Forum Moderators: phranque

Message Too Old, No Replies

Is this an attempted hack?

GET /~!^~!^~!.html

         

Wizcrafts

10:14 pm on Aug 26, 2004 (gmt 0)

10+ Year Member



I found this strange request in my logs last night:
61.***.131.173 - - [26/Aug/2004:03:41:07 -0400] "GET /~!^~!^~!.html HTTP/1.1" 404 657 "-" "google"

Dose anybody know if this is a hack attempt, or known exploit? The website is on a RAQ4 server, running Linux and Apache.

The IP is based in China and the User_Agent is forged. The log shows a 404, but when I typed this filename into my addressbar, after my domain, I got a "Server File Not Found" page, from the RAQ server, not my own custom 404. This tells me that the codes are somehow aimed at fooling the server into doing or allowing something unfriendly. Am I correct in this assumption?

TIA, Wiz

[edited by: jdMorgan at 10:23 pm (utc) on Aug. 26, 2004]
[edit reason] Obscured IP address [/edit]

jdMorgan

10:24 pm on Aug 26, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Wiz,

I got the exact same request from the exact same IP address. On a straight-up Apache server, it was blocked by a check for forged googlebot UAs:


61.***.131.173 - - [26/Aug/2004:12:33:37 -0400] "GET /~!^~!^~!.html HTTP/1.1" 403 683 "-" "google"

So something in the RAQ setup may be interfering with your checks.

Jim

encyclo

12:17 am on Aug 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Wizcrafts, have you applied all the patches to your system available on the sun.com website? There are quite a few known security vulnerabilities with the old Cobalt line of servers - but if you're patched you should be quite safe (Sun is still supporting the Cobalt line of servers until 2007 I believe, even if it is discontinued).

I don't know if this is a known exploit, and you can't search google for "~" or "/" anyway, so it's difficult to tell. If jdMorgan has seen it too, that would indicate that it is a random attempt rather than a specific attack on your system. Still, better to be patched and secured properly.

RonPK

5:07 pm on Aug 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I've also got such a hit in my server log. However I do get my custom 404 page when I request the page in my browser. The server is a RaQ4, fully patched.

Staffa

9:49 pm on Aug 27, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I had the same request from the same IP. It got a 404 but time to ban this IP for it will come back for more.
The 'google' UA also comes from 61.****.131.163 and 61.****.131.174