Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 20 Sep 1998 19:09:19 -0400
From:      Gary Schrock <root@eyelab.psy.msu.edu>
To:        Brett Glass <brett@lariat.org>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: Bogus hits on our Web server
Message-ID:  <199809202309.TAA05189@eyelab.psy.msu.edu>
In-Reply-To: <199809202128.PAA11447@lariat.lariat.org>

next in thread | previous in thread | raw e-mail | index | archive | help
At 02:43 PM 9/20/98 -0600, you wrote:
>We've gotten several spates of Web log entries like the following:
>
>62.8.15.131 unknown - [20/Sep/1998:10:43:16 -0600] "GET /cgi-bin/phf" 404 -
>62.8.15.131 unknown - [20/Sep/1998:10:43:17 -0600] "GET /cgi-bin/test-cgi"
>404 -
>62.8.15.131 unknown - [20/Sep/1998:10:43:18 -0600] "GET /cgi-bin/handler"
>404 -

People running scripts.  The phf one is an old old hole in one of the cgi
programs that was included in apache (or maybe just ncsa?).  It was removed
a couple years ago or so, but people still scan for it.  I get several of
them every month.


Gary Schrock
root@eyelab.msu.edu


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199809202309.TAA05189>