Hi. We have a joomla website and it seems to have a vonurebility in one of the plugin. We have now disable plugin but i want to understand what the hack means. What are they acheiving/doing. Below some example from the log. I have changed the domain name:
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:21 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:21 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:21 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:48:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:48:17 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
Can anyone out from this see what they are doing or get out if this hack
Thanks
Morten
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:39 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:36:40 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=www.ostgotatrafiken.se HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:21 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:21 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:21 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:22 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:46:23 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 81.17.20.38 - - [23/Nov/2014:09:47:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=imcute.yt HTTP/1.1" 503 308 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:48:15 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
domainname.com:80 23.95.12.146 - - [23/Nov/2014:09:48:17 +0100] "HEAD /plugins/system/plugin_googlemap2/plugin_googlemap2_proxy.php?url=ragerp.net HTTP/1.1" 200 190 "-" "Mozilla/5.0"
Can anyone out from this see what they are doing or get out if this hack
Thanks
Morten