freelance84 Posted March 29, 2011 Share Posted March 29, 2011 After having a look through the visitors to my site the other day i came across a rather dubious attempt... Host: 109.120.144.247 * /plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/tinybrowser.php?type=file&folder= Http Code: 404 Date: Mar 28 23:14:02 Http Version: HTTP/1.0 Size in Bytes: 2936 Referer: http://www.mysite.net/plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/tinybro Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90) /plugins/editors/tinymce/jscripts/tiny_mce/plugins/tinybrowser/tinybrowser.php?type=file&folder= This directory doesn't exist. I searched tiny_mce and it looks like it is some sort of editor. I also found this thread. Does anyone have any experience with what exactly this is? Has someone tried to hack my site? We did have a very odd issue with $_SESSION variables magically being unset... could these be linked? I shall shortly be moving onto my own server instead of using a shared one... am i to be entering a whole new world of security threats? Quote Link to comment Share on other sites More sharing options...
Philip Posted March 29, 2011 Share Posted March 29, 2011 TinyMCE is a JS WYSIWYG text editor. I've heard it's pretty secure from XSS attacks (of course without good server side it doesnt matter), and never had any problems with it myself. Do you have a lot of hits to 404 pages like that? Quote Link to comment Share on other sites More sharing options...
freelance84 Posted March 29, 2011 Author Share Posted March 29, 2011 Do you have a lot of hits to 404 pages like that?]Do you have a lot of hits to 404 pages like that? I get a few. Just looked at the %.... around 3% are 404's Why? I assume this is people/bots searching for files on my server that do not exist? Any 404's get redirected to the index though. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.