Weird/Suspicious behaviour by blog user
-
I’ve had a few visits by a web user on one of my blogs that I was a bit strange and suspicious.
These are the access logs that I saw:
85.92.222.254 - - [11/May/2010:07:44:26 +0100] "GET /wp-admin HTTP/1.1" 301 568 "-" "Mozilla/4.0" 85.92.222.254 - - [11/May/2010:07:44:34 +0100] "GET / HTTP/1.1" 200 80831 "-" "Mozilla/4.0" 85.92.222.254 - - [13/May/2010:07:50:43 +0100] "GET /wp-admin/load-scripts.php HTTP/1.1" 403 497 "-" "Mozilla/4.0" 85.92.222.254 - - [13/May/2010:07:50:43 +0100] "GET /wp-admin/load-styles.php HTTP/1.1" 403 497 "-" "Mozilla/4.0" 85.92.222.254 - - [17/May/2010:07:52:52 +0100] "GET /wp-admin HTTP/1.1" 403 497 "-" "Mozilla/4.0" 85.92.222.254 - - [17/May/2010:07:53:00 +0100] "GET /wp-admin/load-styles.php HTTP/1.1" 403 497 "-" "Mozilla/4.0" 85.92.222.254 - - [17/May/2010:07:53:00 +0100] "GET / HTTP/1.1" 403 5233 "-" "Mozilla/4.0" 85.92.222.254 - - [17/May/2010:07:53:00 +0100] "GET /wp-admin/load-scripts.php HTTP/1.1" 403 497 "-" "Mozilla/4.0"
It looks like a robot of some kind – I can’t imagine a valid user accessing those pages. Does anyone know what they might be trying to achieve? or what they might of already achieved?
I’ve now blocked the IP using the .htaccess and my host turns ftp off by default.
Many Thanks.
Viewing 5 replies - 1 through 5 (of 5 total)
Viewing 5 replies - 1 through 5 (of 5 total)
- The topic ‘Weird/Suspicious behaviour by blog user’ is closed to new replies.