Forum Moderators: coopster & phranque

Message Too Old, No Replies

strange scripts

in my error logs

         

stef25

11:34 am on Jul 27, 2004 (gmt 0)

10+ Year Member



in my error logs im noticing over the past couple of days that various IP's are trying to hit scripts that were never on my servers. the scripts they try to find have generic names such as mailform.cgi, formmail.pl, contact.cgi, uniform.pl, eforms.pl.

one of the servers has recently been under ddos attack

some of the IP's are 200.49.21x.xx and 81.223.xx.**** which seem to come out of austria and argentina, but some traceroutes i run come up with "does not exist" type results

spammers, hackers, mydoom?

a google for those scripts comes up with some obscure references to those files ...

[edited by: Brett_Tabke at 12:58 pm (utc) on July 27, 2004]

Brett_Tabke

12:59 pm on Jul 27, 2004 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



They are compromised machines running scripts looking for security faults.

kaled

9:12 pm on Jul 28, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



You're not alone - I see the same thing in my error logs. If the scripts don't exist on your server, there's nothing to worry about.

Kaled.

stef25

2:39 pm on Jul 30, 2004 (gmt 0)

10+ Year Member



thanks for this info

i now notice error entries in my logs for scripts that ARE hosted on my site. its tellafriend.cgi which isnt a generic name that was being targetted before (eform.pl, formmail.pl)

log says "script not found or unable to stat" (stat no typo)

are my scripts being disabled? at a first try, i could not get it to work ...

chubba

7:14 pm on Aug 4, 2004 (gmt 0)

10+ Year Member



Hiya,

Spammers auto search for formmail.cgi as if found it is thought to be easily compromised. If you see that it is not found in error logs then you are all OK - the spammers have moved on.

One common from to mail is 'Matt's Form to Mail', early versions of which were highly hackable by all accounts, when looking for a form to mail find one that is secure.

If you see from your main usage logs that it is getting a lot more traffic than usual then it becomes something you would need to investigate.

Like I saif though if it is there in the error log you can rest easy as the resource was not found.

OK - errors for files that are on your site is more worrying but not due to hackers I would have thought. If you got an error there and the logs show other errors then there is something screwy with the scripts.

You said 'at first try i could not get it to work', does this mean it worked later? If it is intermittent I would monitor it and let your host know when it stops working next. See if they can track down what the problem is, especially if it is a script that is provided by them. They may have access to more detialed error logs to help them find out what triggered these errors too.

Chubba