Forum Moderators: DixonJones

Message Too Old, No Replies

security issues

weired pages requested in the logfiles

         

Oliver Henniges

9:21 am on Aug 2, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I am currently taking a closer look at my logfiles analysing their code with some self written php-scripts, in order to deepen my understanding of what is going on at my website.

As a matter of fact, I found quite a lot of attempts to hack my website, for instance many, many requests to get access to php-myadmin-files, all answered with a 404-return, because these don't exist.

But I also found some requests on some obscure php-files, answered with a 200-return code. These files never existed, but if a hacker temporarily had access to my site, he might have deleted them. Should I worry and perhaps take a closer look at my ftp-logs?

I have temporarily deleted the results in my database so I cannot provide any examples today. Maybe next week if necessary.

Oliver Henniges

9:53 pm on Aug 2, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Huh? Is this the wrong forum?

I really doubt I am the only one with hints on hacker attacks in his logfiles?

pavlovapete

12:07 am on Aug 3, 2007 (gmt 0)

10+ Year Member



Hi Oliver_Henniges,

I have the same "problem" - I'm often firing up my ftp application to make sure there aren't weird php files on the server :)

I've been focussing on logs over the past few months and I'm amazed at the waste - they probe for things that aren't even on my site - makes me think it is largely automated.

The 200 is a worry - I get them as well and cannot explain.

So not much help to you I'm afraid.

Cheers

Oliver Henniges

10:57 am on Aug 3, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



thx for your comment.

Actually I also found a few sort of "corrupted" lines in my logfiles, namely almost empty entries with a wrong number of quotes and hyphens. I'd suspect if my website has really been hacked, a careful hacker would also use a script to rewrite logfiles and delete the lines which may indicate his activities. We all make mistakes, so it is quite likely some lines were simply forgotten and the corrupted lines might result from my webserver trying to rewrite the file at the same time.

jnadams

7:08 am on Aug 8, 2007 (gmt 0)

10+ Year Member



I am finding the same thing. I am also finding downloaded code from www.w3.org in my temp int. folder. I do not use that site. Lost control of GP snap in, etc.

Forgive me folks.....i hate to say it.....but it seems like MACtime.