最近我的服务器访问日志里一直有大量的诸如以下的的访问记录:
估计是使用了什么黑客工具,而工具里有自带user-agent:zmEu @ WhiteHat Team -
www.whitehat.ro我直接通过user-agent 就封了, 他还是不断的一直在试图探出诸如Php mysql admin这样的访问接口。。全不返回的403 还是一直再试。。。。。。。。。。。无语了
老在日志里看到这样的东西很不爽。。 大家可以看看自己web服务器的访问记录里也有诸如: Made by ZmEu @ WhiteHat Team - www.whitehat.ro的?
IP:[ 88.34.113.33 ] - - "GET //mysqladmin/ HTTP/1.1" 403 169 "-" HTTP_USER_AGENT:[ Made by ZmEu @ WhiteHat Team -
www.whitehat.ro ] 26/Dec/2010:19:51:32 +0800 ]
IP:[ 58.177.206.19 ] - - "GET //phpmyadmin/ HTTP/1.1" 403 169 REF:[ - ] HTTP_USER_AGENT:[ Made by ZmEu @ WhiteHat Team -
www.whitehat.ro ] [ 28/Dec/2010:09:31:05 +0800 ]
IP:[ 58.177.206.19 ] - - "GET //PHPmyadmin HTTP/1.1" 403 169 REF:[ - ] HTTP_USER_AGENT:[ Made by ZmEu @ WhiteHat Team -
www.whitehat.ro ] [ 28/Dec/2010:09:31:09 +0800 ]
IP:[ 58.177.206.19 ] - - "GET //admin/ HTTP/1.1" 403 169 REF:[ - ] HTTP_USER_AGENT:[ Made by ZmEu @ WhiteHat Team -
www.whitehat.ro ] [ 28/Dec/2010:09:31:24 +0800 ]
IP:[ 58.177.206.19 ] - - "GET //mysql/ HTTP/1.1" 403 169 REF:[ - ] HTTP_USER_AGENT:[ Made by ZmEu @ WhiteHat Team -
www.whitehat.ro ] [ 28/Dec/2010:09:31:24 +0800 ]
这是一个专为移动设备优化的页面(即为了让你能够在 Google 搜索结果里秒开这个页面),如果你希望参与 V2EX 社区的讨论,你可以继续到 V2EX 上打开本讨论主题的完整版本。
https://www.v2ex.com/t/6447
V2EX 是创意工作者们的社区,是一个分享自己正在做的有趣事物、交流想法,可以遇见新朋友甚至新机会的地方。
V2EX is a community of developers, designers and creative people.