MyBB Community Forums

Full Version: Hackers? Two strange things in error log
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
[Fri Oct 24 09:43:00 2014] [error] [client 222.77.200.49] File does not exist: /home/sitedomain/public_html/403.shtml, referer: http://mysite.com/forum/+++++++++++++++++++++++++++++++++Result:+chosen+nickname+%22ljdedseyrolod%22;+registered+%28registering+only+mode+is+ON%29;+Result:+chosen+nickname+%22ljdwefdsyrohct%22;+registered+%28registering+only+mode+is+ON%29;

And hundreds of attempts from the same German IP to access robots.txt in the public_html base


[Fri Oct 24 10:01:57 2014] [error] [client 144.76.95.231] File does not exist: /home/sitedomain/public_html/robots.txt

Suspicious... Or just random bots?
robots.txt is a file that contains rules for search engine crawlers to follow when indexing your content. Not all search engines honor these rules, but the vast majority of the established ones will, so you will see a lot of requests to this file.
This is likely a bug in a spam bot, I've seen similar requests in the past.
http://stopforumspam.com/ipcheck/222.77.200.49
http://botscout.com/ipcheck.htm?ip=222.77.200.49

Definitely a spam bot. You may like to block the IP. Not that any harm will necessarily be done, but still, your system resources get wasted with these pesky bots floating around.
Thanks for the answers. Makes sense.

Though don't understand the 1st one. Very odd looking IMO. Looking for +++++++++++++++ and specific users? Maybe some spam bot..?

(2014-10-24, 02:24 PM)Diminished Wrote: [ -> ]http://stopforumspam.com/ipcheck/222.77.200.49
http://botscout.com/ipcheck.htm?ip=222.77.200.49

Definitely a spam bot. You may like to block the IP. Not that any harm will necessarily be done, but still, your system resources get wasted with these pesky bots floating around.

Ahhh... The first. Okay. Thanks Diminished.

And 2nd likely some search engine stuck looking for robots.txt? It's hundreds of times in just a minute or two.
(2014-10-24, 02:24 PM)DrXotick Wrote: [ -> ]And 2nd likely some search engine stuck looking for robots.txt? It's hundreds of times in just a minute or two.

Enter the 2nd IP in the browser URL bar and you'll see.
Thanks destroy. That's majestic.com "The planet's largest Link Index database "
You know that it's someone trying to compromise your site when you start seeing them attempting to use SQL and other similar things in the logs. Those guys can be so annoying -.-