Jump to content


VlexoFree Notice

Interviews will be open every Friday starting at 12am PDT and lasting for 24 hours.

- - - - -

Suspicious Awstats 404 Log


  • Please log in to reply
5 replies to this topic

#1 perishingflames

perishingflames

    Advanced Member

  • Members
  • 35 posts

Posted 07 January 2012 - 09:36 PM

Hi,

I noticed a bunch of requests for php my admin directories on my site in the Awstats 404 log that are being shown as referred from random directories of my site (like perishingflames.com/Fhjdh) that don't exist.

For example, /apps/phpAlbum/main.php has 18 hits

//phpMyAdmin/index.php has 4 (I didn't log in to cpanel during the time period)

//phpMyAdmin-2.6.3/scripts/setup.php has 2

//phpMyAdmin-2.8.1-rc1/scripts/setup.php has 1


and there are at least a hundred variations of those.


Is this anything to worry about or am I just being paranoid?



Also, while I have a thread open, is this anything to worry about?
Posted Image

Edited by perishingflames, 07 January 2012 - 09:39 PM.


Ad Bot


      #2 Eli L

      Eli L

        VlexoFree Owner

      • Owner
      • 6,950 posts
      • LocationWashington, USA

      Posted 08 January 2012 - 12:30 AM

      Are these requests coming from the same IP?

      Posted Image


      Please do not PM me for support (unless its a private matter). Instead, post in the appropriate forum and help will be provided accordingly.
      Helpful links: Terms of Service | Privacy Policy | Wiki - Tutorials & Help | VlexoFree Support |


      #3 perishingflames

      perishingflames

        Advanced Member

      • Members
      • 35 posts

      Posted 08 January 2012 - 12:43 AM

      Can you instruct me on how to find the IPs that accessed those pages? I downloaded the raw access log but that only does January and all the phpMyAdmin hits were from December.

      #4 Alex C.

      Alex C.

        Advanced Member

      • VlexoFree Support
      • 87 posts
      • LocationCleveland, OH, USA

      Posted 08 January 2012 - 06:27 AM

      Hello perishingflames,

      Go to "Raw Access Files" in CPanel. Check to see if their are archived copies on the bottom of the page.

      If so, Find the one in December and PM the file to either Me or Eli. Either one of us will take a look at the log.
      My Blog (Proudly Hosted on VlexoFree) : http://myacblog.tk
      --
      I try to help out the best I can on this forum! (However, Please don't PM me for support. Go here for that!)

      "True Value is in Every Person" - Myself

      #5 Eli L

      Eli L

        VlexoFree Owner

      • Owner
      • 6,950 posts
      • LocationWashington, USA

      Posted 08 January 2012 - 04:02 PM

      I would say dont worry about the hits. As long as the scripts on your site are up to date and you have a secure password you should be fine. Probably just some script kiddies looking for exploits.

      Posted Image


      Please do not PM me for support (unless its a private matter). Instead, post in the appropriate forum and help will be provided accordingly.
      Helpful links: Terms of Service | Privacy Policy | Wiki - Tutorials & Help | VlexoFree Support |


      #6 perishingflames

      perishingflames

        Advanced Member

      • Members
      • 35 posts

      Posted 08 January 2012 - 09:52 PM

      I don't have any archived logs. I set it up to do that in the future, though. Thanks for the help, I won't worry about it for now.




      0 user(s) are reading this topic

      0 members, 0 guests, 0 anonymous users