Re: Fw: Hack Attack - Let's guess mail file names(in Domino).
"Jim Franz" <franz400-goaWJWIt5zpWk0Htik3J/[email protected]> Mon, 27 Oct 2008 09:49:31 -0400
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <BBD1441D96774CFBB8710ED9FA2BBA35@D3L5F1C1> |
In my Apache logs I see an increasing nbr of guess/scan of php files (we are not running any php) /administrator/index3.php /modules/My_eGallery/index.php /phplive/help.php /index1.php /index.php /PHP/includes/header.inc.php /samPHPweb//common/db.php config.inc.php Jim ----- Original Message ----- From: <ChadB-wiCRs0dFRMj+7NiPasB1ylaTQe2KTcn/@public.gmane.org> To: "Security Administration on the AS400 / iSeries" <security400-Zwy7GipZuJhWk0Htik3J/[email protected]> Sent: Monday, October 27, 2008 9:15 AM Subject: Re: [Security400] Fw: Hack Attack - Let's guess mail file names(in Domino). Looks like the types of log entries you'll get from certain 'security scan' type software packages or tools. Any possibility your network group was doing some vulnerability testing? If not, looks like you got scanned by someone 'outside'! _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.