| Unintentional Honey Trap - Checking Logs |
| Written by Mandville |
| Sunday, 13 May 2012 17:59 |
While checking my site logs, as should be standard practice for everyone, I discovered an unintentional honeytrap.Q. What is the point of trying to hack an rss feed and is it possible?To show how bad some of these hack attempts are a quick view over the logs of your site should highlight some of the basic hacking attempts on vulnerable extensions.This site has a feed to content using the great feedgator tool that will take the VEL list and insert it into a content item/article/post. Obviously this eventually turns up into a search engine somewhere. Script kiddies doing their first exploit search will see probably see these results and attempt to hack these links.
A check of my logs shows that all the people who recently scoured this rss to content feed tried to exploit known vel items (which are not used on the site) Personally i think the "best" attack is this one ## This attempts to block the most common type of exploit `attempts` to Joomla!
Here are some examples of how they would appear in the log, They are trimed for easy reading, but also note the libwww bot, that is commented on in this topic. The 403 code indeicates they were blocked. /joomla/news//index.php?option=com_properties&controller=../../../../../../../../../../../../../../../../. /joomla/news//index.php?option=com_juliaportfolio&controller=../../../../../../../../../../../../../../../
|

