EXCEPTION_LOG analyse

Hallo leute,

wir hatten gestern in unserer EXCEPTION_LOG viele komische" einträge die ich nicht so richtig deuten kann aber es sieht irgend wie nach hackversuchen aus … Kann mir jemand vielleicht etwas dazu sagen

Hier ein kleiner auszug der EXCEPTION_LOG von gestern, die ganze log vom 17.11.16 umfasst knappe 50 mb und ist voll mit solchen einträgen. Was genau wurde da versucht und wie kann man sich evtl. schützen?

Faulty component --> -1 OR 2+328-328-1=0+0+0+1

oxSystemComponentException-oxException (time: 2016-11-17 09:07:03): [0]: ERROR_MESSAGE_SYSTEMCOMPONENT_FUNCTIONNOTFOUND
Stack Trace: #0 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(125): oxUtilsObject->_getObject(‘oxsystemcompone…’, 0, Array)
#1 [internal function]: oxUtilsObject->oxNew(‘oxSystemCompone…’)
#2 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#3 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxview.php(527): oxNew(‘oxSystemCompone…’)
#4 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(312): oxView->executeFunction(’-1’ OR 2+2…’)
#5 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(114): oxShopControl->_process(‘search’, ‘-1’ OR 2+2…’)
#6 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3/autoload/views/d3_oxshopcontrol_autoload.php(33): oxShopControl->start()
#7 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3log/views/d3_oxshopcontrol_errorhandler.php(14): d3_oxshopcontrol_autoload->start()
#8 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3clrtmp/views/d3_oxshopcontrol_clrtmp.php(19): d3_oxshopcontrol_errorhandler->start()
#9 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/index.php(103): d3_oxshopcontrol_clrtmp->start()
#10 {main}

Faulty component --> Vysr5kwY

oxSystemComponentException-oxException (time: 2016-11-17 07:02:03): [0]: ERROR_MESSAGE_SYSTEMCOMPONENT_FUNCTIONNOTFOUND
Stack Trace: #0 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(125): oxUtilsObject->_getObject(‘oxsystemcompone…’, 0, Array)
#1 [internal function]: oxUtilsObject->oxNew(‘oxSystemCompone…’)
#2 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#3 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxview.php(527): oxNew(‘oxSystemCompone…’)
#4 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(312): oxView->executeFunction(’’+response…’)
#5 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(114): oxShopControl->_process(‘alist’, ‘’+response…’)
#6 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3/autoload/views/d3_oxshopcontrol_autoload.php(33): oxShopControl->start()
#7 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3log/views/d3_oxshopcontrol_errorhandler.php(14): d3_oxshopcontrol_autoload->start()
#8 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3clrtmp/views/d3_oxshopcontrol_clrtmp.php(19): d3_oxshopcontrol_errorhandler->start()
#9 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/index.php(103): d3_oxshopcontrol_clrtmp->start()
#10 {main}

Faulty component --> custom/"+response.write(9308236*9457807)+"

oxSystemComponentException-oxException (time: 2016-11-17 07:12:53): [0]: EXCEPTION_SYSTEMCOMPONENT_CLASSNOTFOUND
Stack Trace: #0 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(125): oxUtilsObject->_getObject(‘oxsystemcompone…’, 0, Array)
#1 [internal function]: oxUtilsObject->oxNew(‘oxSystemCompone…’)
#2 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#3 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(115): oxNew(‘oxSystemCompone…’)
#4 [internal function]: oxUtilsObject->oxNew(’^(#[email protected]#$)(()))…’)
#5 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#6 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(357): oxNew(’^(#[email protected]#$)(()))
…’)
#7 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(309): oxShopControl->_initializeViewObject(’^(#[email protected]#$)(()))…’, ‘executefilter’)
#8 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(114): oxShopControl->_process(’^(#[email protected]#$)(()))
…’, ‘executefilter’)
#9 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3/autoload/views/d3_oxshopcontrol_autoload.php(33): oxShopControl->start()
#10 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3log/views/d3_oxshopcontrol_errorhandler.php(14): d3_oxshopcontrol_autoload->start()
#11 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3clrtmp/views/d3_oxshopcontrol_clrtmp.php(19): d3_oxshopcontrol_errorhandler->start()
#12 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/index.php(103): d3_oxshopcontrol_clrtmp->start()
#13 {main}

Faulty component --> ${@print(md5(acunetix_wvs_security_test))}\

oxSystemComponentException-oxException (time: 2016-11-17 07:17:34): [0]: EXCEPTION_SYSTEMCOMPONENT_CLASSNOTFOUND
Stack Trace: #0 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(125): oxUtilsObject->_getObject(‘oxsystemcompone…’, 0, Array)
#1 [internal function]: oxUtilsObject->oxNew(‘oxSystemCompone…’)
#2 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#3 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(115): oxNew(‘oxSystemCompone…’)
#4 [internal function]: oxUtilsObject->oxNew(’${@print(md5(ac…’)
#5 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#6 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(357): oxNew(’${@print(md5(ac…’)
#7 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(309): oxShopControl->_initializeViewObject(’${@print(md5(ac…’, ‘executefilter’)
#8 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(114): oxShopControl->_process(’${@print(md5(ac…’, ‘executefilter’)
#9 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3/autoload/views/d3_oxshopcontrol_autoload.php(33): oxShopControl->start()
#10 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3log/views/d3_oxshopcontrol_errorhandler.php(14): d3_oxshopcontrol_autoload->start()
#11 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3clrtmp/views/d3_oxshopcontrol_clrtmp.php(19): d3_oxshopcontrol_errorhandler->start()

Faulty component --> (select convert(int,CHAR(65)))

oxSystemComponentException-oxException (time: 2016-11-17 07:47:30): [0]: EXCEPTION_SYSTEMCOMPONENT_CLASSNOTFOUND
Stack Trace: #0 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(125): oxUtilsObject->_getObject(‘oxsystemcompone…’, 0, Array)
#1 [internal function]: oxUtilsObject->oxNew(‘oxSystemCompone…’)
#2 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#3 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxutilsobject.php(115): oxNew(‘oxSystemCompone…’)
#4 [internal function]: oxUtilsObject->oxNew(’…/…//…/…//…’)
#5 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/core/oxfunctions.php(316): call_user_func_array(Array, Array)
#6 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(357): oxNew(’…/…//…/…//…’)
#7 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(309): oxShopControl->_initializeViewObject(’…/…//…/…//…’, ‘executefilter’)
#8 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/views/oxshopcontrol.php(114): oxShopControl->_process(’…/…//…/…//…’, ‘executefilter’)
#9 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3/autoload/views/d3_oxshopcontrol_autoload.php(33): oxShopControl->start()
#10 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3log/views/d3_oxshopcontrol_errorhandler.php(14): d3_oxshopcontrol_autoload->start()
#11 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/modules/d3clrtmp/views/d3_oxshopcontrol_clrtmp.php(19): d3_oxshopcontrol_errorhandler->start()
#12 /var/www/vhosts/lvps92-51-115-74.dedicated.hosteurope.de/httpdocs/xyz/index.php(103): d3_oxshopcontrol_clrtmp->start()
#13 {main}

Das ist eine Suche nach Sicherheitslücken: http://www.acunetix.com/vulnerability-scanner/
In erster Linie sollten bei jeder Software die auf dem Server läuft verfügbare Updates bzw. Sicherheitspatches eingespielt werden.