Would the user of IP addresses 83.103.119.239 and 80.83.210.250 please stop attempting directory traversal attacks on my blog, there’s really nothing on it so it’s a little pointless and just generates emails from my IDS which waste my time!
Oh, and I’m not running TimThumb
Hear hear. I have learned that they go by “Scorpian” (oooh, scary!) and that they have the ingenious plan of replacing your index.php file with a more self-promoting one. Original!
I’m getting the same message from the same two IP address. Are you using iPower as your host?
No I’m not on iPower, they’re trying to exploit the vulnerability described at http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/. I suspect they’re using google to find wordpress blogs and hitting them with a scripted attack.