Stop hacking my server!

Well... Stop trying at any rate!
By Oli on Saturday, 28th April 2007. More information. Comments.

Oli gets mad as hackers converge on his server... But the problem is none of them have a brain cell between them. Sigh...

If you run a web server have you ever wondered what people are trying to do when you notice that your 404-log is jam-packed with requests for dodgy looking files? They're looking for known exploitable scripts.

Here are some that I've had requests for over the past week:

cgi-bin/FormMail.pl
jobs.cgi
events.cgi
media.cgi
newsdesk.cgi
deportes.cgi
newsupdate.cgi
news.cgi
biznews.cgi
app/webeditor/login.cgi
cgi-bin/awstats/awstats.pl
cgi-bin/awstats/awstats.pl
scgi-bin/awstats/awstats.pl
cgi/awstats/awstats.pl
scgi/awstats/awstats.pl
horde/README
horde3/README
horde2/README
horde-3.0.9/README
Horde/README
horde-3.0.5/README
horde-3.0.7/README

Who's doing this and why?!

Who's scanning? Script kiddies. In other words, poor excuses for people using other people's work to try and hack servers so they can use your space, CPU and bandwidth without cost.

Why? Well chances are these "people" want to use your server to do illegal things. This could be just scanning other servers for similar exploits but it could also be things like sending spam, hosting copyright-infringing files or even working together with other servers to take down another server (DDoS).

The slightly idiotic thing is this isn't a Linux server!

The slightly idiotic thing is this isn't a Linux server! Most people with Windows servers don't faff around with Perl and CGI and it should be obvious to anybody with more than one brain cell that when a server writes this in its response header:

Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
X-AspNet-Version: 2.0.50727

... it's not a sodding Linux box!

Grav

Written by Oli on Saturday, 28 April 2007. Tagged with <rant>. Read 3152 times. If you liked it, please give it a digg.

#1 /* 87 days, 19 hours ago */
if we catch these asshats doing this can we take them out and shoot them
#2 — Author comment /* 87 days, 14 hours ago */
Amen to that, brother.

Don't just sit there like a lemon! Reply!

Got something to say? Now's the time to share it with the author and everybody else that reads this posting! Lemons need not apply.

edtBOX - xHTML: yes - bbcode:no
Home | Advertise | About | Contact | Legal © Oli Warner 2001—2007 Proud 9rules member