TNGUSER Posted April 21, 2008 Report Share Posted April 21, 2008 I posted a question on the Forum awhile back regarding a "()" entry that I've seen in my showlog from various IP addresses but no one knew the answer to my question as to what this entry was or how it was generated. I've also searched the WWW and no hits on identifying what this entry means. When I click on the "()" entry in my log file I get a 404 error code. Today I found three more "()" entries by the same IP address: Mon 21 Apr 2008 01:05:15 PM () accessed by 211.78.87.178Mon 21 Apr 2008 01:05:13 PM () accessed by 211.78.87.178 Mon 21 Apr 2008 01:05:09 PM () accessed by 211.78.87.178I wrote to my webhost, ICDSoft and they suggested I get in touch with Darrin. Here is his reply. I strongly urge anyone reading this to review your log files for any "()" entries and most especially make sure you've applied the most recent (security) updates from Darrin. I've also denied access from 211.78.87.178 in my .htaccess file and will continue to ban all others who I see have generated a "()" log entry. CarolDarrin's reply received today Monday, April 21, 2008................It could very well be an attempt to find a vulnerability in the software.As long as you're up to date, you shouldn't fall prey to any knownvulnerabilities, however. The empty parentheses probably mean that someoneattempted to access the getperson.php page without a valid person ID.In any case, please contact me or the support forum or the mailing listwith any questions about TNG. ICDSoft will not know anything about thesoftware.Darrin Quote Link to comment Share on other sites More sharing options...
TNGUSER Posted April 21, 2008 Author Report Share Posted April 21, 2008 In the interest and for the security of all, you might want to post here, IP addresses that you see in your log file that include the "()" entry. It would be up to the individual TNG site owner whether or not to exclude those IP address from access but at least those of us viewing this Topic would know which IP addresses may be suspect.Carol Quote Link to comment Share on other sites More sharing options...
Lucky Posted April 22, 2008 Report Share Posted April 22, 2008 I'm also getting hammered by these guys. We've been playing a little game all day. They show up, I add an IP to my htaccess file, they go away and then an hour or two later they come back with another IP. They are only around for a couple of minutes but they hit lots of files at about one every couple of seconds. I get some of the () entries and they hit lots of files that don't exist. Looks like this;Mon 21 Apr 2008 03:43:14 PM Cemeteries and Headstones in USA accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:12 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:12 PM Earl B. and Eva Allison (60) accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:11 PM Place List: accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:10 PM Place List: accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:08 PM Notes accessed by mail.peter-c.com. The scary one is this one;Mon 21 Apr 2008 12:01:35 PM Descendancy for (I203) accessed by unknown.Mon 21 Apr 2008 12:01:32 PM Documents accessed by unknown.Mon 21 Apr 2008 12:01:30 PM Descendancy for (I203) accessed by unknown.Mon 21 Apr 2008 12:01:28 PM () accessed by unknown.Mon 21 Apr 2008 12:01:27 PM () accessed by unknown.Mon 21 Apr 2008 12:01:26 PM () accessed by unknown.Mon 21 Apr 2008 12:01:25 PM Documents accessed by unknown.Mon 21 Apr 2008 12:01:24 PM Documents accessed by unknown.Mon 21 Apr 2008 12:01:23 PM Documents accessed by unknown. How do you block someone who you can't identify?Here are some of the other IPs I have banned so far;Mon 21 Apr 2008 06:22:14 PM (R1) accessed by host-213-189-188-42.brutele.be. Mon 21 Apr 2008 11:09:12 AM Ahnentafel: (I261) accessed by ws03.hosting.nl. Sun 20 Apr 2008 09:14:15 PM Family of Maugherman Orpha (I278) accessed by vev69-2-82-241-34-212.fbx.proxad.net.retail.telecomitalia.it212.6.249.20And that's just today. I'm pretty paranoid since I got hacked last month (yeah I know, I should have upgraded sooner). There is no evidence that anything has been compromised and they only stick around for a few minutes but I'll keep blocking and maybe they will eventually go away.Lucky Quote Link to comment Share on other sites More sharing options...
TNGUSER Posted April 22, 2008 Author Report Share Posted April 22, 2008 I'm also getting hammered by these guys. We've been playing a little game all day. They show up, I add an IP to my htaccess file, they go away and then an hour or two later they come back with another IP. They are only around for a couple of minutes but they hit lots of files at about one every couple of seconds. I get some of the () entries and they hit lots of files that don't exist. Looks like this;Mon 21 Apr 2008 03:43:14 PM Cemeteries and Headstones in USA accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:12 PM () accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:12 PM Earl B. and Eva Allison (60) accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:11 PM Place List: accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:10 PM Place List: accessed by mail.peter-c.com.Mon 21 Apr 2008 03:43:08 PM Notes accessed by mail.peter-c.com. The scary one is this one;Mon 21 Apr 2008 12:01:35 PM Descendancy for (I203) accessed by unknown.Mon 21 Apr 2008 12:01:32 PM Documents accessed by unknown.Mon 21 Apr 2008 12:01:30 PM Descendancy for (I203) accessed by unknown.Mon 21 Apr 2008 12:01:28 PM () accessed by unknown.Mon 21 Apr 2008 12:01:27 PM () accessed by unknown.Mon 21 Apr 2008 12:01:26 PM () accessed by unknown.Mon 21 Apr 2008 12:01:25 PM Documents accessed by unknown.Mon 21 Apr 2008 12:01:24 PM Documents accessed by unknown.Mon 21 Apr 2008 12:01:23 PM Documents accessed by unknown. How do you block someone who you can't identify?Here are some of the other IPs I have banned so far;Mon 21 Apr 2008 06:22:14 PM (R1) accessed by host-213-189-188-42.brutele.be. Mon 21 Apr 2008 11:09:12 AM Ahnentafel: (I261) accessed by ws03.hosting.nl. Sun 20 Apr 2008 09:14:15 PM Family of Maugherman Orpha (I278) accessed by vev69-2-82-241-34-212.fbx.proxad.net.retail.telecomitalia.it212.6.249.20And that's just today. I'm pretty paranoid since I got hacked last month (yeah I know, I should have upgraded sooner). There is no evidence that anything has been compromised and they only stick around for a few minutes but I'll keep blocking and maybe they will eventually go away.LuckyLucky, you are getting hit pretty hard and the "Unknown" entry would worry me too. I hope someone will be able to tell you how that kind of entry can be blocked.Carol Quote Link to comment Share on other sites More sharing options...
Torben Posted April 22, 2008 Report Share Posted April 22, 2008 In the interest and for the security of all, please post HERE any IP addresses that you see in your log file that include the "()" entry. It would be up to the individual TNG site owner whether or not to exclude those IP address from access but at least those of us viewing this Topic would know which IP addresses are suspect.CarolHi I'm also having the problemMon 21 Apr 2008 10:33:07 PM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.unduetretoccaate.it/codice/fog/iyi/ accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:45 PM () accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/. And I think this one are trying the sameTue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://wwww.tureksfuar.com.tr/joomla/mambots/content/cobojax/udak/ accessed by 193.254.184.38/. Tue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 193.254.184.38/. Tue 22 Apr 2008 11:43:20 AM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 193.254.184.38/. Torben Quote Link to comment Share on other sites More sharing options...
TNGUSER Posted April 22, 2008 Author Report Share Posted April 22, 2008 Hi I'm also having the problemMon 21 Apr 2008 10:33:07 PM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.unduetretoccaate.it/codice/fog/iyi/ accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:45 PM () accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/. Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/. And I think this one are trying the sameTue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://wwww.tureksfuar.com.tr/joomla/mambots/content/cobojax/udak/ accessed by 193.254.184.38/. Tue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 193.254.184.38/. Tue 22 Apr 2008 11:43:20 AM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 193.254.184.38/. TorbenBetween these two they viewed 300+ records early this morning.() accessed by ip202-182-124-4.voicevalley-networks.com() accessed by ev1s-67-15-72-87.ev1servers.netCarol Quote Link to comment Share on other sites More sharing options...
Lucky Posted April 22, 2008 Report Share Posted April 22, 2008 Between these two they viewed 300+ records early this morning.() accessed by ip202-182-124-4.voicevalley-networks.com() accessed by ev1s-67-15-72-87.ev1servers.netCarolI got a couple more but they seem to be slowing down today. They were each only around about two minutes hitting 40-50 records each. Maybe they are getting tired.Mon 21 Apr 2008 11:02:36 PM () accessed by cornaline.logicek.netTue 22 Apr 2008 07:35:39 AM () accessed by 66.205.65.100Lucky Quote Link to comment Share on other sites More sharing options...
Lucky Posted April 22, 2008 Report Share Posted April 22, 2008 Interestingly I'm getting some of the same urls mentioned by Torben above. Seems like they search for a form on your page and then insert the http://........ stuff into the form. Going to the websites shown above you find a web page that has only "<?php echo md5("just_a_test");?>"I suspect that's what would be inserted into your website if they are successful. If anybody knows how to read server logs (I really don't) here's what most of the lines look like in my server log with differing URLs.66.205.65.100 - - [22/Apr/2008:09:35:02 -0400] "GET /placesearch.php?psearch=http%3A%2F%2Fwww.thoseguysfilms.com%2Fforums%2Ftemplates%2FsubSilver%2Fimages%2Ftimuji%2Fogu%2F HTTP/1.0" 200 10975 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"Lucky Quote Link to comment Share on other sites More sharing options...
TNGUSER Posted April 22, 2008 Author Report Share Posted April 22, 2008 Interestingly I'm getting some of the same urls mentioned by Torben above. Seems like they search for a form on your page and then insert the http://........ stuff into the form. Going to the websites shown above you find a web page that has only "<?php echo md5("just_a_test");?>"I suspect that's what would be inserted into your website if they are successful. If anybody knows how to read server logs (I really don't) here's what most of the lines look like in my server log with differing URLs.66.205.65.100 - - [22/Apr/2008:09:35:02 -0400] "GET /placesearch.php?psearch=http%3A%2F%2Fwww.thoseguysfilms.com%2Fforums%2Ftemplates%2FsubSilver%2Fimages%2Ftimuji%2Fogu%2F HTTP/1.0" 200 10975 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"LuckyI don't have any idea either how to read those logs. Hopefully someone else will take a look and know what it all means.I wonder if there is any way to edit the .htaccess file or similar file to auto block any IP address that tries to access the getperson.php without a valid ID rather than adding all the individual IP addresses that return a "()" in the showlog file.Carol Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.