFS refuses these with a 404 Not found.
I have added to Events
Code: [Select]
[+request]
{.if|{.match|*.php*;*.js*|%url%.} |{: {.disconnect.}:}.}
And
[disconnected]
{.if|{.match|*.php*;*.js*|%url%.} |{:{.add to log|%ip% Disconnected .}:}.}
I am a bit puzzled as to how their doing this with out my log showing a
User Agent?

Now to sit back and watch (and learn) ;D
« Last Edit: February 07, 2010, 09:29:34 PM by r][m »


Offline rejetto

  • Administrator
  • Tireless poster
  • *****
    • Posts: 13510
    • View Profile

Offline Mars

  • Operator
  • Tireless poster
  • *****
    • Posts: 2059
    • View Profile
note the full path of their request and create it as virtual in the vfs, then the link return a web page which contain the attached image..
 ;D
« Last Edit: February 08, 2010, 07:35:49 PM by Mars »


Offline uvbeenzaned

  • Occasional poster
  • *
    • Posts: 38
    • View Profile
Hackers would not want to hack anything small like an hfs server.  It's the truth.  They dream of hacking huge apache servers with mysql databases and all those goodies.
Antec 900 Gaming Case, Nvidia XFX 780i 3 Way SLI Motherboard, 6 GB RAM, EVGA-Nvidia GeForce 9800 GTX + and Nvidia GeForce 8600 GT using 2 Way SLI, Pentium Dual Core Processor, Core Speed=2.6 MHz, 3 Monitors, 1150 GBs of hd storage, Win7=YEAH!


Offline r][m

  • Tireless poster
  • ****
    • Posts: 347
    • View Profile
Mars
Thanks, I like it  ;D

uvbeenzaned
While these guys may not have their doctorate degree in hacking,
they gave it a pretty good try. My log had about ever php call for admin, mysql and config
commonly used, as well as zen-cart, ecommerce, etc in js. Actually, I kinda learned some from
this.
I'll bet they're awful frustrated.  ;)




Offline uvbeenzaned

  • Occasional poster
  • *
    • Posts: 38
    • View Profile
I guess I didn't realize all the stuff you really had in your log. ;D :)
Antec 900 Gaming Case, Nvidia XFX 780i 3 Way SLI Motherboard, 6 GB RAM, EVGA-Nvidia GeForce 9800 GTX + and Nvidia GeForce 8600 GT using 2 Way SLI, Pentium Dual Core Processor, Core Speed=2.6 MHz, 3 Monitors, 1150 GBs of hd storage, Win7=YEAH!