Forum Moderators: DixonJones

Message Too Old, No Replies

pwd, etc. files sniffing on a new non-promoted site

how this could happen?

         

Moby_Dim

12:47 pm on Sep 28, 2006 (gmt 0)

10+ Year Member



A website created recently, less than for 2 months have been used for cgi scripts testing purposes only. *nix server, no DNS flaws, no dedic.IP for the site. Nobody except a client and the hoster provider knows about the site existence. Nobody except those was emailed from the site too. robots.txt - full denial from all spiders. No links from the index page too. No inbound links to the site too, of course ;))) There are only a few Perl scripts being tesed in /cgi-bin/ folder. Logs - nobody have ever been visiting the site except the site owner and the client mentioned above. google and whois bots too (robots.txt), of course.

And suddenly - an attack of a spider - a trial to sniff nonexisting here but very common and usual on any alive real website folders paths and files (e.g. /config/, /conf/, /private/, /privat/, /upload/, password.txt, users.txt, etc.... more than 200 such different requests total in a few seconds). Spider's IP reveals a webhosting provider site from a "3-rd country". No before in logs too, of course.

A question - being in my, the site owner's shoes, how high would you estimate the probability (in approx. %%) that the spider was blessed by the client mentioned above? Any other ways to direct my minds/suspicions? Do not want to think badly about G. and whois teams guys silly jokes;)) LOL

Ethics and credibility issues you know...

daveVk

1:45 am on Sep 29, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Probably just tries random ip addresses, is you domain name included in requists?

Moby_Dim

5:25 am on Sep 29, 2006 (gmt 0)

10+ Year Member



The site does not have own IP as I've mentioned.