Any tips on what to do with bogus hits?

Discussion in 'Site & Server Administration' started by TommyD, Apr 8, 2005.

  1. #1
    Hope this is in the right forum, figured it's a site admin question.

    I've seen request for cgi-bin/formmail.pl go up recently on several sites. I don't have form mail, but I was wondering, does anyone have tips how to utilitze these hits to their advantage?

    thanks,

    tom
     
    TommyD, Apr 8, 2005 IP
  2. DangerMouse

    DangerMouse Peon

    Messages:
    275
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Include them in you monthly 'hit report'... easy as ;)
     
    DangerMouse, Apr 8, 2005 IP
  3. hulkster

    hulkster Peon

    Messages:
    1,705
    Likes Received:
    93
    Best Answers:
    0
    Trophy Points:
    0
    #3
    In case you don't know, formmail.pl (and others) are popular CGI scripts that older versions had security holes in 'em ... so the auto-script-kiddies poke around for 'em ... I get these every day along with a slew of other attempted IIS exploits on my Apache web server ...
     
    hulkster, Apr 9, 2005 IP
  4. TommyD

    TommyD Peon

    Messages:
    1,397
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Thank you Alek,

    I understand what the file is for, I just want to add, I was told it isn't script kiddies only. Spammers go looking for this easy exploit so they can make a buck or two, and leave the account owner holding the spam bag.

    Now I see many office hacks/exploits being tested, with the formmail one, what do you do with them. I started redirecting them back to the home page, and was toying with the idea of forwarding them to some popup farm, or police agency.

    Any suggestions?

    tom
     
    TommyD, Apr 9, 2005 IP
  5. hulkster

    hulkster Peon

    Messages:
    1,705
    Likes Received:
    93
    Best Answers:
    0
    Trophy Points:
    0
    #5
    I redirect especially obnoxious User Agents to a file that basically says WTF. For stuff like formmail.pl, I just let it return file not found since this means they probably won't followup on it.
     
    hulkster, Apr 9, 2005 IP