spammer hacking asp and access files

spammer hacking asp and access files

am 24.09.2007 02:54:00 von riprod

I have had a couple of occasions where I found log entries like this :

2007-09-21 00:46:25 W3SVC849604990 PE2650 216.242.142.233 GET
/shopcontent.asp
type=%3ca+href%3d%22http%3a%2f%2fk2njydpenispumpgaga%2einfo% 2fpenis%2benlargement%2bpill%2fpenis%2benlargement%2bpill%2b testimonys%2ehtm%22%3epenis+enlargement+pill%3c%2fa%3e
80 - 74.6.28.233 HTTP/1.0
Mozilla/5.0+(compatible;+Yahoo!+Slurp;+http://help.yahoo.com /help/us/ysearch/slurp) - - www.cobbq.com 200 0 0 16159 370 2264

They appear to be from Yahoo's web crawler but are obviously attempting to
hack or spam my server.

I have blocked all 74.6.x.x IPs for now, until I can figure this out.

any ideas

Re: spammer hacking asp and access files

am 24.09.2007 05:05:03 von Ken Schaefer

I don't think they're trying to "hack" anything. Just get their spam into
your log files. Some websites display their logfiles, and obviously if you
did that then this spammer's spam would show up.

Cheers
Ken

--
My IIS Blog: www.adOpenStatic.com/cs/blogs/ken

"riprod" wrote in message
news:87CE630F-95AC-44E4-B389-AA1F66215E5E@microsoft.com...
>I have had a couple of occasions where I found log entries like this :
>
> 2007-09-21 00:46:25 W3SVC849604990 PE2650 216.242.142.233 GET
> /shopcontent.asp
> type=%3ca+href%3d%22http%3a%2f%2fk2njydpenispumpgaga%2einfo% 2fpenis%2benlargement%2bpill%2fpenis%2benlargement%2bpill%2b testimonys%2ehtm%22%3epenis+enlargement+pill%3c%2fa%3e
> 80 - 74.6.28.233 HTTP/1.0
> Mozilla/5.0+(compatible;+Yahoo!+Slurp;+http://help.yahoo.com /help/us/ysearch/slurp)
> - - www.cobbq.com 200 0 0 16159 370 2264
>
> They appear to be from Yahoo's web crawler but are obviously attempting to
> hack or spam my server.
>
> I have blocked all 74.6.x.x IPs for now, until I can figure this out.
>
> any ideas
>