[NBLUG/talk] awstats

Troy Arnold troy at zenux.net
Wed Feb 16 23:20:02 PST 2005


To anyone using the awstats web statistics program... It's being
actively exploited right now, with bots checking for likely installation
locations.  Also it appears that this was how lugod.org's server was
recently compromised.

I mention this because I know that I've recommended that particular
piece of software here before. :-(

Personally, I took a variant of (Bob Blick's ?) nifty little honeypot
cgi and stuck it in /cgi-bin/awstats.pl.  That'll keep 'em busy for
awhile.


-t





More information about the talk mailing list