06-10-31.Spamer第3次袭来!

日志分析

219.142.250.46 - - [31/Oct/2006:23:04:30 +0800] "GET /moin/UsenetTroll?action=AttachFile&do=del&target=b_9F9D4FFB7F3B520D.jpg HTTP/1.1" 200 11240 "http://wiki.woodpecker.org.cn/moin/UsenetTroll?action=info" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.7) Gecko/20061008 Firefox/1.5.0.7" 219.142.250.46 - - [31/Oct/2006:23:04:37 +0800] "GET /moin/FindPage HTTP/1.1" 200 19071 "http://wiki.woodpecker.org.cn/moin/UsenetTroll?action=AttachFile&do=del&target=b_9F9D4FFB7F3B520D.jpg" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.7) Gecko/20061008 Firefox/1.5.0.7" 219.142.250.46 - - [31/Oct/2006:23:08:05 +0800] "GET /moin/UsenetTroll HTTP/1.1" 200 18568 "http://wiki.woodpecker.org.cn/moin/RecentChanges" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.7) Gecko/20061008 Firefox/1.5.0.7" 219.142.250.46 - - [31/Oct/2006:23:08:08 +0800] "GET /moin/UsenetTroll?action=info HTTP/1.1" 200 21983 "http://wiki.woodpecker.org.cn/moin/UsenetTroll" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.7) Gecko/20061008 Firefox/1.5.0.7" 219.142.250.46 - - [31/Oct/2006:23:09:44 +0800] "GET /moin/UsenetTroll?action=diff&rev2=12&rev1=10 HTTP/1.1" 200 27499 "http://wiki.woodpecker.org.cn/moin/UsenetTroll?action=info" "Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.0.7) Gecko/20061008 Firefox/1.5.0.7" }}}

IP 追查

{{{> traceroute 219.142.250.46 traceroute to 219.142.250.46 (219.142.250.46), 64 hops max, 44 byte packets

10 bj141-130-98.bjtelecom.net (219.141.130.98) 3.528 ms 2.803 ms 2.677 ms 11 bj141-130-142.bjtelecom.net (219.141.130.142) 5.151 ms 4.655 ms 3.948 ms 12 219.142.250.46 (219.142.250.46) 5.334 ms 6.828 ms 5.566 ms 13 219.142.250.46 (219.142.250.46) 5.040 ms 10.212 ms 8.261 ms }}}

细节

attachment:061031-spam_844x656_scrot.png