Quantcast
Channel: Software Support - PKP Community Forum
Viewing all articles
Browse latest Browse all 18210

Getting URL hits like (%20AND%205800=CONVERT(INT,(SELECT%20CHAR(113)+CHAR(113)+CHAR(113)+CHAR(118)+CHAR(113)CHAR(120)+CHAR(113)))download/12410/6133/26427/ HTTP/1.1" 404 696)

$
0
0

OJS-3.4.0.5

We are currently receiving repeated hits as shown below. Although I have blocked the relevant IPs, the Access Log continues to display similar activity.

I have tested the IP blocking, and it appears to be working as expected. However, the log entries indicate that these hits are still being registered.

Could you please advise on any additional measures we might take to prevent these entries from appearing?

92.255.57.151 - - [30/Oct/2024:15:01:00 +0530] "GET /index.php/MR/%22)%20AND%202522=2522%20AND%20(%22FPIb%22=%22FPIbarticle/view/78662/ HTTP/1.1" 403 288
92.255.57.151 - - [30/Oct/2024:15:01:00 +0530] "GET /index.php/IJAgS/-1091')%20OR%204353=(SELECT%20(CASE%20WHEN%20(4353=4353)%20THEN%204353%20ELSE%20(SELECT%201816%20UNION%20SELECT%204281)%20END))--%20BWNzarticle/download/68751/29300/172568/ HTTP/1.1" 403 360
92.255.57.151 - - [30/Oct/2024:15:01:01 +0530] "GET /ejournal/index.php/%22%20AND%201868=5586%20AND%20%22LmFn%22=%22LmFnIJF/article/download/30444/17819/ HTTP/1.1" 403 306
92.255.57.151 - - [30/Oct/2024:15:01:01 +0530] "GET /index.php/%25'%20AND%207692=UTL_INADDR.GET_HOST_ADDRESS(CHR(113)%7c%7cCHR(98)%7c%7cCHR(120)%7c%7cCHR(98)%7c%7cCHR(113)%7c%7c(SELECT%20(CASE%20WHEN%20(7692=7692)%20THEN%201%20ELSE%200%20END)%20FROM%20DUAL)%7c%7cCHR(113)%7c%7cCHR(107)%7c%7cCHR(106)%7c%7cCHR(122)%7c%7cCHR(113))%20AND%20'wOxg%25'='wOxgIJAnS/issue/view/2811/ HTTP/1.1" 403 451
92.255.57.151 - - [30/Oct/2024:15:01:01 +0530] "GET /index.php/%25';DECLARE%20@vktR%20NVARCHAR(4000);SET%20@vktR=(SELECT%20'qppjq'+(SELECT%20(CASE%20WHEN%20(1610=1610)%20THEN%20'1'%20ELSE%20'0'%20END))+'qxjqq');EXEC%20@vktR--PotatoJ/article/download/127181/49482/356656/ HTTP/1.1" 403 391
92.255.57.151 - - [30/Oct/2024:15:01:01 +0530] "GET /index.php/-3022%25'%20OR%202532=UTL_INADDR.GET_HOST_ADDRESS(CHR(113)%7c%7cCHR(120)%7c%7cCHR(118)%7c%7cCHR(107)%7c%7cCHR(113)%7c%7c(SELECT%20(CASE%20WHEN%20(2532=2532)%20THEN%201%20ELSE%200%20END)%20FROM%20DUAL)%7c%7cCHR(113)%7c%7cCHR(98)%7c%7cCHR(120)%7c%7cCHR(106)%7c%7cCHR(113))%20AND%20'CCmE%25'='CCmEIndHort/article/download/87716/35764/224824/ HTTP/1.1" 403 478
92.255.57.151 - - [30/Oct/2024:15:01:01 +0530] "GET /index.php/%22;SELECT%20DBMS_PIPE.RECEIVE_MESSAGE(CHR(119)%7c%7cCHR(119)%7c%7cCHR(80)%7c%7cCHR(107),32)%20FROM%20DUAL--IJF/article/download/11845/5661/25111/ HTTP/1.1" 403 343
92.255.57.151 - - [30/Oct/2024:15:01:02 +0530] "GET /index.php/IJAgS/-2042')%20OR%209919=(SELECT%20(CASE%20WHEN%20(9919=7855)%20THEN%209919%20ELSE%20(SELECT%207855%20UNION%20SELECT%208106)%20END))--%20ZcQzarticle/download/68751/29300/172568/ HTTP/1.1" 403 360



176.113.115.216 - - [29/Oct/2024:11:28:32 +0530] "GET /index.php/TJRP/article/')%20RLIKE%20(SELECT%20(CASE%20WHEN%20(5361=5361)%20THEN%20''%20ELSE%200x28%20END))%20AND%20('LWDy'='LWDyview/67882/ HTTP/1.1" 404 696
176.113.115.216 - - [29/Oct/2024:11:28:32 +0530] "GET /index.php/IJVA/article/-8792%25'%20OR%206802=(SELECT%20(CASE%20WHEN%20(6802=8242)%20THEN%206802%20ELSE%20(SELECT%208242%20UNION%20SELECT%205857)%20END))--%20frUZview/41350/ HTTP/1.1" 404 696
176.113.115.216 - - [29/Oct/2024:11:28:32 +0530] "GET /index.php/%22%20AND%208108=(SELECT%20(CASE%20WHEN%20(8108=8108)%20THEN%208108%20ELSE%20(SELECT%207109%20UNION%20SELECT%209476)%20END))--%20sOelIJAnS/article/download/48591/20864/385973/ HTTP/1.1" 404 1270
176.113.115.216 - - [29/Oct/2024:11:28:33 +0530] "GET /index.php/IJF/article/%25';DECLARE%20@tVEk%20NVARCHAR(4000);SET%20@tVEk=(SELECT%20'qqqvq'+(SELECT%20(CASE%20WHEN%20(6673=6673)%20THEN%20'1'%20ELSE%20'0'%20END))+'qpvxq');EXEC%20@tVEk--download/12410/6133/26427/ HTTP/1.1" 404 696

4 posts - 2 participants

Read full topic


Viewing all articles
Browse latest Browse all 18210

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>