Injection Conjecture

Discussion in 'General Chat' started by VSDan, Apr 20, 2008.

  1. #1
    I was just checking server logs (as I do several times a day looking for anything suspicious) when I found this:

    
    /phpld/?=Hello+everybody!%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-7.html+santa+fe+loan%2C++%3A-%5B%5B%5B%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-729.html+america+loan+motorcycle%2C++6015%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-445.html+business+government+loan+minority+woman%2C++rfz%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-461.html+car+loan+secure+title%2C++mkcbc%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-30.html+consumer+finance+leasing+loan%2C++vfyczl%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-141.html+corporation+history+home+loan+owner+teacher%2C++831%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-708.html+banks+who+give+bad+credit+personal+loan%2C++%25-P%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-364.html+in+lender+loan+nebraska+personal+subprime%2C++719016%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-369.html+gauranteed+loan%2C++%25-))%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-368.html+gauranteed+loan+student+texas%2C++%3D%5D%5D%5D%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-268.html+bad+credit+repo+cash+loan+auto%2C++371106%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-531.html+boise+loan+money+quick%2C++%3E%3ADD%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-802.html+american+equity+loan%2C++2618%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-431.html+mobile+home+loan+for+low+income%2C++950282%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-774.html+home+loan+first+time+buyer+indiana%2C++vwa%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-634.html+compare+cheap+loan%2C++%25-)%2C+http%3A%2F%2Fmipagina.americaonline.com.mx%2Fphlkepzvd%2Fapril-478.html+car+loan+hollister+california%2C++qnf%2C+ 
    
    Code (markup):
    An attempt to inject spam (and green eggs and ham). The desperation of some people. I don't know if they are trying to exploit the phpld/index.shtml SSI page, or it was targeted because of the php in the directory name, but pretty silly. But what is scary, is that so-o-o-o-o many websites out there are so easily exploited in this way or similar ways.
     
    VSDan, Apr 20, 2008 IP