Forum Moderators: phranque

Message Too Old, No Replies

Apache logs Vars.txt

         

kenerly

5:36 am on Mar 9, 2005 (gmt 0)

10+ Year Member



In my apache error log I just started getting the following.

[Tue Mar 08 16:49:46 2005] [error] [client 192.168.1.1] File does not exist: C:/WEB/CGO/forum/vars.txt
[Tue Mar 08 21:29:51 2005] [error] [client 68.***.183.170] File does not exist: C:/WEB/CGO/forum/vars.txt

Funny thing is 192.168.1.1 is my routers internal ip.

Any idea why this has started?

[edited by: jdMorgan at 5:41 am (utc) on Mar. 9, 2005]
[edit reason] Obscured specifics per TOS. [/edit]

jdMorgan

5:41 am on Mar 9, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



kenerly,

Welcome to WebmasterWorld!

This could mean that you're being hacked. If you're not using a *firewall* router, you might consider doing so.

Jim

kenerly

6:21 am on Mar 9, 2005 (gmt 0)

10+ Year Member



I'm using kerio firewall. Any way to block it?

And what are they trying to do or have they already done it?

kenerly

6:23 am on Mar 9, 2005 (gmt 0)

10+ Year Member



btw I searched the computer for a vars.txt and there is not such a file on this server.

I also looked up the 68.***.183.170 ip. Its the ip for the person who is forum moderator and a very close friend. So its not a hack attempt. Could something on the server be calling for this file. PHP, perl etc.?

mack

6:29 am on Mar 9, 2005 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



it may bee someone or a bot perhaps searching for known exploits. If they are found then it is possible they will come back to have a closer look.

It's almost like script exploiters who use search engines to find known weaknesses such as remining install files or open admin areas.

In the same way some people hit random sites with a bot to look for open doors into the server.

If they are in your error log then this is probably a good thing because the files where not found.

Mack.

jdMorgan

4:22 pm on Mar 9, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



> 68.***.183.170 ip. Its the ip for the person who is forum moderator and a very close friend.

Ask that person about this. Then, have them run AdAware and Spybot, etc. on their computer(s) to make sure they haven't been zombied by a hack script.

Really, I can only guess at what the cause of this might be, or its purpose. But as Mack says, there are a lot of forum exploit attempts going on these days.

Jim

kenerly

6:06 pm on Mar 9, 2005 (gmt 0)

10+ Year Member



Found the problem. I have a arcade on the forum. When the game Karts was played it would call for vars.txt hince the error. So i just removed that game from the arcade.