看到一段Apache的日志,难道这家伙要黑我服务器?
192.95.19.211 - - "GET /phpmyadmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 216 "-" "-"192.95.19.211 - - "GET /phpMyadmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 216 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 216 "-" "-"
192.95.19.211 - - "GET /mysqladmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 216 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-3.3.5-all-languages/sql.php?db=mysql&sql_query= HTTP/1.1" 404 236 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-3.3.4-all-languages/sql.php?db=mysql&sql_query= HTTP/1.1" 404 236 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.8.2/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.11.10-all-languages/sql.php?db=mysql&sql_query= HTTP/1.1" 404 238 "-" "-"
192.95.19.211 - - "GET /PMA/sql.php?db=mysql&sql_query= HTTP/1.1" 404 209 "-" "-"
192.95.19.211 - - "GET /mysql/sql.php?db=mysql&sql_query= HTTP/1.1" 404 211 "-" "-"
192.95.19.211 - - "GET /admin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 211 "-" "-"
192.95.19.211 - - "GET /db/sql.php?db=mysql&sql_query= HTTP/1.1" 404 208 "-" "-"
192.95.19.211 - - "GET /dbadmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 213 "-" "-"
192.95.19.211 - - "GET /admin/phpMyAdmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /admin/phpmyadmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /admin/mysql/sql.php?db=mysql&sql_query= HTTP/1.1" 404 217 "-" "-"
192.95.19.211 - - "GET /admincp/phpmyadmin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 224 "-" "-"
192.95.19.211 - - "GET /mydb/sql.php?db=mysql&sql_query= HTTP/1.1" 404 210 "-" "-"
192.95.19.211 - - "GET /sqldb/sql.php?db=mysql&sql_query= HTTP/1.1" 404 211 "-" "-"
192.95.19.211 - - "GET /mysql-admin/sql.php?db=mysql&sql_query= HTTP/1.1" 404 217 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.5.6/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.5.4/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.5.1/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.2.3/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "GET /phpMyAdmin-2.2.6/sql.php?db=mysql&sql_query= HTTP/1.1" 404 222 "-" "-"
192.95.19.211 - - "PUT /webdav/7846728399998221000 HTTP/1.1" 405 247 "-" "Sardine/UNAVAILABLE"我站点上根本就没放这些文件,看来他在猜测。。。。。。这个IP一直能Ping通,加拿大的,没准是个服务器抓鸡用的。
怎么查这个IP的主机商啊?
Montreal ovh.net 习惯就好。。我服务器天天被暴力破解 http://who.is/whois-ip/ip-address/192.95.19.211
OVH Hosting, Inc.
我上次也遇到过.:curse: 就连空间也是整天被扫,wordpress程序经常有个固定的错误页面来源,呵呵。 只是扫一下 不是要黑 估计是想帮你检查下安全问题吧 想暴库,看你的防御了 增长了见识了呵呵呵 扫描程序很平常:'( 这根本就是挠痒一样的
这种就是扫描器留下的脚印
我还曾经观察过,根据字典的url或者其它特征,有时候可以找出是什么扫描器
一般情况下,可以直接忽略
页:
[1]