Go to the FreeLists Home Page Home Signup Help Login
 



Browse dokuwiki: This Month's ArchiveMain Archive PageRelated postsPrevious by DateNext by Date

[dokuwiki] Re: attempt to use possible vulnerability of dokuwiki

  • From: Jonathan Dill <jonathan@xxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Wed, 06 Feb 2008 13:15:34 -0500
I plugged in some of the "search" strings at random to Google and there are thousands of reports of this type of activity, it does not appear to be targeted at dokuwiki, but any type of website. Some people have reported a Denial of Service with 20+ per second of this type of activity. I have not found a good explanation yet of what they appear to be trying to exploit.

For dokuwiki, the most common thing that I would expect is a POST with some sort of spamming or defacement, not a GET. Offhand, I would guess it is some type attempt at Buffer Overrun (BO) but I don't know what the actual target is.

Jonathan
--
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist

Other related posts:

  • [dokuwiki] attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki
  • [dokuwiki] Re: attempt to use possible vulnerability of dokuwiki




  • [ Home | Signup | Help | Login | Archives | Lists ]

    All trademarks and copyrights within the FreeLists archives are owned by their respective owners.
    Everything else ©2008 Avenir Technologies, LLC.