Abdull Karem scans
-
Hi there,
Lately our servers are getting hammered by some sort of scan with query string like:
GET /test.php?450699=1&php4=1&root=1&upl=1&wphp4=1&abdullkarem= GET /include.php?450699=1&php4=1&root=1&upl=1&wphp4=1&abdullkar GET /sql.php?450699=1&php4=1&root=1&upl=1&wphp4=1&abdullkarem=1 GET /img.php?450699=1&php4=1&root=1&upl=1&wphp4=1&abdullkarem=1
Only WordPress sites seem to be affected.
When a scan is in progress, it will almost certain get the server in OOM mode and needs to be rebooted.
When I did a search through the Firewall log of a NinjaFirewall protected site, I also found traces of abdullkarem21/Oct/15 04:22:35 #1989814 critical 1417 46.4.112.7 GET /index.php - Suspicious bot - [GET:abdullkarem = 1] 21/Oct/15 04:22:40 #3382768 critical 1417 46.4.112.7 GET /index.php - Suspicious bot - [GET:abdullkarem = 1]
The server did not go down though.
Does it mean NinjaFirewall for WordPress is blocking this can? (Which would be great!) ??Greetings,
Robert
Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)
- The topic ‘Abdull Karem scans’ is closed to new replies.