Note that there are some explanatory texts on larger screens.

plurals
  1. POBotnet spams server with POST and GET requests
    primarykey
    data
    text
    <p>Each request is coming from a different IP. So I think these are botnet victims still requesting a botnet script I removed a week ago.</p> <p>Here you can see a tiny part of the access log:</p> <pre><code>95.228.246.9 - - [26/Oct/2013:15:40:52 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; BRI/2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" 95.228.246.9 - - [26/Oct/2013:15:40:52 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; BRI/2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" 72.85.226.216 - - [26/Oct/2013:15:40:53 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.4506.2152; .NET4.0C; .NET4.0E; IPH 1.1.21.4019; BRI/2)" 72.85.226.216 - - [26/Oct/2013:15:40:53 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.4506.2152; .NET4.0C; .NET4.0E; IPH 1.1.21.4019; BRI/2)" 94.201.237.81 - - [26/Oct/2013:15:40:55 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 94.201.237.81 - - [26/Oct/2013:15:40:55 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 72.85.226.216 - - [26/Oct/2013:15:40:58 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.4506.2152; .NET4.0C; .NET4.0E; IPH 1.1.21.4019; BRI/2)" 94.201.237.81 - - [26/Oct/2013:15:40:58 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 72.85.226.216 - - [26/Oct/2013:15:40:59 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.4506.2152; .NET4.0C; .NET4.0E; IPH 1.1.21.4019; BRI/2)" 94.201.237.81 - - [26/Oct/2013:15:41:00 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 188.135.15.144 - - [26/Oct/2013:15:41:00 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0; BRI/1; InfoPath.2; BRI/2)" 188.135.15.144 - - [26/Oct/2013:15:41:01 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; Tablet PC 2.0; BRI/1; InfoPath.2; BRI/2)" 94.201.237.81 - - [26/Oct/2013:15:41:01 +0200] "GET /eze/panel/config.bin HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 94.201.237.81 - - [26/Oct/2013:15:41:02 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 85.154.191.178 - - [26/Oct/2013:15:41:02 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)" 85.154.191.178 - - [26/Oct/2013:15:41:02 +0200] "POST /eze/panel/entry.php HTTP/1.1" 302 - "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)" 85.154.191.178 - - [26/Oct/2013:15:41:03 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)" 94.201.237.81 - - [26/Oct/2013:15:41:03 +0200] "GET /eze/panel/config.bin HTTP/1.1" 302 - "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)" 85.154.191.178 - - [26/Oct/2013:15:41:03 +0200] "GET / HTTP/1.1" 503 41 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C)" </code></pre> <p>The GET requests are also requesting the whole index page everytime. This results in insane bandwidth usage.</p> <p>I tried:</p> <pre><code>&lt;IfModule mod_rewrite.c&gt; RewriteEngine On RewriteBase / RewriteCond %{REQUEST_METHOD} POST RewriteCond %{REQUEST_URI} /eze/panel/entry\.php RewriteRule .* - [F] &lt;/IfModule&gt; </code></pre> <p>But its not working. Can please somebody help me out to block all this nasty stuff.</p>
    singulars
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    plurals
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
    1. This table or related slice is empty.
 

Querying!

 
Guidance

SQuiL has stopped working due to an internal error.

If you are curious you may find further information in the browser console, which is accessible through the devtools (F12).

Reload