[aprssig] Screen scraper

Andrew Rich vk4tec at tech-software.net
Mon Dec 19 21:58:44 EST 2005


all that has happened is some goose has opened it up and left it running.

I have killed of the target cgi's it should be immediate


-----------------------------------------
Andrew Rich - VK4TEC
vk4tec at tech-software.net <mailto:vk4tec at tech-software.net> 
www.tech-software.net
Brisbane AUSTRALIA 



-----Original Message-----
From: Steve Dimse [mailto:steve at dimse.com]
Sent: Tuesday, 20 December 2005 12:36 PM
To: vk4tec at tech-software.net
Cc: TAPR APRS Mailing List
Subject: Re: [aprssig] Screen scraper



On Dec 19, 2005, at 9:16 PM, Andrew Rich wrote:

> It was on call
>
> Just so many people tried it
>
> There is no looping

The same calls get hit over and over, in alphabetical order, for example

63.247.82.82 - - [20/Dec/2005:01:31:03 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2BHS&comma=1" 200 379 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:03 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2CMO-9&comma=1" 200 383 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:04 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2CPW-9&comma=1" 200 1092 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:04 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2CSU-1&comma=1" 200 383 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:05 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2CZZ&comma=1" 200 6687 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:05 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2DOR&comma=1" 200 379 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:06 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2DRK&comma=1" 200 379 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:06 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2EHQ&comma=1" 200 4167 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:07 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2EJC-3&comma=1" 200 383 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:07 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2EMD&comma=1" 200 2277 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:08 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2EMD-4&comma=1" 200 383 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:08 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2EMD-9&comma=1" 200 1140 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:09 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2GWK&comma=1" 200 6597 "-" "-"
63.247.82.82 - - [20/Dec/2005:01:31:09 +0000] "GET /cgi-bin/posit.cgi? 
call=VK2HIM-7&comma=1" 200 1570 "-" "-"

unless you want to tell me that VK hams are so organized that they  
all access the web in alphabetical order, two every second, it sure  
looks to me like your code is looping! If that isn't enough proof,  
the volume is unbelievable:

[root at loudmouth sdimse]# grep "63.247.82.82" /var/log/httpd/ 
access_log /var/log/httpd/access_log.1 | wc -l
   724438

Google Earth may be nice, but I have a hard time believing it has  
been accessed by aprs users 724,438 times in the last 8 days....

Steve K4HG






More information about the aprssig mailing list