Forum Moderators: phranque
[edited by: phranque at 1:56 am (utc) on Dec 8, 2017]
[edit reason] exemplified domain [/edit]
14.215.176.12[22/Nov/2017:06:31:26GET /wp/tag/developer-android-com/&wd=test HTTP/1.140416905http://www.baidu.com/s?wd=RAAMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
14.215.176.4[23/Nov/2017:09:21:29GET /wp/tag/developer-android-com/&wd=test HTTP/1.140416905http://www.baidu.com/s?wd=EEHMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
111.206.36.17[23/Nov/2017:20:32:25GET /wp/tag/developer-android-com/&wd=test HTTP/1.140313http://www.baidu.com/s?wd=GISMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
180.97.35.36[28/Nov/2017:23:14:10GET /wp/?p=4054&indometacin-over-the-counter&wd=test HTTP/1.140313http://www.baidu.com/s?wd=6CJMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
123.125.143.151[30/Nov/2017:01:21:34GET /wp/?p=4054&indometacin-over-the-counter&wd=test HTTP/1.1301-http://www.baidu.com/s?wd=JVDWMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
123.125.143.151[30/Nov/2017:01:21:35GET /wp/2011/12/01/my-wordpress-blog-hijacked-the-pharma-hack/?indometacin-over-the-counter&wd=test HTTP/1.120045657http://www.baidu.com/s?wd=JVDWMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
115.239.212.197[30/Nov/2017:13:44:13GET /wp/tag/visaforchina-org/&wd=test HTTP/1.140416917http://www.baidu.com/s?wd=W9GMozilla/5.0 (Windows NT 6.1; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0 GET /wp/tag/developer-android-com/&wd=test HTTP/1.1404
GET /wp/wp-includes/js/wp-emoji-release.min.js?ver=4.9 HTTP/1.1200
GET /wp/wp-content/plugins/yet-another-related-posts-plugin/style/widget.css?ver=4.9 HTTP/1.1200
GET /wp/wp-includes/js/jquery/jquery.js?ver=1.12.4 HTTP/1.1200
GET /wp/wp-includes/css/dashicons.min.css?ver=4.9 HTTP/1.1200
GET /wp/wp-content/themes/ribosome-child/style.css?ver=1.0.0 HTTP/1.1200
GET /wp/wp-content/themes/ribosome/css/font-awesome-4.7.0/css/font-awesome.min.css?ver=4.9 HTTP/1.1200
GET /wp/wp-content/themes/ribosome/style.css?ver=4.9 HTTP/1.1200
GET /wp/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1 HTTP/1.1200
GET /wp/?p=4054&indometacin-over-the-counter&wd=test HTTP/1.1301
GET /wp/2011/12/01/my-wordpress-blog-hijacked-the-pharma-hack/?indometacin-over-the-counter&wd=test HTTP/1.1200
GET /wp/wp-content/themes/ribosome/style.css?ver=4.9.1 HTTP/1.1200
GET /wp/wp-content/themes/ribosome-child/style.css?ver=1.0.0 HTTP/1.1200
GET /wp/wp-includes/css/dashicons.min.css?ver=4.9.1 HTTP/1.1200
GET /wp/wp-includes/js/wp-emoji-release.min.js?ver=4.9.1 HTTP/1.1200
GET /wp/wp-content/plugins/yet-another-related-posts-plugin/style/widget.css?ver=4.9.1 HTTP/1.1200
GET /wp/wp-includes/js/wp-embed.min.js?ver=4.9.1 HTTP/1.1200
GET /wp/wp-content/themes/ribosome/css/font-awesome-4.7.0/css/font-awesome.min.css?ver=4.9.1 HTTP/1.1200
GET /wp/wp-content/plugins/yet-another-related-posts-plugin/style/related.css?ver=4.9.1 HTTP/1.1200
GET /wp/wp-content/themes/ribosome/js/ribosome-scripts-functions.js?ver=1.0.0 HTTP/1.1200
GET /wp/?live-comment-preview.js HTTP/1.1200
GET /wp/wp-content/plugins/akismet/_inc/form.js?ver=4.0.1 HTTP/1.1200
GET /wp/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1 HTTP/1.1200
GET /wp/wp-content/themes/ribosome/js/navigation.js?ver=20140711 HTTP/1.1200
GET /wp/wp-includes/js/jquery/jquery.js?ver=1.12.4 HTTP/1.1200
GET /wp/wp-content/themes/ribosome/css/font-awesome-4.7.0/fonts/fontawesome-webfont.woff?v=4.7.0 HTTP/1.1200
Here they target HTTP/1.1200, except for the first GET which goes after HTTP/1.1301Seems like “HTTP/1\.\d\d” in and of itself would be grounds for denial. I’ve never seen multiple decimal places in my life. (I’m on shared hosting. Is it the kind of thing they would block at the gate?) Are those even legitimate numbers, or is it another bizarre kind of typo? Looking it up, I find it only as a response header. Which, in turn, explains “1.1404” and “1.1200”.
GET /wp/2011/12/01/my-wordpress-blog-hijacked-the-pharma-hack/?indometacin-over-the-counter&wd=testSays it all, doesn’t it. They are going after javascript and css but no content.In the case of WP, aren’t these highly specialized script- or stylenames an indicator of exactly which plugins, addons, themes, skins and assorted software variations you’re using? It gives them information, but is liable to attract less attention than an up-front file request.
http://www.someplaceelse.com/IPaddress:<% =Request.ServerVariables("REMOTE_ADDR") %> I would create a directory named /information and in it place a redirect to the correct page
You could for example redirect to 127.0.0.1 or to their originating IP.Bad webmastering & unethical IMO.
In the unlikely event that they actually follow up on the redirect, this may even result in their getting kicked off a server that otherwise doesn't care what its users do. Very serious caution: Do not do thisSo why mention this in a public forum? You know someone will try this stupid trick.