ExpressionEngine CMS
Open, Free, Amazing

Thread

This is an archived forum and the content is probably no longer relevant, but is provided here for posterity.

The active forums are here.

Is my site being hacked?

July 08, 2012 11:08pm

Subscribe [3]
  • #1 / Jul 08, 2012 11:08pm

    Jbeitel

    16 posts

    I posted this in General Discussion a few days ago, got 40 looks but no feedback.  Let’s see if Community Help is more vocal…

    I was tracking template hits on my website, and noticed what I thought were unusually high counts for my 404-page not found template.  So, I installed an extension which sends me an email from the 404 template.

    First, internal redirects don’t provide the original url which wasn’t found.  However, I figured out the cause, and have corrected the problem.

    What’s left are a few unexplainable URLs which do show up since they are not part of the EE template hierarchy.  Here’s the prototype for the email body:

    Page Not Found: {uri_string} by {httpagent}

    ‘uri_string’ is whatever was sent following my root website (e.g. example.com/uri_string.  ‘httpagent’ supposedly identifies the sender’s browser.

    Here are a few of the unexplained URL’s:
    1. Page Not Found: admin/module-builtin.xml by Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
    2. Page Not Found: vtigercrm/modules/com_vtiger_workflow/sortfieldsjson.php by
    3. Page Not Found: sitemap.php by msnbot/2.0b (+http://search.msn.com/msnbot.htm)
    4. Page Not Found: recordings/index.php by Mozilla/5.0 (Windows NT 5.1) AppleWebKit/534.30 (KHTML, like Gecko) Chrome/12.0.742.112 Safari/534.30
    5. Page Not Found: phpmyadmin/translators.html by Mozilla/4.0 (compatible;MSIE 6.0; MSIE 5.5; Windows NT 5.1) Opera 7.01 [en]
    6. Page Not Found: admin/config.php by Python-urllib/2.4

    Some of this might be search bots (3, for example is almost certainly msn).  But others look like hacking attempts.  Note that 2 is anonymous.

    I’d be interested in your opinions as to what these might be, and what, if anything, should be done.

    Thanks! —Jim

  • #2 / Jul 11, 2012 7:02am

    silenz

    1651 posts

    Your site is not hacked but scanned randomly for known vulnerable scripts.
    As long as those are not present you are safe.

  • #3 / Jul 11, 2012 12:29pm

    Jbeitel

    16 posts

    Thanks!  I appreciate the clarification.  This was my suspicion, but better to know than assume.

  • #4 / Jul 17, 2012 5:40pm

    carlosq

    9 posts

    Just to let you know I have the same issue, they’re always scanning for scripts vulnelabirities to hack.

  • #5 / Jul 18, 2012 9:48am

    Matthew81

    81 posts

    I know a lot of webmasters who install scripts to add temporary .htaccess blocks for IP addresses that generate these sorts of requests. I’ve never done that myself, but I plan to look into it soon.

  • #6 / Jul 18, 2012 2:00pm

    Jbeitel

    16 posts

    Thanks, Carlos and Matthew.  As you probably can guess, I’m new to this part of the game, so you’ve at least made me feel much better!

    It’s pretty low volume, but if it gets out of hand, I too will look into blocking.

    —Jim

.(JavaScript must be enabled to view this email address)

ExpressionEngine News!

#eecms, #events, #releases