Re: Server Traffic - Anybody know the name of this type attack?

David C Rankin <[email protected]>
Newsgroups gmane.linux.suse.general
Message-ID <[email protected]>
On 8/26/26 7:01 AM, Adam Tauno Williams via openSUSE Users wrote:
> On Wed, 2026-08-26 at 13:36 +0200, Andreas Stieger via openSUSE Users
> wrote:
>> On 2026-08-26 07:00, David C Rankin wrote:
>>> [...] hammered by rotating IP addresses [...] trying random .php
>>> pages.
>> These are not random, but names of known previously vulnerable PHP
>> scripts.
> We have a long-ish list of these which we filter out at the nginx
> front-end, or previously in the Apache config.   It is easy to do,
> these are very repetative, you just return HTTP/418 TEAPOT to all these
> paths.
> 
> Otherwise you will have a lot of noise in your logs.
> 
> Also, never code anything which matches these paths

Thank you both!

   Carlos also helped off-list with AI's assessment of the entries and 
concluded the traffic was most likely trying to trigger or web-shell 
vulnerability or as you indicate trying names of prior known vulnerable 
vulnerable scripts.

   They made more than 10,000 attempts generating 20,000 + entries and 
megabytes of logs -- but after pouring over the logs, none were 
successful. The only 200 responses were the ones for legitimate pages 
and traffic.

   I, like the rest, get scraped and crawled almost continually, but 
this set of logs caught my eye. Thankfully, it just led to getting a 
little smarter, and no harm done.

-- 
David C. Rankin, J.D.,P.E.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.