[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] (GET requests)



Looks like someone was trying to read your password file using an exploit in
PHP.cgi.

-----Original Message-----
From: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]On Behalf Of Paul Brown
Sent: Tuesday, August 21, 2001 10:02 AM
To: Cobalt Users List
Subject: [cobalt-users] (no subject)


All

I had hundreds of the two GET requests below within a couple of minutes.
What do they mean? Is someone trying to hack me?



dns0.internethosting.co.uk 213.20.48.33 - - [13/Aug/2001:07:56:11 +0100]
"GET /cgi-bin/php.cgi?/etc/passwd HTTP/1.0" 302 238 "-"
"Mozilla/2.0 (compatible; NEWT ActiveX; Win32)"

dns0.internethosting.co.uk 213.20.48.33 - - [13/Aug/2001:07:56:11 +0100]
"GET /_vti_pvt/ HTTP/1.0" 302 220 "-" "Mozilla/2.0
(compatible; NEWT ActiveX; Win32)"

Kind Regards

Paul Brown
Teknek Electronics
0141 568 8250



_______________________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To Subscribe or Unsubscribe, please go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users