Forum Moderators: open

Message Too Old, No Replies

core-project/1.0

Seems to be looking for FrontPage vulnerabilities

         

GaryK

1:37 pm on Oct 9, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



core-project/1.0
209.112.56.***

10/02/2005 17:30:35 /_vti_bin/_vti_aut/author.dll core-project/1.0
10/08/2005 21:08:16 /core.html core-project/1.0
10/08/2005 21:08:16 /_vti_bin/_vti_aut/author.dll core-project/1.0
10/08/2005 21:38:47 /_vti_bin/_vti_aut/author.dll core-project/1.0

404 Errors on all the above files because they do not exist on any of my websites. I see lots of recent log entries for it in Google. I could not find anything definitive about it via a search on WW or the web in general.

[edited by: volatilegx at 2:09 am (utc) on Oct. 10, 2005]
[edit reason] obscured IP address [/edit]

keyplyr

6:29 am on Oct 10, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



/_vti_bin/ are MicroSoft Front Page (MSFP) extension files, so possibly someone has saved your site to their desktop - or - has re-published a webpage from your site with MSFP and someone else is using this UA (core-project/1.0) to request these files. If so, there should be an active link to your domain remaining or else these file requests wouldn't be in your log.

Looks like core-project/1.0 is a personal bot written by someone over at codingforums.com.

GaryK

4:14 pm on Oct 10, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



If so, there should be an active link to your domain remaining or else these file requests wouldn't be in your log.

Nope. I've never had Front Page Extensions installed on my server. :)

I often see bots requesting files that have never been on my server. I usually suspect them of being vulnerability probes.

Looks like core-project/1.0 is a personal bot written by someone over at codingforums.com.

That's sort of what I thought, but if it's the same forum I looked at the name of the project was just slightly different, code project vs. code-project, so I wasn't positive about it referring to this user agent.

wilderness

4:57 pm on Oct 10, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I often see bots requesting files that have never been on my server.

The vti prompts can also come from a visitor using either MS-Word or FP for a browser.

I've had a few instances were visitors using FP actually attempt to modify a page.
These instances have been so rare and non-sucessive in attempts that I'm not so sure they were as much malicious as accidental.

I've never had the FP extnsions installed. I did at one time use FP to create web pages, however in a very limited capapcity and mainly as a text editor. NEVER having used any of the componets options.

keyplyr

7:31 pm on Oct 10, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Nope. I've never had Front Page Extensions installed on my server. :)

I didn't intend to imply you did, as Wilderness said, these file requests do not necessarily require that MS extensions are on your server, just that the user is asking for them, for several of the above reasons.

GaryK

6:38 am on Oct 11, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I understand now. Thanks for being patient with me. :)