rejetto forum

Software => HFS ~ HTTP File Server => Topic started by: Damian on July 05, 2008, 10:26:06 PM

Title: hack attempt?
Post by: Damian on July 05, 2008, 10:26:06 PM
Good evening all

I have a little question about a command I found in my logging;
unknown ip /GET //?mosConfig_absolute_path=(my ip here)/1.gif
(something like this)
There is nothing else in the template....so I am a little confused what this is.
MY pc seems clean also..and I use user account o the whole server now.
Any ideas what this command tries to do?

thank you in advance

Damian
Title: Re: hack attempt?
Post by: Rarst on July 05, 2008, 11:05:56 PM
It indeed looks like hack attempt (imho not targeted, just carpet bombing) by trying to exploit vulnerability that according to quick googling is specific to CMS like Mambo and Joomla.

HFS is most certainly not vulnerable to that. :)
Title: Re: hack attempt?
Post by: Damian on July 05, 2008, 11:19:30 PM
Good evening

Thank you for the reply.
I couldn't find more about it too.
Nothing happened aftherwards gladly. Well no more open zones on the server for now.
Safely behind useraccounts.

Damian