Hi -- Another very strange server log entry. Does anyone know what this is?
201.153.nn.nnn - - [31/Aug/2010:14:59:54 -0400] "GET /osc/product_info.php?cpath=183&products_id=1388%20and%201=2%20union%20select%20CONCAT(0x27,0x7c,0x5f,0x7c), CONCAT(0x27,0x7c,0x5f,0x7c),CONCAT(0x27,0x7c,0x5f,0x7c), CONCAT(0x27,0x7c,0x5f,0x7c), CONCAT(0x27,0x7c,0x5f,0x7c),CONCAT(0x27,0x7c,0x5f,0x7c),CONCAT(0x27,0x7c,0x5f,0x7c), CONCAT(0x27,0x7c,0x5f,0x7c)%20/* HTTP/1.1" 200 31271 "-" "czxt2s"
There were many log entries like this, but a variety of different IPs. I assume the czxt2s is the user agent, which I blocked in htaccess. I am planning to also block the various IPs.
Grandma_genie
[edited by: Ocean10000 at 3:49 pm (utc) on Sep 8, 2010]
[edit reason] Added spaces to allow for wrapping. [/edit]