nginx的日志显示有人一直在尝试访问phpMyAdmin的setup.php,用了各种位置。
其实我只有一个nginx,别的什么也没有。
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpmyadmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.0/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.7/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.1.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/pma/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:37 +0800] "GET http://abc.com:80/phpMyAdmin3/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/myadmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/MyAdmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/PHPMYADMIN/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/mysqladmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/SQL/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.5.5-pl1/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.5.5/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.5.4/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.5.7-pl1/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/admin/pma/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/phpMyAdmin-2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/web/phpMyAdmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/webadmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:38 +0800] "GET http://abc.com:80/admin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/dbadmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/mysql/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/phpMyAdmin2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/phpma/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/sqlweb/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/webdb/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/websql/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/_phpMyAdmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/php/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/admin/phpmyadmin/scripts/setup.txt HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/db/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/sqlmanager/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/mysqlmanager/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:39 +0800] "GET http://abc.com:80/phpmanager/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:40 +0800] "GET http://abc.com:80/php-myadmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:40 +0800] "GET http://abc.com:80/phpmy-admin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
47.99.136.156 - - [01:44:40 +0800] "GET http://abc.com:80/mysql-admin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
https://ip.teoh.io/47.99.136.156
情报显示此IP位于杭州,阿里云上的服务器。
还有另一个IP 8.130.126.73,也在不停的扫描。
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpmyadmin/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.4/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.3/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.10.0.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.10.3/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.8.0.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:38 +0800] "GET http://abc.com:80/phpMyAdmin-2.10.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
8.130.126.73 - - [01:47:39 +0800] "GET http://abc.com:80/phpMyAdmin-2.11.9.2/scripts/setup.php HTTP/1.0" 404 162 "-" "-"
同样是阿里云,不过是北京的。
https://ip.teoh.io/8.130.126.73