odd web log entry

Ben Scott dragonhawk at gmail.com
Fri Aug 3 09:25:55 EDT 2007


On 8/3/07, Lloyd Kvam <python at venix.com> wrote:
> I assume this was an attempt to use my web server as a client proxy to
> reach a different site.

  Or perhaps a probe for some known vulnerability in that PHP script,
whatever it is.

  Either way, Googling for "proxygrade.php" seems to indicate it's a
commonly probed script.  Lots of similar web logs match.

  Anyone know of a good way to look-up these kinds of things?  That is
to say, when one sees what is apparently a probe or attach, is there
some website of signatures somewhere that one could check against,
and/or report possible new ones?  One could go hunting at the various
security sites, of course, but a better way would be nice.  :)

-- Ben


More information about the gnhlug-discuss mailing list