<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Autarchy of the Private Cave &#187; abuse</title> <atom:link href="https://bogdan.org.ua/tags/abuse/feed" rel="self" type="application/rss+xml" /><link>https://bogdan.org.ua</link> <description>Tiny bits of bioinformatics, [web-]programming etc</description> <lastBuildDate>Wed, 28 Dec 2022 16:09:04 +0000</lastBuildDate> <language>en-US</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>https://wordpress.org/?v=3.8.27</generator> <item><title>Does Google attack your servers, too?</title><link>https://bogdan.org.ua/2009/12/05/does-google-attack-your-servers-too.html</link> <comments>https://bogdan.org.ua/2009/12/05/does-google-attack-your-servers-too.html#comments</comments> <pubDate>Sat, 05 Dec 2009 12:28:34 +0000</pubDate> <dc:creator><![CDATA[Bogdan]]></dc:creator> <category><![CDATA[Misc]]></category> <category><![CDATA[Web]]></category> <category><![CDATA[abuse]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[google]]></category> <category><![CDATA[server]]></category> <guid
isPermaLink="false">http://bogdan.org.ua/?p=942</guid> <description><![CDATA[For about 2 weeks now, I am every day alerted of the suspicious behavior of some computer/server from the Google&#8217;s IP range: Dec 5 05:39:33 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;_REQUEST[option]&#8216; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;) Dec 5 05:39:33 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;_REQUEST[Itemid]&#8216; [&#8230;]]]></description> <content:encoded><![CDATA[<div
align="center"><img
src="http://bogdan.org.ua/wp-content/uploads/2009/12/evil-google.jpg" alt="Evil?" title="Evil?" width="276" height="135" class="aligncenter size-full wp-image-944" /></div><p>For about 2 weeks now, I am every day alerted of the suspicious behavior of some computer/server from the Google&#8217;s IP range:<br
/> <span
id="more-942"></span></p><blockquote><p> Dec  5 05:39:33 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;_REQUEST[option]&#8216; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:33 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;_REQUEST[Itemid]&#8216; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:33 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;GLOBALS&#8217; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:33 mx suhosin[3701]: ALERT &#8211; ASCII-NUL chars not allowed within request variables &#8211; dropped variable &#8216;mosConfig_absolute_path&#8217; (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:42 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;_REQUEST[option]&#8216; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:42 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;_REQUEST[Itemid]&#8216; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:42 mx suhosin[3701]: ALERT &#8211; tried to register forbidden variable &#8216;GLOBALS&#8217; through GET variables (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)<br
/> Dec  5 05:39:42 mx suhosin[3701]: ALERT &#8211; ASCII-NUL chars not allowed within request variables &#8211; dropped variable &#8216;mosConfig_absolute_path&#8217; (attacker &#8217;66.249.71.20&#8242;, file &#8216;html/index.php&#8217;)</p></blockquote><p>These requests repeat up to several hundred times per hour, with periods of no or very little malicious requests.</p><p>Here&#8217;s WHOIS information about 66.249.71.20:</p><blockquote><p> OrgName:    Google Inc.<br
/> OrgID:      GOGL<br
/> &#8230;<br
/> NetRange:   66.249.64.0 &#8211; 66.249.95.255<br
/> CIDR:       66.249.64.0/19<br
/> NetName:    GOOGLE<br
/> NetHandle:  NET-66-249-64-0-1<br
/> Parent:     NET-66-0-0-0-0</p></blockquote><p><strong>Does Google attack you, too?</strong></p><p>These attacks initially started from a different Google IP &#8211; 66.249.71.2; I wrote to abuse at google, and got an automated response with the ticket number (in the hundreds of millions range). A week after that, requests started flowing from IP 66.249.71.20. I am not inferring &#8220;evil Google abuse department&#8221; here, just that there was no response, and the problem shifted to a different IP from the Google&#8217;s IP range.</p><p><ins
datetime="2009-12-27T18:54:46+00:00">Update:</ins> I decided just to ignore this class of problems.</p><p><em>&#8220;Evil?&#8221; image by copyblogger.com.</em></p><p><a
class="a2a_button_citeulike" href="https://www.addtoany.com/add_to/citeulike?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F12%2F05%2Fdoes-google-attack-your-servers-too.html&amp;linkname=Does%20Google%20attack%20your%20servers%2C%20too%3F" title="CiteULike" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pocket" href="https://www.addtoany.com/add_to/pocket?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F12%2F05%2Fdoes-google-attack-your-servers-too.html&amp;linkname=Does%20Google%20attack%20your%20servers%2C%20too%3F" title="Pocket" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_kindle_it" href="https://www.addtoany.com/add_to/kindle_it?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F12%2F05%2Fdoes-google-attack-your-servers-too.html&amp;linkname=Does%20Google%20attack%20your%20servers%2C%20too%3F" title="Kindle It" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_evernote" href="https://www.addtoany.com/add_to/evernote?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F12%2F05%2Fdoes-google-attack-your-servers-too.html&amp;linkname=Does%20Google%20attack%20your%20servers%2C%20too%3F" title="Evernote" rel="nofollow noopener" target="_blank"></a><a
class="a2a_button_pinterest" href="https://www.addtoany.com/add_to/pinterest?linkurl=https%3A%2F%2Fbogdan.org.ua%2F2009%2F12%2F05%2Fdoes-google-attack-your-servers-too.html&amp;linkname=Does%20Google%20attack%20your%20servers%2C%20too%3F" title="Pinterest" rel="nofollow noopener" target="_blank"></a><a
class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share#url=https%3A%2F%2Fbogdan.org.ua%2F2009%2F12%2F05%2Fdoes-google-attack-your-servers-too.html&#038;title=Does%20Google%20attack%20your%20servers%2C%20too%3F" data-a2a-url="https://bogdan.org.ua/2009/12/05/does-google-attack-your-servers-too.html" data-a2a-title="Does Google attack your servers, too?"><img
src="https://static.addtoany.com/buttons/share_save_120_16.png" alt="Share"></a></p>]]></content:encoded> <wfw:commentRss>https://bogdan.org.ua/2009/12/05/does-google-attack-your-servers-too.html/feed</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>