Коллеги, тут последние несколько дней кто-то видать пытается взломать сайтик мой.
error.log:[Mon Oct 04 02:30:07 2010] [error] [client 91.214.44.233] PHP Notice: Use of undefined constant _HASHCASH_ADMINMAILHEADER - assumed '_HASHCASH_ADMINMAILHEADER' in \\htdocs\\Administrator\\components\\com_securityimages\\class\\logUtils.php on line 94, referer: http://speedboy.ru/index.php?option=com_user&view=register
access.log с этого айпишника:
91.214.44.233 - - [04/Oct/2010:02:30:04 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:30:04 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:30:06 +0400] "GET /index.php?option=com_user&view=register HTTP/1.0" 200 14427
91.214.44.233 - - [04/Oct/2010:02:30:06 +0400] "POST /index.php?option=com_user HTTP/1.0" 200 14720
91.214.44.233 - - [04/Oct/2010:02:30:08 +0400] "GET /index.php?option=com_user&view=login&Itemid=19 HTTP/1.0" 200 13343
91.214.44.233 - - [04/Oct/2010:02:30:08 +0400] "POST /index.php?option=com_user&view=login&Itemid=19 HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:30:14 +0400] "GET /index.php HTTP/1.0" 200 31194
91.214.44.233 - - [04/Oct/2010:02:30:16 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:30:17 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:30:21 +0400] "GET /index.php?option=com_agora&task=forum&id=11&Itemid=25 HTTP/1.0" 200 35432
91.214.44.233 - - [04/Oct/2010:02:30:21 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:30:27 +0400] "GET /index.php?option=com_agora&task=forum&id=11&Itemid=25 HTTP/1.0" 200 35692
91.214.44.233 - - [04/Oct/2010:02:30:28 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:30:29 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:30:30 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:30:36 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 59222
91.214.44.233 - - [04/Oct/2010:02:30:37 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:30:38 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:30:39 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:30:44 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 59222
91.214.44.233 - - [04/Oct/2010:02:30:45 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:30:47 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:30:51 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:30:57 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 59222
91.214.44.233 - - [04/Oct/2010:02:30:58 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:30:59 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:31:00 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:31:06 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 59222
91.214.44.233 - - [04/Oct/2010:02:31:07 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:31:08 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:31:09 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:31:15 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 59222
91.214.44.233 - - [04/Oct/2010:02:31:15 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:31:18 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
91.214.44.233 - - [04/Oct/2010:02:31:19 +0400] "POST /index.php HTTP/1.0" 303 -
91.214.44.233 - - [04/Oct/2010:02:31:25 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 59222
91.214.44.233 - - [04/Oct/2010:02:31:27 +0400] "GET /index.php HTTP/1.0" 200 30934
91.214.44.233 - - [04/Oct/2010:02:31:28 +0400] "GET /index.php?option=com_agora&Itemid=25 HTTP/1.0" 200 58962
а вот что мне приходит в почту при этом:
<table><th><td><strong>ID:</strong></td><td><strong>Accepted:</strong></td><td><strong>Date:</strong></td><td><strong>IP:</strong>
</td><td><strong>UserAgent:</strong></td><td><strong>Referer:</strong></td><td><strong>Text:</strong></td><td><strong>Itemid:</strong>
</td></th><tr><td align='center'>1</td><td align='center'>No</td><td align='center'>2010-09-10 07:34:58</td>
<td align='center'>62.231.9.22</td><td align='center'>Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.2.9) Gecko/20100824 Firefox/3.6.9</td>
<td align='center'>http://speedboy.ru/index.php?option=com_user&view=register&Itemid=19</td>
<td align='left'></td><td align='center'>0</td></tr></table></body></html>
я смотрю, что при этом регается новый пользователь.
может в каком-то билде есть уязвимость на эту тему, поэтому и тыкают ?
бэкап есть на каждый день, если что. так что я не боюсь

ну и до кучи в error.log вот такая ошибочка есть:
[Sun Oct 03 08:18:37 2010] [error] [client 94.142.134.218] PHP Warning: htmlspecialchars(): Invalid multibyte sequence in argument in \\htdocs\\components\\com_agora\\include\\string.php on line 9, referer: http://speedboy.ru/index.php?option=com_agora&Itemid=25+++++++++++Result:+%E8%F1%EF%EE%EB%FC%E7%EE%E2%E0%ED+%ED%E8%EA%ED%E5%E9%EC+%22Henoaftetty%22;%E7%E0%F0%E5%E3%E8%F1%F2%F0%E8%F0%EE%E2%E0%EB%E8%F1%FC;%E2%EE%E7%EC%EE%E6%ED%EE,+%EE%F2%EF%F0%E0%E2%EB%E5%ED%EE;
даже не знаю, что бы это значило, но меня пугают эти +++++++++++ =)