je suis victime depuis quelques temps de cette attaque sur mon site.
Grace aux renseignements de ce forum: (https://www.webmaster-hub.com/topic/40057-virus-d%C3%A9tect%C3%A9-par-avast-en-allant-sur-mon-propre-site/ j'ai peut être trouvé la (l'une des ?) faille sur mon site:
Je passait en paramètre dans l'url le nom de ma page à afficher. Mon script fesait un include du nom de ma pageconcaténé avec l'extention .php
J'ai donc créé un petit scrip affin de récuperer l'adresse ip de la personne essayant d'entrer un autre nom de page.
Je viens d'avoir dix tentatives d'attaques, voici ce que je récupère de deux de mes srcipt:
Alerte 1:
Le: 19/03/2008 à 19:17:43
Page Demandée:http://www.filter-international.com/about-us/ I
IP: 125.45.197.7FAI: hn.kd.ny.adsl
Utilisateur: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Alerte 2:
Le: 19/03/2008 à 19:07:50
Page Demandée:http://www.filter-international.com/about-us/ IP: 78.47.78.82FAI: static.82.78.47.78.clients.your-server.de
Utilisateur: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
J'ai aussitôt fait un tracage de l'adresse ip renvoyé par mon script et donc voici ce qu'on me donne:
[code] 78.47.78.82 - DE - GERMANY
static.82.78.47.78.clients.your-server.de.
Le serveur whois.ripe.net à retourné l'information suivante :
% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '78.47.78.80 - 78.47.78.87'
inetnum: 202.216.0.0 - 202.219.255.255
netname: JPNIC-NET-JP
descr: Japan Network Information Center
country: JP
admin-c: JNIC1-AP
tech-c: JNIC1-AP
remarks: JPNIC Allocation Block
remarks: Authoritative information regarding assignments and
remarks: allocations made from within this block can also be
remarks: queried at whois.nic.ad.jp. To obtain an English
remarks: output query whois -h whois.nic.ad.jp x.x.x.x/e
mnt-by: APNIC-HM
mnt-lower: MAINT-JPNIC
changed: apnic-ftp@nic.ad.jp 19991115
status: ALLOCATED PORTABLE
source: APNIC
role: Japan Network Information Center
address: Kokusai-Kougyou-Kanda Bldg 6F, 2-3-4 Uchi-Kanda
address: Chiyoda-ku, Tokyo 101-0047, Japan
country: JP
phone: +81-3-5297-2311
fax-no: +81-3-5297-2312
e-mail: hostmaster@nic.ad.jp
admin-c: JI13-AP
tech-c: JE53-AP
nic-hdl: JNIC1-AP
mnt-by: MAINT-JPNIC
changed: hm-changed@apnic.net 20041222
changed: hm-changed@apnic.net 20050324
changed: ip-apnic@nic.ad.jp 20051027
source: APNIC
inetnum: 202.216.176.0 - 202.216.191.255
netname: TAC-NET
descr: Tokoname New-TV Corporation
country: JP
admin-c: YF743JP
tech-c: YF743JP
remarks: This information has been partially mirrored by APNIC from
remarks: JPNIC. To obtain more specific information, please use the
remarks: JPNIC WHOIS Gateway at
remarks: https://www.nic.ad.jp/en/db/whois/en-gateway.html or
remarks: whois.nic.ad.jp for WHOIS client. (The WHOIS client
remarks: defaults to Japanese output, use the /e switch for English
remarks: output)
changed: apnic-ftp@nic.ad.jp 20030217
source: JPNIC
196.29.201.170 - MU -
Le serveur whois.arin.net à retourné l'information suivante :
OrgName: African Network Information Center
OrgID: AFRINIC
Address: 03B3 - 3rd Floor - Ebene Cyber Tower
Address: Cyber City
Address: Ebene
Address: Mauritius
City: Ebene
StateProv:
PostalCode: 0001
Country: MU
Le serveur whois.ripe.net à retourné l'information suivante :
% This is the RIPE Whois query server #2.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag
% Information related to '196.205.0.0 - 196.205.255.255'
inetnum: 196.205.0.0 - 196.205.255.255
org: ORG-AFNC1-RIPE
netname: AFRINIC-NET-TRANSFERRED-20050223
descr: This network has been transferred to AFRINIC
remarks: These IP addresses are assigned in the AFRINIC region.
remarks: Authoritative registration information for this network
remarks: is available for query and modification in
remarks: the AFRINIC whois database: whois.afrinic.net or
remarks: web site: https://www.afrinic.net/ remarks: The routing registry information (route(6) objects)
remarks: may be published in any Routing Registry, including
remarks: RIPE Whois Database
country: EU # country is really somewhere in African Region
admin-c: AFRI-RIPE
tech-c: AFRI-RIPE
status: ALLOCATED PA
mnt-by: RIPE-NCC-HM-MNT
mnt-routes: RIPE-NCC-RPSL-MNT
source: RIPE # Filtered
organisation: ORG-AFNC1-RIPE
org-name: African Internet Numbers Registry
org-type: RIR
address: see https://www.afrinic.net/ e-mail: bitbucket@ripe.net
admin-c: AFRI-RIPE
tech-c: AFRI-RIPE
remarks: For more information on AFRINIC assigned blocks, use
remarks: AFRINIC's whois database, whois.afrinic.net.
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered
role: The African Internet Numbers Registry
org: ORG-AFNC1-RIPE
address: AFRINIC, see https://www.afrinic.net/ admin-c: AFRI-RIPE
tech-c: AFRI-RIPE
nic-hdl: AFRI-RIPE
e-mail: bitbucket@ripe.net
remarks: For more information on AFRINIC assigned blocks, connect
remarks: to AFRINIC's whois database, whois.afrinic.net.
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered
person: sun ying
address: fu xing men nei da jie 97, Xicheng District
address: Beijing 100800
country: CN
phone: +86-10-66030657
fax-no: +86-10-66078815
e-mail: suny@publicf.bta.net.cn
nic-hdl: SY21-AP
mnt-by: MAINT-CNCGROUP-BJ
changed: suny@publicf.bta.net.cn 19980824
changed: hm-changed@apnic.net 20060717
source: APNIC
78.47.78.82 - DE - GERMANY
static.82.78.47.78.clients.your-server.de.
Le serveur whois.ripe.net à retourné l'information suivante :
% This is the RIPE Whois query server #3.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '78.47.78.80 - 78.47.78.87'
Pour info la page demandé était (http://) www.filter-international.com/webservice/aro/ipedido/a/ ou se situe un script php.
Ce site a a mon avis lui aussi été hacké.
Voila peut etre quelqu'un pourrat en dire plus :?: :?:
Je viens d'ouvrir mon ftp (Filezilla) et avant de me connecter à mon site, j'ai reçu l'alerte de ZoneAlarm:
FileZilla voulait se connecter à
213.239.222.5
hetzner.de
évidemment, j'ai interdit la connection (après quoi, je ne pouvais pas me connecter à mon site non plus).
Toute de suite, après l'alerte, j'ai redémarré Filezilla et "personne" ne guettait à ma porte cette fois-ci...
Juste pour info (ce site /hetzner/ figure également dans les rapports de "totor").
...en fait, quel programme espion ou autre intrus pourrait bien être à l'origine de cette tentative d'intrusion??
La réponse se cache peut-être par là: