June 29, 2009

Mysterious traffic

I wonder what in hell this person in China was trying to do?

- -> /adminhh/ytpylogin.asp 61.191.53.53
- -> /adminhh/login.asp 61.191.53.53
- -> /adminhh/login.asp 61.191.53.53
- -> /database/pibuaddsfedsffdsggfhhdf.asa 61.191.53.53
- -> /database/addsfedsffdsggfhhdf.asa 61.191.53.53
- -> /database/addsfedsffdsggfhhdf.asa 61.191.53.53
- -> /database/fqtmaaddsfedsffdsggfhhdf.asa 61.191.53.53
- -> /database/aaddsfedsffdsggfhhdf.asa 61.191.53.53
- -> /database/aaddsfedsffdsggfhhdf.asa 61.191.53.53

Nothing good, I'm sure.

UPDATE: Presumably they were looking for some sort of vulnerability in a Windows Server, since that's what ASP runs on. Still, it's a weird one.

There's another thing I've seen off and on over the years where someone tries to access a specific GIF file in one of two specific directories, and when they don't find them they go away. I've always assumed they were using that as a way of determining if a certain specific software package or server package was present. Presumably if they did find it they would then launch some sort of targeted attack. Since they never did (neither directory exists here) they left me alone.

Posted by: Steven Den Beste in Site Stuff at 01:01 PM | No Comments | Add Comment
Post contains 165 words, total size 1 kb.

Enclose all spoilers in spoiler tags:
      [spoiler]your spoiler here[/spoiler]
Spoilers which are not properly tagged will be ruthlessly deleted on sight.
Also, I hate unsolicited suggestions and advice. (Even when you think you're being funny.)

At Chizumatic, we take pride in being incomplete, incorrect, inconsistent, and unfair. We do all of them deliberately.

How to put links in your comment

Comments are disabled. Post is locked.
5kb generated in CPU 0.0095, elapsed 0.0193 seconds.
18 queries taking 0.0129 seconds, 16 records returned.
Powered by Minx 1.1.6c-pink.