Dear Hacker

Would the user of IP addresses 83.103.119.239 and 80.83.210.250 please stop attempting directory traversal attacks on my blog, there’s really nothing on it so it’s a little pointless and just generates emails from my IDS which waste my time!

Oh, and I’m not running TimThumb ;)

3 Responses to “Dear Hacker”

  1. Jesse says:

    Hear hear. I have learned that they go by “Scorpian” (oooh, scary!) and that they have the ingenious plan of replacing your index.php file with a more self-promoting one. Original!

  2. I’m getting the same message from the same two IP address. Are you using iPower as your host?

  3. rootEth says:

    No I’m not on iPower, they’re trying to exploit the vulnerability described at http://markmaunder.com/2011/08/01/zero-day-vulnerability-in-many-wordpress-themes/. I suspect they’re using google to find wordpress blogs and hitting them with a scripted attack.

Leave a Reply