Bluehost虚拟主机cPanel中有完备的日志体系,可以让你随时掌握网站受访、流量和错误状况,日志分别为:Lastest Visitors、Bandwith、Webalizer、Weblizer FTP、Raw Access Logs、Error Logs、Awstats。
从日志中找出了最近的恶意访问记录,归纳一下,文件和路径是下面的几种,采用的方式都是尝试直接下载。对于Bluehost虚拟主机用户,可能构成威胁的有下面几种:
/web.rar
/web.zip
/www.rar
/www.zip
/wwwroot.rar
/wwwroot.zip
全部文件和路径:
/admin/htmledit/db/ewebeditor.mdb
/admin/editor/db/ewebeditor.mdb
/admin/Databackup/NewCloud_Backup.MDB
/bbs/data/dvbbs7.mdb
/data/dvbbs7.mdb
/data/scadata.mdb
/database/PowerEasy2006.mdb
/eWebEditor/db/ewebeditor.mdb
/Foosun_Data/FS400.mdb
/FooSun_Data/FooSun_Data.mdb
/HSH.mdb
/HYTop.mdb
/KS_Data/KesionCMS4.mdb
/MirCMS_ADB.mdb
/mirserver.rar
/msmir_net.mdb
/msmir/msmir.mdb
/packet.mdb
/tomdb.mdb
/web.rar
/web.zip
/www.rar
/www.zip
/wwwroot.rar
/wwwroot.zip
恶意访问记录:
122.137.6.108 - - [14/May/2008:12:42:28 -0600] "GET /packet.mdb HTTP/1.1" 404 457 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:31 -0600] "GET /tomdb.mdb HTTP/1.1" 404 456 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:32 -0600] "GET /HSH.mdb HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:12 -0600] "GET /HYTop.mdb HTTP/1.1" 404 456 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:08 -0600] "GET /web.zip HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:09 -0600] "GET /www.rar HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:10 -0600] "GET /www.zip HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:10 -0600] "GET /wwwroot.rar HTTP/1.1" 404 458 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:11 -0600] "GET /wwwroot.zip HTTP/1.1" 404 458 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:12 -0600] "GET /HYTop.mdb HTTP/1.1" 404 456 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:13 -0600] "GET /packet.mdb HTTP/1.1" 404 457 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:14 -0600] "GET /tomdb.mdb HTTP/1.1" 404 456 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:15 -0600] "GET /HSH.mdb HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:16 -0600] "GET /data/scadata.mdb HTTP/1.1" 404 463 "-" "-"
61.191.228.125 - - [14/May/2008:14:14:01 -0600] "GET /database/PowerEasy2006.mdb HTTP/1.1" 404 473 "-" "-"
61.183.45.178 - - [15/May/2008:00:29:11 -0600] "GET /database/PowerEasy2006.mdb HTTP/1.1" 404 473 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:05 -0600] "GET /FooSun_Data/FooSun_Data.mdb HTTP/1.1" 404 474 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:06 -0600] "GET /Foosun_Data/FS400.mdb HTTP/1.1" 404 468 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:21 -0600] "GET /FooSun_Data/FooSun_Data.mdb HTTP/1.1" 404 474 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:22 -0600] "GET /Foosun_Data/FS400.mdb HTTP/1.1" 404 468 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:16 -0600] "GET /web.rar HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:19 -0600] "GET /web.zip HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:20 -0600] "GET /www.rar HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:21 -0600] "GET /www.zip HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:21 -0600] "GET /wwwroot.rar HTTP/1.1" 404 458 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:22 -0600] "GET /wwwroot.zip HTTP/1.1" 404 458 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:23 -0600] "GET /HYTop.mdb HTTP/1.1" 404 456 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:16 -0600] "GET /web.rar HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:19 -0600] "GET /web.zip HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:20 -0600] "GET /www.rar HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:21 -0600] "GET /www.zip HTTP/1.1" 404 454 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:21 -0600] "GET /wwwroot.rar HTTP/1.1" 404 458 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:22 -0600] "GET /wwwroot.zip HTTP/1.1" 404 458 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:23 -0600] "GET /HYTop.mdb HTTP/1.1" 404 456 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:28 -0600] "GET /packet.mdb HTTP/1.1" 404 457 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:31 -0600] "GET /tomdb.mdb HTTP/1.1" 404 456 "-" "-"
122.137.6.108 - - [14/May/2008:12:42:32 -0600] "GET /HSH.mdb HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:08 -0600] "GET /web.zip HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:09 -0600] "GET /www.rar HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:10 -0600] "GET /www.zip HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:10 -0600] "GET /wwwroot.rar HTTP/1.1" 404 458 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:11 -0600] "GET /wwwroot.zip HTTP/1.1" 404 458 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:12 -0600] "GET /HYTop.mdb HTTP/1.1" 404 456 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:13 -0600] "GET /packet.mdb HTTP/1.1" 404 457 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:14 -0600] "GET /tomdb.mdb HTTP/1.1" 404 456 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:15 -0600] "GET /HSH.mdb HTTP/1.1" 404 454 "-" "-"
58.51.63.120 - - [14/May/2008:13:23:16 -0600] "GET /data/scadata.mdb HTTP/1.1" 404 463 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:05 -0600] "GET /FooSun_Data/FooSun_Data.mdb HTTP/1.1" 404 474 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:06 -0600] "GET /Foosun_Data/FS400.mdb HTTP/1.1" 404 468 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:21 -0600] "GET /FooSun_Data/FooSun_Data.mdb HTTP/1.1" 404 474 "-" "-"
218.68.66.231 - - [15/May/2008:00:48:22 -0600] "GET /Foosun_Data/FS400.mdb HTTP/1.1" 404 468 "-" "-"
219.134.78.5 - - [14/May/2008:16:12:48 -0600] "GET /MirCMS_ADB.mdb HTTP/1.1" 302 703 "-" "-"
219.134.78.5 - - [14/May/2008:16:12:48 -0600] "GET /mirserver.rar HTTP/1.1" 302 703 "-" "-"
219.134.78.5 - - [14/May/2008:16:12:49 -0600] "GET /msmir_net.mdb HTTP/1.1" 302 703 "-" "-"
219.134.78.5 - - [14/May/2008:16:12:51 -0600] "GET /msmir/msmir.mdb HTTP/1.1" 302 703 "-" "-"
222.242.171.220 - - [14/May/2008:17:00:25 -0600] "GET /database/PowerEasy2006.mdb HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:48 -0600] "GET /wwwroot.rar HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:50 -0600] "GET /wwwroot.zip HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:51 -0600] "GET /HYTop.mdb HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:52 -0600] "GET /packet.mdb HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:53 -0600] "GET /tomdb.mdb HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:55 -0600] "GET /HSH.mdb HTTP/1.1" 302 703 "-" "-"
58.51.63.120 - - [14/May/2008:18:35:56 -0600] "GET /data/scadata.mdb HTTP/1.1" 302 703 "-" "-"
121.10.162.50 - - [14/May/2008:19:04:18 -0600] "GET /Foosun_Data/FS400.mdb HTTP/1.1" 302 703 "-" "-"
121.10.162.50 - - [14/May/2008:19:04:19 -0600] "GET /KS_Data/KesionCMS4.mdb HTTP/1.1" 302 703 "-" "-"
121.10.162.50 - - [14/May/2008:19:04:20 -0600] "GET /admin/Databackup/NewCloud_Backup.MDB HTTP/1.1" 302 703 "-" "-"
218.68.66.231 - - [15/May/2008:00:19:17 -0600] "GET /FooSun_Data/FooSun_Data.mdb HTTP/1.1" 302 703 "-" "-"
218.68.66.231 - - [15/May/2008:00:19:18 -0600] "GET /Foosun_Data/FS400.mdb HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:46:50 -0600] "GET /web.zip HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:46:51 -0600] "GET /www.rar HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:46:52 -0600] "GET /www.zip HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:46:56 -0600] "GET /wwwroot.rar HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:47:01 -0600] "GET /wwwroot.zip HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:47:05 -0600] "GET /HYTop.mdb HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:47:06 -0600] "GET /packet.mdb HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:47:07 -0600] "GET /tomdb.mdb HTTP/1.1" 302 703 "-" "-"
59.60.129.197 - - [15/May/2008:01:47:09 -0600] "GET /HSH.mdb HTTP/1.1" 302 703 "-" "-"
58.218.96.51 - - [15/May/2008:02:52:36 -0600] "GET /eWebEditor/db/ewebeditor.mdb HTTP/1.1" 302 699 "-" "-"
58.218.96.51 - - [15/May/2008:02:52:37 -0600] "GET /admin/htmledit/db/ewebeditor.mdb HTTP/1.1" 302 699 "-" "-
58.218.96.51 - - [15/May/2008:02:52:40 -0600] "GET /admin/editor/db/ewebeditor.mdb HTTP/1.1" 302 699 "-" "-"
58.51.63.120 - - [14/May/2008:18:16:58 -0600] "GET /packet.mdb HTTP/1.1" 404 622 "-" "-"
"
58.51.63.120 - - [14/May/2008:18:16:59 -0600] "GET /tomdb.mdb HTTP/1.1" 404 622 "-" "-"
58.51.63.120 - - [14/May/2008:18:17:00 -0600] "GET /HSH.mdb HTTP/1.1" 404 622 "-" "-"
58.51.63.120 - - [14/May/2008:18:17:01 -0600] "GET /data/scadata.mdb HTTP/1.1" 404 622 "-" "-"
59.40.179.208 - - [14/May/2008:20:33:22 -0600] "GET /bbs/data/dvbbs7.mdb HTTP/1.1" 302 703 "-" "-"
59.40.179.208 - - [14/May/2008:20:33:22 -0600] "GET /data/dvbbs7.mdb HTTP/1.1" 404 622 "-" "-"
58.51.63.120 - - [14/May/2008:23:23:31 -0600] "GET /HYTop.mdb HTTP/1.1" 404 622 "-" "-"
58.51.63.120 - - [14/May/2008:23:23:33 -0600] "GET /packet.mdb HTTP/1.1" 404 622 "-" "-"