Quote:
185.82.20.45 - - [19/Oct/2017:23:32:57 +0200] "GET /recover.php?wvstest=javascript:domxssExecutionSink (1,%22%3Cbr%3E()locxss%22)& HTTP/1.1" 200 2248 "http://www.acunetix-referrer.com/javascript:domxssExecutionSink(0,\x22<br>()refdxss \x22)" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:32:57 +0200] "GET /classcolor.php HTTP/1.1" 302 5 "https://kaffee-wellblech.org/recover.php?wvstest=javascript:domxssExecutionSink (1,%22%3Cbr%3E()locxss%22)&" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:32:57 +0200] "GET /anonymous.php HTTP/1.1" 200 1795 "https://kaffee-wellblech.org/recover.php?wvstest=javascript:domxssExecutionSink (1,%22%3Cbr%3E()locxss%22)&" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:32:57 +0200] "GET /pic/carbon/cellpic.gif HTTP/1.1" 200 906 "https://kaffee-wellblech.org/recover.php?wvstest=javascript:domxssExecutionSink (1,%22%3Cbr%3E()locxss%22)&" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:32:57 +0200] "GET /pic/loading.gif HTTP/1.1" 200 3522 "https://kaffee-wellblech.org/recover.php?wvstest=javascript:domxssExecutionSink(1,%22%3Cbr% 3E()locxss%22)&" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:32:57 +0200] "GET /pic/carbon/tablea.png HTTP/1.1" 200 2914 "https://kaffee-wellblech.org/recover.php?wvstest=javascript:domxssExecutionSink (1,%22%3Cbr%3E()locxss%22)&" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:33:04 +0200] "GET /highslide/graphics/loader.white.gif HTTP/1.1" 200 673 "https://kaffee-wellblech.org/recover.php?wvstest=javascript:domxssExecutionSink (1,%22%3Cbr%3E()locxss%22)&" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php/933120%40 HTTP/1.1" 404 191 "https://kaffee-wellblech.org:443/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /~recover.phpHlmYQ HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php?974505%40 HTTP/1.1" 200 2248 "https://kaffee-wellblech.org:443/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php?=997605%40 HTTP/1.1" 200 2248 "https://kaffee-wellblech.org:443/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php.bak HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php\x22906030%40 HTTP/1.1" 404 191 "https://kaffee-wellblech.org:443/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php.bac HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:09 +0200] "GET /recover.php_bak HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:10 +0200] "GET /recover.php_ HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:10 +0200] "GET /bak.recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:10 +0200] "GET /recover.php.BAK HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:10 +0200] "GET /recover.php.old HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:10 +0200] "GET /recover.php_old HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:11 +0200] "GET /old.recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:11 +0200] "GET /recover.php.orig HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:11 +0200] "GET /recover.php.tgz HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:11 +0200] "GET /recover.php.gz HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:11 +0200] "GET /recover.php.tar.gz HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:12 +0200] "GET /recover.php.bz2 HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:12 +0200] "GET /recover.php.tar.bz2 HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:12 +0200] "GET /recover.php.rar HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:12 +0200] "GET /recover.php.zip HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:12 +0200] "GET /recover.php.7z HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:12 +0200] "GET /recover.php.temp HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:13 +0200] "GET /recover.php.backup HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:13 +0200] "GET /recover.php.000 HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:13 +0200] "GET /recover.php.001 HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:13 +0200] "GET /recover.php%7e HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:13 +0200] "GET /%7erecover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:13 +0200] "GET /%21recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:14 +0200] "GET /recover.php%7e1 HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:14 +0200] "GET /recover.php.cs HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:14 +0200] "GET /recover.php.vb HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:15 +0200] "GET /recover.php.java HTTP/1.1" 404 191 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:16 +0200] "GET /Copy%20of%20recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:16 +0200] "GET /Copy%20of%20Copy%20of%20recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:16 +0200] "GET /Copy%20(2)%20of%20recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:16 +0200] "GET /Copy_(1)_of_recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:17 +0200] "GET /%21recover.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:37:27 +0200] "GET /recover.php HTTP/1.1" 200 2248 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:21 +0200] "POST /recover.php?-d+allow_url_include%3d1+-d+auto_prepend_file%3dphp://input HTTP/1.1" 200 2248 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?adm1n=1&kRbKjHXU=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?adm1n=true&0OZ0KXSq=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?adm1n=y&N2ZqnKap=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?adm1n=yes&G7rGkG7b=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?admin=1&on9QJtNM=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?admin=true&re0xzH5Y=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?admin=y&iLgKcLWF=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?admin=yes&Nm34XjAY=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?adm=1&9Ku23WDT=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:22 +0200] "POST /takebewerbung.php?adm=true&aZRj2EZG=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:23 +0200] "POST /takebewerbung.php?adm=y&DyHqL7CU=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
185.82.20.45 - - [19/Oct/2017:23:38:23 +0200] "POST /takebewerbung.php?adm=yes&x5TuCS2Y=1 HTTP/1.1" 200 1610 "https://kaffee-wellblech.org/recover.php" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36"
Am meisten mussten wir über Parameter wie "admin=1" lachen, vielen Dank dafür. Funktioniert sowas irgendwo? Sieht nach dem 08/15 Freeware Parametertester aus. Der test mit .old und so ist aber nur gute Idee, bei WoT funktioniert das bestimmt, Thor hat ja von jeder Datei 100.000 Versionen im Ordner liegen. Falls mal beim Copy-Paste was kaputt geht...