Michael Lazin on 4 Nov 2008 17:49:43 -0800


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: [PLUG] weird process?


I am not familiar with the .bs extension, but without the =http string a GET in the access logs was most likely not a successful hack, even if it is a 200, but I would be curious to see the whole log entry. 

On Tue, Nov 4, 2008 at 8:44 PM, George A. Theall <theall@tifaware.com> wrote:
On Tue, Nov 04, 2008 at 08:39:06PM -0500, Michael Lazin wrote:

>    Morpheus fucking scanner is pretty common in access logs, I see it a lot.

But specifically what is "GET /user/soapCaller.bs" trying to do?

George
--
theall@tifaware.com
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug



--
Michael Lazin
To gar auto estin noein te kai enai
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug