Checks for "list.txt" on websites - why?

General discussion and chat (archived)
User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-19, 11:46

I noticed a lot of checks on my websites for "list.txt" in the root of the website. I've tried to find any information on that, but not getting any useful hits.

Does anyone know what checks for this file, why, and what is supposed to be in it?
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

Latitude

Re: Checks for "list.txt" on websites - why?

Unread post by Latitude » 2017-09-19, 13:39

Moonchild wrote:I noticed a lot of checks on my websites for "list.txt" in the root of the website.
What do you mean with "the website"? Palemoon.org?

Are your account hacked? You don't sound like Moonchild at all....

User avatar
Admin
Site Admin
Site Admin
Posts: 405
Joined: 2012-05-17, 19:06

Re: Checks for "list.txt" on websites - why?

Unread post by Admin » 2017-09-19, 13:50

Latitude wrote:Are your account hacked? You don't sound like Moonchild at all....
What does text sound like?

Anyway, this is a verified post by Moonchild.
Did you know that moral outrage triggers the pleasure centers of the brain? It's unlikely you can actually get addicted to outrage, but there is plausible evidence that you can become strongly predisposed to it.
Source: https://www.bbc.co.uk/programmes/p002w557/episodes/downloads - "The cooperative species" and "Behaving better online"
Image

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-19, 14:04

Latitude wrote:What do you mean with "the website"? Palemoon.org?
I mean all websites I host. "the website in question".

I'm assuming it's a bot of some sort that checks for this file, but I'm having the hardest time finding any sort of information on it.

And yeah rest assured my account has not been hacked ;) It's me!
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
adesh
Board Warrior
Board Warrior
Posts: 1277
Joined: 2017-06-06, 07:38

Re: Checks for "list.txt" on websites - why?

Unread post by adesh » 2017-09-19, 14:39

All websites? Maybe status monitoring from your VPS provider.

User avatar
satrow
Forum staff
Forum staff
Posts: 1885
Joined: 2011-09-08, 11:27

Re: Checks for "list.txt" on websites - why?

Unread post by satrow » 2017-09-19, 14:47

I wouldn't rule out some bot looking for a specific vuln. but their info was garbled during translation or misreading of a screenshot, eg. the original might be related to a ???_list.txt.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-19, 14:57

adesh wrote:All websites? Maybe status monitoring from your VPS provider.
No, that wouldn't make any sense. There's no reason for a VPS provider to make http(s) requests to VMs they employ - status monitoring of the VMs would be done with internal checks.
satrow wrote:I wouldn't rule out some bot looking for a specific vuln. but their info was garbled during translation or misreading of a screenshot, eg. the original might be related to a ???_list.txt.
I doubt it. the requests are specifically for "list.txt" in the web root, nothing else.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-19, 15:04

FTR, here's a log excerpt from the forum. IP addresses from Indonesia, Brazil, Honduras, Bulgaria and Russia. no real rhyme or reason to it far as I can tell.
2017/09/18 05:02:14 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:15 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:15 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:16 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:16 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:17 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:17 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 05:02:18 [error] 20945#20945: *56975 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 36.78.100.89, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:00 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:01 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:02 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:02 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:03 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:04 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:05 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:06 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:07 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 07:05:07 [error] 20945#20945: *67897 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.47.9.239, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 11:22:06 [error] 17895#17895: *1961 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 177.67.153.45, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 11:22:18 [error] 17897#17897: *1995 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 37.193.121.240, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 11:22:19 [error] 17896#17896: *2004 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 85.187.245.220, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:51 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:51 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:52 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:52 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:52 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:53 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:53 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:53 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:54 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
2017/09/18 15:05:54 [error] 27529#27529: *27210 open() "/srv/www/forum.palemoon.org/public_html/list.txt" failed (2: No such file or directory), client: 181.189.235.11, server: forum.palemoon.org, request: "GET /list.txt HTTP/1.1", host: "forum.palemoon.org"
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
satrow
Forum staff
Forum staff
Posts: 1885
Joined: 2011-09-08, 11:27

Re: Checks for "list.txt" on websites - why?

Unread post by satrow » 2017-09-19, 15:38

181.47.9.239, AR residential broadband and known proxy server, quite active over the last eight days, including what looks like a CN user several times on the 17th.

I'll try to find some space later to dig for dirt on the others.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-19, 18:03

So, likely checking for compromised servers via proxy?
Maybe I should create a list.txt with false data in it once we know what it's used for ;)
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
satrow
Forum staff
Forum staff
Posts: 1885
Joined: 2011-09-08, 11:27

Re: Checks for "list.txt" on websites - why?

Unread post by satrow » 2017-09-19, 20:31

Moonchild wrote:So, likely checking for compromised servers via proxy?
Yes, either compromised or open to some recently discovered vuln. is my guess, via a chain of non-Tor proxies to inhibit any track back yet minimise suspicion.

John connor

Re: Checks for "list.txt" on websites - why?

Unread post by John connor » 2017-09-20, 06:27

You might be interested in CIDRAM and Ninjafirewall. I use both and know the CIDRAM author. https://cidram.github.io/

Using these two websites I don't see anything reported.


https://www.abuseipdb.com/

http://www.blocklist.de/en/search.html? ... art+search

What was the user agent for these requests?

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-20, 09:22

John connor wrote:What was the user agent for these requests?
Various, so likely spoofed from a table of known ones. No referrers were sent, either.

193.188.254.67 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
61.7.186.96 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
182.160.124.29 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
212.22.86.114 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
188.211.224.162 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
201.249.88.35 - "Mozilla/5.0 (compatible; Googlebot/2.1;+http://www.google.com/bot.html)"
180.183.104.120 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.1)"
185.64.220.113 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
182.253.178.194 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; en) Opera 8.50"
193.93.228.209 - "Mozilla/5.0 (Windows NT 5.1; U) Opera 7.54 [ru]"
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

User avatar
satrow
Forum staff
Forum staff
Posts: 1885
Joined: 2011-09-08, 11:27

Re: Checks for "list.txt" on websites - why?

Unread post by satrow » 2017-09-20, 13:27

Excepting the ID IP 36.78.100.89, which might be too new on the scene to be sure of, the IPs are all flagged as static broadband from regular ISPs and proxy servers or network sharing devices.

User avatar
Moonchild
Pale Moon guru
Pale Moon guru
Posts: 35635
Joined: 2011-08-28, 17:27
Location: Motala, SE
Contact:

Re: Checks for "list.txt" on websites - why?

Unread post by Moonchild » 2017-09-20, 13:33

Definitely interesting. Ohwell, I'll just happily serve 404s to them; takes no resources to do so.
"Sometimes, the best way to get what you want is to be a good person." -- Louis Rossmann
"Seek wisdom, not knowledge. Knowledge is of the past; wisdom is of the future." -- Native American proverb
"Linux makes everything difficult." -- Lyceus Anubite

CharmCityCrab

Re: Checks for "list.txt" on websites - why?

Unread post by CharmCityCrab » 2017-09-20, 17:50

I wonder if list.txt is an evolution of urllist.txt?

https://www.drupal.org/project/urllist

CharmCityCrab

Re: Checks for "list.txt" on websites - why?

Unread post by CharmCityCrab » 2017-09-20, 18:05

A lot of the examples of "list.text" I'm seeing from websearchs are associated with torrent and piracy sites. Not sure if that helps or not. I figure it's worth throwing in as a datum point that might be combined with other information that someone comes across later to solve our mystery.

I tend not to want to click on those domains lest I find my computer hijacked to mine bitcoins or something. :) But if anyone regularly visits those type of sites anyway and wants to click and see what the lists actually have on them, that might help MoonChild out.

CharmCityCrab

Re: Checks for "list.txt" on websites - why?

Unread post by CharmCityCrab » 2017-09-20, 18:10

Here's one I found on a reputable site:

https://www.scribd.com/document/359053561/list.txt (redirects to the same URL, but with "list-txt" replacing "list.txt")

What they have on there is kind of interesting...

User avatar
satrow
Forum staff
Forum staff
Posts: 1885
Joined: 2011-09-08, 11:27

Re: Checks for "list.txt" on websites - why?

Unread post by satrow » 2017-09-20, 18:21

CharmCityCrab wrote:Here's one I found on a reputable site:

https://www.scribd.com/document/359053561/list.txt (redirects to the same URL, but with "list-txt" replacing "list.txt")

What they have on there is kind of interesting...
I think we might have a winner, good find.

I'll add that one of my checks on those IPs does list brute force attacks but none had been recorded for them.

dark_moon

Re: Checks for "list.txt" on websites - why?

Unread post by dark_moon » 2017-09-20, 19:37

I found that, maybe its related too?
"A list of working Pirate Bay proxy sites" (search result from DuckDuckGo)

Locked