attempted attack on my blog 07-01-2011, 06:43 AM
#1
lol... I got ~400 404 hits to my server in a matter of seconds... some script kiddie must have been using a tool to vuln scan my server.
I'm guessing the first 404 line was an "identifier" line "GET /w00tw00t.at.blackhats.romanian.anti-sec
HTTP/1.1"
It's really funny that they pretty much only scanned to see if I had phpMyAdmin... and looked for a incomplete setup leaving the setup.php...
I set up my tools like awstats and phpmyadmin as a script alias of a fake domain that i put in my hosts file and only allow from that machine... so if i want to edit it remotely i have to set up an ssh tunnel with putty and forward some ports...
There were a number of others as well... but none that I found as interesting. A lot of hits from proxies though... a bunch of sql injection attacks... all of the proxies were public proxies that I was able to get their logs to find the real ips...
What do you guys think when someone attempts to attack you? I just kind of laugh because they're not normally a sophisticated attack.
I'm guessing the first 404 line was an "identifier" line "GET /w00tw00t.at.blackhats.romanian.anti-sec
HTTP/1.1"It's really funny that they pretty much only scanned to see if I had phpMyAdmin... and looked for a incomplete setup leaving the setup.php...
I set up my tools like awstats and phpmyadmin as a script alias of a fake domain that i put in my hosts file and only allow from that machine... so if i want to edit it remotely i have to set up an ssh tunnel with putty and forward some ports...
There were a number of others as well... but none that I found as interesting. A lot of hits from proxies though... a bunch of sql injection attacks... all of the proxies were public proxies that I was able to get their logs to find the real ips...
What do you guys think when someone attempts to attack you? I just kind of laugh because they're not normally a sophisticated attack.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)