Web Hosting Talk







View Full Version : strange logs to formmail.pl/cgi


iago
01-11-2003, 05:33 PM
Im getting this strange logs on my access_log file:

----------------------
cs26209-86.hot.rr.com - - [11/Jan/2003:15:28:42 -0600] "POST http://www.d.am/cgi-local/formmail.pl HTTP/1.0" 404 328 "http://www.d.am/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:32:04 -0600] "POST http://www.dbmslaw.com/cgi-bin/formmail.cgi HTTP/1.0" 404 327 "http://www.dbmslaw.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:32:14 -0600] "POST http://www.dbmslaw.com/cgi-bin/formmail.pl HTTP/1.0" 404 326 "http://www.dbmslaw.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:32:18 -0600] "POST http://www.dbmslaw.com/cgi-local/formmail.cgi HTTP/1.0" 404 329 "http://www.dbmslaw.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:32:19 -0600] "POST http://www.dbmslaw.com/cgi-local/formmail.pl HTTP/1.0" 404 328 "http://www.dbmslaw.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:32:19 -0600] "POST http://www.dbmslaw.com/cgi-local/formmail.pl HTTP/1.0" 404 328 "http://www.dbmslaw.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:35:51 -0600] "POST http://www.dinky-stories.com/cgi-bin/formmail.cgi HTTP/1.0" 404 327 "http://www.dinky-stories.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:35:55 -0600] "POST http://www.dinky-stories.com/cgi-bin/formmail.pl HTTP/1.0" 404 326 "http://www.dinky-stories.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:35:57 -0600] "POST http://www.dinky-stories.com/cgi-local/formmail.cgi HTTP/1.0" 404 329 "http://www.dinky-stories.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:35:58 -0600] "POST http://www.dinky-stories.com/cgi-local/formmail.pl HTTP/1.0" 404 328 "http://www.dinky-stories.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:39:45 -0600] "POST http://www.dragracingpinoy.com/cgi-bin/formmail.cgi HTTP/1.0" 404 327 "http://www.dragracingpinoy.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:39:46 -0600] "POST http://www.dragracingpinoy.com/cgi-bin/formmail.pl HTTP/1.0" 404 326 "http://www.dragracingpinoy.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:39:57 -0600] "POST http://www.dragracingpinoy.com/cgi-local/formmail.cgi HTTP/1.0" 404 329 "http://www.dragracingpinoy.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"
cs26209-86.hot.rr.com - - [11/Jan/2003:15:40:01 -0600] "POST http://www.dragracingpinoy.com/cgi-local/formmail.pl HTTP/1.0" 404 328 "http://www.dragracingpinoy.com/contact.htm" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 95)"

------------------------------------------

Any idea of what this could mean? Could this be a spammer trying to exploit a formail script? What about the "POST" instead of the "GET" tag? Should i block this address to access my server?

Hope somebody could shed some light with this issue?

iago
01-11-2003, 05:36 PM
this is some output from the error_log too:

-------------
[Sat Jan 11 15:43:50 2003] [error] [client 24.26.209.86] script not found or unable to stat: /home/httpd/cgi-bin/formmail.cgi
[Sat Jan 11 15:43:54 2003] [error] [client 24.26.209.86] script not found or unable to stat: /home/httpd/cgi-bin/formmail.pl
[Sat Jan 11 15:43:55 2003] [error] [client 24.26.209.86] File does not exist: /home/httpd/html/cgi-local/formmail.cgi
[Sat Jan 11 15:43:56 2003] [error] [client 24.26.209.86] File does not exist: /home/httpd/html/cgi-local/formmail.pl
[Sat Jan 11 15:47:46 2003] [error] [client 24.26.209.86] script not found or unable to stat: /home/httpd/cgi-bin/formmail.cgi
[Sat Jan 11 15:47:47 2003] [error] [client 24.26.209.86] script not found or unable to stat: /home/httpd/cgi-bin/formmail.pl
[Sat Jan 11 15:47:48 2003] [error] [client 24.26.209.86] File does not exist: /home/httpd/html/cgi-local/formmail.cgi
[Sat Jan 11 15:47:52 2003] [error] [client 24.26.209.86] File does not exist: /home/httpd/html/cgi-local/formmail.pl
---------------

bear
01-11-2003, 05:59 PM
Yes, looks like someone trying out your site(s) for an exploitable FormMail script. Using the POST method, they try to get a response fom FormMail, which will complain about missing information if you POST empty strings to it. 404 means they aren't locating it.
You can rewrite requests for FormMail to go somewhere else using ModRewrite. They get redirected, and your logs stop filling with errors. Or at least that's one method. If it's just the one IP, block it?