webサーバのログの分析2025 2月分

2025-06-14 技術系

公開している web サーバのログから通常のアクセスではない通信について分析しました。
今月はWordPress関連が多かったです。

多かったリクエスト

WordPress関連

/wp-login.php
/post/wp-login.php
/wp-includes/widgets/include.php             
/wp-includes/images/include.php              
/wp-content/plugins/WordPressCore/include.php
/wp-content/themes/include.php 
/wp-content/plugins/include.php
/wp-content/plugins/core-plugin/include.php
/wp-admin/          
/wp-content/themes/ 
/wp-content/plugins/

PHPUnitのevalをリモート実行

PHPのユニットテストツールのPHPUnitの脆弱性を利用してのeval()を実行しようとする通信

JVNDB-2017-005280 - JVN iPedia - 脆弱性対策情報データベース

/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
/vendor/phpunit/src/Util/PHP/eval-stdin.php    
/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php
/vendor/phpunit/Util/PHP/eval-stdin.php                        
/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php         
/vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php     
/vendor/phpunit/phpunit/LICENSE/eval-stdin.php                 
/phpunit/src/Util/PHP/eval-stdin.php                           
/phpunit/phpunit/src/Util/PHP/eval-stdin.php                   
/phpunit/phpunit/Util/PHP/eval-stdin.php                       
/phpunit/Util/PHP/eval-stdin.php                               
/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/lib/phpunit/src/Util/PHP/eval-stdin.php                       
/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php               
/lib/phpunit/phpunit/Util/PHP/eval-stdin.php                   
/lib/phpunit/Util/PHP/eval-stdin.php                           
/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php    
/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php       
/ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php      
/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php      
/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php    
/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php       
/public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php     
/panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php      
/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php       
/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php       
/backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php     
/apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php       
/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php        
/admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php      

traffic-adviceへのアクセス

Google Chromeの機能でアクセスされるみたいです。
traffic-adviceへのアクセスが増加している件 〜Google Chromeの先読みの仕組みの話〜 | 株式会社フーリエ | Web戦略・システム開発[東京/浜松]

/.well-known/traffic-advice

Cisco 製 Cisco IOS XE などのネットワーク機器の Web UI の脆弱性

下記の記事のようなネットワーク機器のWeb UIにアクセスを試みる通信だと思われます。
Cisco 製 Cisco IOS XE の Web UI の脆弱性について(CVE-2023-20198 等) | 情報セキュリティ | IPA 独立行政法人 情報処理推進機構

/webui/

GeoServerの脆弱性を狙った通信

/geoserver/web/

不審な通信の一覧

uri count
/.env 636
/wp-login.php 284
/sw.js 284
/post/wp-login.php 273
/sellers.json 234
/ads.txt 231
/wp-includes/widgets/include.php 218
/wp-includes/images/include.php 218
/wp-content/plugins/WordPressCore/include.php 218
/.git/config 197
/.well-known/traffic-advice 142
/wp-content/themes/include.php 132
/wp-content/plugins/include.php 132
/t4 94
/admin/assets/js/views/login.js 91
/wp-content/plugins/core-plugin/include.php 86
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 76
/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh 76
mstshash=Administr 75
/api/.env 65
/login 64
/libs/js/iframe.js 57
/geoserver/web/ 55
/webui/ 54
/containers/json 54
/wp-content/uploads/ 53
/config.json 53
/wp-includes/ 52
/wp-content/ 52
/app-ads.txt 52
/.well-known/acme-challenge/ 52
/.well-known/ 52
/wp-admin/ 51
/wp-content/themes/ 50
/wp-content/plugins/ 50
/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/%%32%65%%32%65/bin/sh 49
/vendor/phpunit/src/Util/PHP/eval-stdin.php 47
/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php 47
/hello.world?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input 47
/actuator/gateway/routes 47
/vendor/phpunit/Util/PHP/eval-stdin.php 46
/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/vendor/phpunit/phpunit/LICENSE/eval-stdin.php 45
/phpunit/src/Util/PHP/eval-stdin.php 45
/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/phpunit/phpunit/Util/PHP/eval-stdin.php 45
/phpunit/Util/PHP/eval-stdin.php 45
/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/lib/phpunit/src/Util/PHP/eval-stdin.php 45
/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/lib/phpunit/phpunit/Util/PHP/eval-stdin.php 45
/lib/phpunit/Util/PHP/eval-stdin.php 45
/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 45
/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/css/ 44
/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 44
/.well-known/pki-validation/ 44
/v1/agent/service/register 43
/public/index.php?s=/index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello 43
/index.php?s=/index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=md5&vars[1][]=Hello 43
/index.php?lang=../../../../../../../../usr/local/lib/php/pearcmd&+config-create+/&/+/tmp/index1.php 43
/index.php?lang=../../../../../../../../tmp/index1 43
/workspace/drupal/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 42
/tags/centos 42
/V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php 42
/.aws/credentials 42
/admin/.env 41
/_profiler/phpinfo 41
/password/reset 40
/wp 38
/wordpress 38
/.env.production 38
/app/.env 36
/public/.env 35
/backend/.env 34
/teorema505?t=1 33
/phpinfo.php 33
/old 33
/new 33
/core/.env 33
/backup 33
/alive.php 33
/ab2h 33
/ab2g 33
/.env.save 33
/.env.bak 31
/phpinfo 30
/.env.prod 30
/.env.local 29
/upl.php 28
/systembc/password.php 28
/password.php 28
/main 28
/local/.env 28
/home 28
/geoip/ 28
/form.html 28
/bk 28
/bc 28
/1.php 28
/info.php 27
/config/.env 27
/tags/web 26
/old/.env 26
/crm/.env 26
/.env_sample 26
/.env.backup 26
/it-omurice.tokyo/.env 24
/about 24
/.env.stage 23
/.env.example 23
/media../.git/config 22
/laravel/.env 22
/apps/.env 22
/.well-known/security.txt 22
/files/.git/config 21
/new/.env 20
/dev/.git/config 20
/core/.git/config 20
/application/.env 20
/admin/.git/config 20
/src/.env 19
/prod/.env 19
/media/.git/config 19
/library/.env 19
/karma.conf.json 19
/conf/.env 19
/app/config/.env 19
/admin.php 19
/.env.development 19
/www/.env 18
/wp-content/.env 18
/wp-config.php 18
/settings/.env 18
/protected/.env 18
/php_info.php 18
/database/.env 18
/data/.git/config 18
/cgi-bin/.env 18
/base/.env 18
/.env.testing 18
/server_info.php 17
/sendgrid/.env 17
/config/.git/config 17
/config.js 17
/cgi-bin/luci/;stok=/locale 17
/backup/.git/config 17
/app_dev.php/_profiler/phpinfo 17
/app/.git/config 17
/actuator/health 17
/.env.old 17
/.AWS_/credentials 17
/wp-admin/js/about.php 16
/wp-admin/.env 16
/web/.env 16
/shell?cd+/tmp;rm+-rf+*;wget+ 16
/project/.git/config 16
/post/20241227/site_icons/icon-192x192.png 16
/docker/.env 16
/apple-touch-icon.png 16
/api/.git/config 16
/.well-known/acme-challenge/cloud.php 16
/.env.production.local 16
/wp-content/themes/seotheme/db.php?u 15
/vendor/.env 15
/test 15
/src/.git/config 15
/settings.py 15
/public/.git/config 15
/post/20250220 15
/index.js 15
/dev/.env 15
/aab9 15
//.env 15
/.git/HEAD 15
/.env.dist 15
/.env.dev 15
/www/.git/config 14
/test.php 14
/system/.env 14

follow us in feedly

comments powered by Disqus

関連記事

新着記事