PHP script attack?

PHP script attack?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
PHP script attack? Brion 09-24-2007
Posted by Brion on September 24, 2007, 8:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi everyone,
Recently we've started getting error messages similar to the following:

Source: W3SVC-WP
Event ID: 2216

Description:
The script started from the URL '/thisdoesnotexistahaha.php' with parameters
'' has not responded within the configured timeout period. The HTTP server
is terminating the script.

The particular .php script involved has a different name each time. If I'm
reading this right, someone is trying to execute a php script somehow. The
server does host some websites that use php, and it has PostgreSQL installed
too. How are they attempting to execute a script? Via HTTP post? What are
they trying to do? Even if they find one of the php files on the server,
what good would it do them to execute it? Any advice is appreciated.

Thanks!



Posted by on September 24, 2007, 2:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
That comes from an automated scanner. Someone is trying to identify
your web server (e.g., OS, Http server, PHP version, et cetera) and
find vulnerabilities. Best to check that your web server is up-to-date
and your PHP is patched.

Regards,

J Wolfgang Goerlich


Related Links:

[Dshield] What is thisdoesnotexistahaha.php?
http://lists.sans.org/pipermail/list/2006-July/024862.html

Cacti remote injection exploit
http://www.freebsddiary.org/cacti-exploit.php

> Hi everyone,
> Recently we've started getting error messages similar to the following:
>
> Source: W3SVC-WP
> Event ID: 2216
>
> Description:
> The script started from the URL '/thisdoesnotexistahaha.php' with parameters
> '' has not responded within the configured timeout period. The HTTP server
> is terminating the script.
>
> The particular .php script involved has a different name each time. If I'm
> reading this right, someone is trying to execute a php script somehow. The
> server does host some websites that use php, and it has PostgreSQL installed
> too. How are they attempting to execute a script? Via HTTP post? What are
> they trying to do? Even if they find one of the php files on the server,
> what good would it do them to execute it? Any advice is appreciated.
>
> Thanks!



Posted by Brion on September 26, 2007, 9:09 am
If you were  Registered and logged in, you could reply and use other advanced thread options
OK, will do. Thanks for the information!


> That comes from an automated scanner. Someone is trying to identify
> your web server (e.g., OS, Http server, PHP version, et cetera) and
> find vulnerabilities. Best to check that your web server is up-to-date
> and your PHP is patched.
>
> Regards,
>
> J Wolfgang Goerlich
>
>
> Related Links:
>
> [Dshield] What is thisdoesnotexistahaha.php?
> http://lists.sans.org/pipermail/list/2006-July/024862.html
>
> Cacti remote injection exploit
> http://www.freebsddiary.org/cacti-exploit.php
>
>> Hi everyone,
>> Recently we've started getting error messages similar to the
>> following:
>>
>> Source: W3SVC-WP
>> Event ID: 2216
>>
>> Description:
>> The script started from the URL '/thisdoesnotexistahaha.php' with
>> parameters
>> '' has not responded within the configured timeout period. The HTTP
>> server
>> is terminating the script.
>>
>> The particular .php script involved has a different name each time. If
>> I'm
>> reading this right, someone is trying to execute a php script somehow.
>> The
>> server does host some websites that use php, and it has PostgreSQL
>> installed
>> too. How are they attempting to execute a script? Via HTTP post? What
>> are
>> they trying to do? Even if they find one of the php files on the server,
>> what good would it do them to execute it? Any advice is appreciated.
>>
>> Thanks!
>
>



Similar ThreadsPosted
Help - Hacker attack September 4, 2005, 4:00 pm
ethernet attack April 5, 2006, 12:03 pm
Help: "Delayed writes" is this an attack? July 29, 2006, 10:39 am
Flash9 DoS attack on IE6SP1 September 27, 2006, 6:44 am
Help: Windows XP cyber attack? July 31, 2007, 3:30 pm
FTP login flood attack November 22, 2007, 8:01 pm
Remote Attack? Modem security January 24, 2006, 9:36 pm
RE: Microsoft warns of Excel 0-day attack June 19, 2006, 1:57 am
Microsoft Warns of PowerPoint Attack October 13, 2006, 11:33 pm
Microsoft patch opens users to attack August 23, 2006, 11:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy