Friday, April 06, 2007

A string of related PHP hacker IPs

Here are a string of hits in a row from IPs in different parts of the world requesting things that are not on our server. They are requesting a specific URL, not an IP address so this is not a DNS problem where someone pointed a domain to our IP by mistake. I believe our DNS servers are set up correctly as I just double checked everything but my hosting company has a propensity for screwing up DNS records so will have to check that again. However given what they are requesting I assume these are a bunch of related hacked IPs, probably controlled by a command and control bot somewhere.

"inetnum: 220.0.0.0 - 220.63.255.255
netname: BBTECH
descr: Japan nation-wide Network of SOFTBANK BB CORP
descr: Tokyo, Japan
country: JP
" 269236 BLOCKED 7i1768n6s9ky Thu Apr 05 07:10:31 PDT 2007 220.125.98.46 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/5/2007 7:10:31 AM 5 4 4/5/2007 7:10:31 AM
"inetnum: 218.144.0.0 - 218.159.255.255
netname: KORNET
descr: KOREA TELECOM
" 269235 BLOCKED 1n2q7vj1sj66u Thu Apr 05 07:10:28 PDT 2007 218.144.144.230 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/5/2007 7:10:29 AM 5 4 4/5/2007 7:10:29 AM
269234 BLOCKED 17fot0jc7s1g6 Thu Apr 05 07:10:26 PDT 2007 218.239.91.102 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/5/2007 7:10:27 AM 5 4 4/5/2007 7:10:27 AM
269233 BLOCKED 884p8rgc0r4b Thu Apr 05 07:10:24 PDT 2007 222.99.104.139 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/5/2007 7:10:25 AM 5 4 4/5/2007 7:10:25 AM
269232 BLOCKED g6t4qf5acgdc9 Thu Apr 05 07:10:22 PDT 2007 58.226.121.105 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:23 AM 5 4 4/5/2007 7:10:23 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 269231 BLOCKED 1q0g62wvk2a4 Thu Apr 05 07:10:18 PDT 2007 59.93.209.25 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:18 AM 5 4 4/5/2007 7:10:18 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 269231 BLOCKED 1q0g62wvk2a4 Thu Apr 05 07:10:18 PDT 2007 59.93.209.25 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:18 AM 5 4 4/5/2007 7:10:18 AM