default userpic

Possible Security Compromise?

Vote 0 Votes

Hello.

In my backend, i noticed there were heaps of search queries in my activity log

Search: query for 'world vision' 65.208.151.115 1 day ago
Search: query for 'sponsor' 65.208.151.117 1 day ago
Search: query for 'pet TV' 65.208.151.112 1 day ago

I noticed this a while back ago and disable the search box.

How did the searches appeared in the backend when I have no search box on the website?

In this something that I should worry about?

please help

thanks

Reported on Movable Type 4.2

5 Replies

| Add a Reply
  • Hi,

    You should not worry about that!

    Have you checked who is behind those IP addresses?

    Well, go here and check:

    http://whois.domaintools.com/65.208.151.115

    There is no security issue at all!

    You can endup having people do searches on your Web site from orphan pages that still contain the old search box etc.

    Cheers,
    Mihai

  • hello Mihai,

    Thanks you for your reply.

    There are a lot of it possibly hundreds everyday that have the same IP address right down to C block. ie 65.208.151.11x

    Can it be hacker trying to probe for vulnerabilities? what is this person doing?

    And how do I completely turn of off the search button (our blog is still new, search would probably worth turned off completely)..How do I find these orphan pages?

    thanks

    • Usually it is just a search engine or some robot indexing your site. If you want to know who they are, look them up.

      And how do I completely turn of off the search button (our blog is still new, search would probably worth turned off completely)..How do I find these orphan pages?

      There is a search widget in your widget listing. Just remove it and rebuild. Then log into your server and either rename mt-search.cgi or just run "chmod -x mt-search.cgi" to mark the file as non-executable on your host. That way, they can ping it all day long and it won't run.

  • Hiding the search box isn't enough to stop searching since the URL of the MT search script can be easily guessed. I suggest doing one of the following if it worries you:

    * Turn off execution permission to the search script: mt-search.cgi
    * Rename the script: mt-search.cgi.bak
    * Delete it entirely.

    This will truly shut down search if you are not using it.


  • Thanks for all the answers.

    If I removed off all of the seach, I am assuming it will not affect any of the search engine coming in for indexing.

    Secondly why is this happening in the first place? Is someone have too much time and probing for holes?

Add a Reply

If you need to share template code, replace all the "<" signs with "&lt;" or use this utility.

Forum Groups

86 302

Last Topic: website entries by masoud on Oct 26, 2011

1428 5075

Last Topic: Stupid Question? How to make a static homepage by Jeremy on Feb 3, 2012

693 2902

Last Topic: database upgrade hangs - upgrading to 4.37 by CrankyProfessor on Feb 1, 2012

84 291

Last Topic: How to have some other characters in entry basename automatically written by Afshin Haghighatnia on Dec 22, 2011

172 731

Last Topic: I Get An Error Whenever I Try to Log In by David Andrew Wiebe on Jan 17, 2012

189 559

Last Topic: Atom Feed by sali0023 on Feb 2, 2012

48 209

Last Topic: An idea and also a request by Afshin Haghighatnia on Jun 29, 2011

64 246

Last Topic: jQuery in MT 5.1 still at 1.4 - why? by perlmonkey on May 25, 2011

code.sixapart.com

137 478

Last Topic: Getting a thumbnail with xpath by Peter on Mar 13, 2011

221 710

Last Topic: Publish queue cache coherence issue by Istvan Kallai on Jan 27, 2012