off.php wtf?

Discussion in 'Apache' started by James M, Mar 28, 2008.

  1. #1
    I'm getting hundreds of thousands of requests to my web server for "off.php"

    something like this in my cron report:

    404 not found:
    /off.php?l=AR&d=6D207B2D709B48A0AFE386866A ... rvz2=0000832657: 1 Time(s)
    /off.php?l=AR&d=6D207B2D709B48A0AFE386866A ... rvz2=0000834359: 1 Time(s)

    and in my httpd logs: (hundreds of thousands of these from various hosts)

    [Sat Mar 29 08:55:51 2008] [error] [client 71.48.222.104] script '/var/www/html/off.php' not found or unable to stat

    It's obviously some kind of exploit that someone is trying to access which actually doesn't exist on my server.

    It's messing up my logs and makes reading my daily cron email a pain.

    Any suggestions on how to work around it? Maybe I should create an off.php file and redirect it elsewhere, or send it to /dev/null or something...
     
    James M, Mar 28, 2008 IP
  2. joebert

    joebert Well-Known Member

    Messages:
    2,150
    Likes Received:
    88
    Best Answers:
    0
    Trophy Points:
    145
    #2
    301 it to search results for your site.

    RewriteEngine On
    RewriteRule off\.php$ http://www.google.com/search?q=site%3Amysite.com+%22off.php%22 [NC,R=301]
    Code (markup):
     
    joebert, Mar 28, 2008 IP