I have noticed strange log activity on seven occasions over the past two weeks where it looks like someone is trying to hack in to my forum, thankfully being stopped.
I've tracked down the ip's and they seem to hit about 25 pages in a min. None of the seven attacks had a user agent or accept header and went straight for the forum.
They begin to spring my error catch because the login post data they are sending is garbage:
Type mismatch: 'CBool'
/forum/login_user.asp, line 95
Has anyone seen this on their forum or have anything to share.
Below is a clip of one of the log files where the instance occurred:
-Scott
2005-09-16 13:44:37 W3SVC987918689 WEB0006 216.21.198.111 GET /index.asp - 80 - 66.109.49.55 HTTP/1.1 - - -
www.mobilegear.biz 200 0 45844 85 2906
2005-09-16 13:44:49 W3SVC987918689 WEB0006 216.21.198.111 GET /videos/index.asp - 80 - 66.109.49.55 HTTP/1.1 - - -
www.mobilegear.biz 200 0 39566 92 187
2005-09-16 13:45:04 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 35921 991 1343
2005-09-16 13:45:14 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 37222 406 640
2005-09-16 13:45:26 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 35921 967 1093
2005-09-16 13:45:40 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 36235 418 3468
2005-09-16 13:45:53 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 35922 412 1312
22005-09-16 13:46:04 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 36017 1005 515
2005-09-16 13:46:16 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 36236 412 1078
2005-09-16 13:46:28 W3SVC987918689 WEB0006 216.21.198.111 POST /forum/login_user.asp |95|800a000d|Type_mismatch:_'CBool' 80 - 66.109.49.55 HTTP/1.1 - -
http://www.mobilegear.biz/ www.mobilegear.biz 500 0 35923 989 640