Results 1 to 4 of 4

Code injection attempt and user agent to block

This is a discussion on Code injection attempt and user agent to block within the Off-Topic & Chit Chat forums, part of the Focus on Members category; Just going through my visits log and found some rather nice moron in China has been trying what looks like ...

  1. #1
    Senior Member Lee G's Avatar
    Real Name
    Lee
    Join Date
    Sep 2006
    Location
    Costa Blanca
    Posts
    690
    Liked
    40 times
    Blog Entries
    4

    Code injection attempt and user agent to block

    Just going through my visits log and found some rather nice moron in China has been trying what looks like a code injection

    114.80.93.73 - - [15/Feb/2011:00:37:39 -0500] "HEAD /zh-CN/f188/\xe6\xa2\x85\xe8\xa5\xbf\xe4\xb8\xbb\xe6\x9c\xba\x e5\x9c\xa8\xe7\xbd\x97\xe7\xba\xb3\xe5\xb0\x94\xe5 \xa4\x9a\xe7\x9a\x84\xe5\xae\xb6\xe5\x85\x9a-239385/

    Luckily they are easy to ban in both user agent and country

    HTTP/1.0" 403 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; WPS; .NET CLR 1.1.4322"

    I had five attacks all from different ips

    I cant find any mention of the above code on the net. Just what does, is supposed to do etc

  2. #2
    vBSEO Staff Brian Cummiskey's Avatar
    Real Name
    Brian Cummiskey
    Join Date
    Jul 2009
    Location
    btwn NYC and Boston
    Posts
    12,789
    Liked
    657 times
    Blog Entries
    2
    That's actually common to see in logs. I don't know the exact reasoning behind it, but it's 'normal'. Perhaps a server guru can offer more info.

  3. #3
    Senior Member Lee G's Avatar
    Real Name
    Lee
    Join Date
    Sep 2006
    Location
    Costa Blanca
    Posts
    690
    Liked
    40 times
    Blog Entries
    4
    Cheers for that Brian. The only time I noticed it was with someone using QQDownload

  4. #4
    Senior Member
    Real Name
    gotlinks
    Join Date
    Jun 2006
    Posts
    202
    Liked
    5 times
    Quote Originally Posted by Lee G View Post
    Just going through my visits log and found some rather nice moron in China has been trying what looks like a code injection

    114.80.93.73 - - [15/Feb/2011:00:37:39 -0500] "HEAD /zh-CN/f188/\xe6\xa2\x85\xe8\xa5\xbf\xe4\xb8\xbb\xe6\x9c\xba\x e5\x9c\xa8\xe7\xbd\x97\xe7\xba\xb3\xe5\xb0\x94\xe5 \xa4\x9a\xe7\x9a\x84\xe5\xae\xb6\xe5\x85\x9a-239385/

    Luckily they are easy to ban in both user agent and country

    HTTP/1.0" 403 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; QQDownload 1.7; WPS; .NET CLR 1.1.4322"

    I had five attacks all from different ips

    I cant find any mention of the above code on the net. Just what does, is supposed to do etc
    I get these hackting attempt emails all the time. I get them when they fail their attempt
    and my system auto bans their IP from trying again...they are probably using a fake IP or
    something anyway...so the system bans one IP, and it starts all over again...I get about 2-3
    daily emails...keep your server up-to-date, keep your VB up-to-date, keep your mods up-to-date....
    mostly I get hacking attempts from China/India, sometimes even from the US.

Similar Threads

  1. xss injection question
    By dascrow in forum General Discussion
    Replies: 6
    Last Post: 12-11-2009, 01:52 PM
  2. Strange code / caracter injection above header / below footer *argh*
    By Doc Great in forum Off-Topic & Chit Chat
    Replies: 2
    Last Post: 02-22-2007, 02:57 PM
  3. vBSEO agent?
    By viperalley in forum General Discussion
    Replies: 2
    Last Post: 12-08-2006, 05:04 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •