Acunetix From 50.31.240.223

No replies
RaT
RaT's picture
Offline
SX High Council
Joined: 2008/03/12

One would think with all the lame Acunetix scans being posted, these kids would figure it out.

Looks like each one thinks maybe his/her magic copy of Acunetix will hack our site Tongue

50.31.240.223 - - [01/Jul/2013:08:57:13 -0400] "GET /acunetix-wvs-test-for-some-inexistent-file HTTP/1.1" 403 367 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:14 -0400] "GET / HTTP/1.1" 200 7438 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:14 -0400] "GET /F7Dm6EQ4 HTTP/1.1" 403 360 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:14 -0400] "GET /Kh5tRBoN HTTP/1.1" 403 360 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET /DGjnUitQ HTTP/1.1" 403 360 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET / HTTP/1.1" 403 404 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "CONNECT <a href="http://www.acunetix.wvs:443" title="443">www.acunetix.wvs:443</a> HTTP/1.1" 405 483 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET <a href="http://www.acunetix.wvs" title="http://www.acunetix.wvs">http://www.acunetix.wvs</a> HTTP/1.1" 200 723 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET /WebResource.axd?d=vWkpbCNE HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET /|~.aspx HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET /index HTTP/1.1" 406 691 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET /Account/Register.aspx?ReturnUrl= HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET /server-info HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "POST /console/j_security_check HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET / HTTP/1.1" 417 543 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /favicon.ico HTTP/1.1" 200 22695 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /robots.txt HTTP/1.1" 200 996 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /server-status HTTP/1.1" 403 699 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /clientaccesspolicy.xml HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /fGs7UGyCwc.cfm HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /inexistent_file_name.inexistent0123450987.cfm HTTP/1.1" 403 396 "-" "<script>alert(12345)</script>"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /crossdomain.xml HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /cZzoNS8Hp6.cfm HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:16 -0400] "GET / HTTP/1.1" 400 502 "-" "-"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /default HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /solr/select/?q=test HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /3W1rFANvyt HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /elmah.axd HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /fantastico_fileslist.txt HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /stronghold-info HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET <a href="http://soldierx.com/clientaccesspolicy.xml" title="http://soldierx.com/clientaccesspolicy.xml">http://soldierx.com/clientaccesspolicy.xml</a> HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:17 -0400] "GET /_vti_pvt/authors.pwd HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET /_vti_inf.html HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "POST /_vti_bin/shtml.exe?_vti_rpc HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET / HTTP/1.1" 200 7474 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET <a href="http://soldierx.com/crossdomain.xml" title="http://soldierx.com/crossdomain.xml">http://soldierx.com/crossdomain.xml</a> HTTP/1.1" 403 397 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET /long_inexistent_path12345_/Null.htw?CiWebhitsfile=:&CiRestriction=b&CiHiliteType=full HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET /stronghold-status HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET /3W1rFANvyt.php HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:18 -0400] "GET /web-console/Invoker HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"

This of course continued for some time...

50.31.240.223 - - [01/Jul/2013:08:57:24 -0400] "GET //config/database.yml_original HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:24 -0400] "GET /3W1rFANvyt.jhtml HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:24 -0400] "GET /webstat/ HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:24 -0400] "GET /update.php?op=../../../../../../../../../../etc/passwd%00.jpg HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:24 -0400] "GET /update.php?op=-1%20or%2015%3d0 HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:08:57:24 -0400] "GET /update.php?op=%0acat%20%2fetc%2fpasswd%0a HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:09:01:23 -0400] "GET /profiles/../profiles.tar HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
50.31.240.223 - - [01/Jul/2013:09:01:23 -0400] "GET /modules/types HTTP/1.1" 403 396 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"

I would post more, but by now everybody knows what an Acunetix scan looks like. All you have to do is monitor "/acunetix-wvs-test-for-some-inexistent-file" and you catch most of them.