Hi all,
Since I started looking at my logs closely, I’ve noticed lots of attempts to get into the site via, mambo, awstats.pl, xmlrpc.php etc etc. Now as far as I know, I don’t run any of these anyway, so hopefully I’m alright on that front.
I just wondered - is this one of those things like when you first install a firewall and realize you’re getting constantly bombarded, or should I worry - are the versions running on these servers all exploit free (as far as known?).
Well, this is beyond what any firewall does, we could install some software like MS’s old “urlscan” tool, but it would disable some legit items as well.
I have noticed the same thing in logs, there are in my opinion a lot of cheap dedicated servers and dsl/cable users that are infected with some trojan that is controlled by someone, or at least reporting back to someone when they find holes in sites via their scanning engines.
The sheer number of scans I have seen in logs recently tells me that it can not be just a couple computers, but possible THOUSANDS of computers doing this.
Thanks Stephen.
So it is slightly abnormal then ?
Is it something that has started recently ? And could it cause any slowdowns ? I suppose they’re like any other spider… just with bad intent.
Abnormal, yes in the last 2 weeks I have seen just random accesses go up to probably 15-20 a day on noname sites, and possible hundreds on other sites.
I have seen a large numer of log entries like this:
/phpMyAdmin-2.6.0/read_dump.php 1 -
/phpMyAdmin+2.2.7-pl1/read_dump.php 1 -
(actually that is awstats output)
I don’t think this type of activity will be ending anytime soon, so peope need to remain vigilant in keeping software up to date to protect themselves.