Forum Moderators: DixonJones
Here are some samples from my Access_log.
Some were repeated 3 to 10 times.
GET /awstats/awstats.pl?configdir=¦echo%20;echo%20;id;
echo%20;echo¦ 562
PUT /tosh.txt 405 300 Microsoft Data Access
Internet Publishing Provider
WGET /_vti_bin/_vti_aut/author.exe 403 301 MSFrontPage/4.0
PUT /default.htm - Microsoft Data Access...
/awstats/awstats.pl?configdir=¦echo%20;echo%20__comeco__;
ls%20/var/www/;echo%20__fim__;echo%20¦ 592 -
All had identical Brazilian DNS #s.
Does anyone know what this is all about?
Have others seen same/similar entries? - Larry
I did a G search for some salient words from the first entry (see above).
There was a lot about AWSTATS (which I don't know anything about)
I use Weblog Expert (lite freebie version) to analyze my logs offline. Nothing server side.
I don't know if my host ISP has AWstats or not.
Given the entries I copied above, does it look like their attempts were all failures?
Many but not all of these also showed up in my Error_log file.
May I presume that somebody was trying to use my site to launch a DOS attack on
somebody else, by co-opting my site?
Thanks much for the info. -Larry
No reason to freak out though: these guys know NOTHING special about you. Those attacks are fired off to whole ranges of IP addresses to get the few back which are actually vulnerable. They are not after you personally :-)