ich bekomme im Apache Log immer sowas:
Code: Select all
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:21:36:12 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
gruß cirox
Code: Select all
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:21:36:12 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
Code: Select all
a2dismod
Which module would you like to disable?
Your choices are: actions cgid fastcgi include mod_python perl rewrite ssl suexec suphp userdir
Code: Select all
<Proxy *>
deny bla blub
</Proxy>
Code: Select all
www-data 27686 0.0 0.7 12780 7464 ? S Oct06 0:00 /usr/sbin/apache2
www-data 27687 0.0 0.7 12780 7476 ? S Oct06 0:00 /usr/sbin/fcgi-pm
web0 27688 0.0 0.3 8720 3764 ? Ss Oct06 0:00 /home/admin/php/b
web0 27689 0.0 0.3 8720 3768 ? S Oct06 0:00 /home/admin/php/b
web0 27690 0.0 0.3 8720 3768 ? S Oct06 0:00 /home/admin/php/b
web0 27691 0.0 0.3 8720 3768 ? S Oct06 0:00 /home/admin/php/b
web0 27692 0.0 0.3 8720 3768 ? S Oct06 0:00 /home/admin/php/b
denke auch das da jemand versucht Deine kiste als proxy zu missbrauchen, anscheinend klappts auch weil in Deinem log steht ja "200" also OK. kommt da nur "www.ebay.com" (was ja eventuell nur ein test sein koennte) oer auch sinnvolle URLs?cirox wrote: versteh aber den Sinn nicht. Weiss jemand was das ist?
Code: Select all
5.10.197.143 :: 85.10.91.154 - - [07/Oct/2006:22:06:40 +0200] "GET / HTTP/1.0" 200 242 "-" "-"
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:22:36:42 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:22:36:47 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:22:36:48 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:22:36:49 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
meine.ip :: 85.201.72.22 - - [07/Oct/2006:22:36:49 +0200] "GET / HTTP/1.0" 200 242 "-" "-"
www.ebay.com :: 124.8.9.113 - - [07/Oct/2006:22:36:50 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.yahoo.com :: 124.8.9.113 - - [07/Oct/2006:23:06:18 +0200] "GET http://www.yahoo.com/ HTTP/1.1" 200 1053 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.yahoo.com :: 124.8.9.113 - - [07/Oct/2006:23:36:18 +0200] "GET http://www.yahoo.com/ HTTP/1.1" 200 1053 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [08/Oct/2006:00:06:25 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [08/Oct/2006:00:06:26 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [08/Oct/2006:00:06:26 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [08/Oct/2006:00:06:27 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.yahoo.com :: 124.8.9.113 - - [08/Oct/2006:00:36:16 +0200] "GET http://www.yahoo.com/ HTTP/1.1" 200 1053 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
www.ebay.com :: 124.8.9.113 - - [08/Oct/2006:01:06:34 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:44 +0200] "GET /admin/phpmyadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:44 +0200] "GET /admin/phpMyAdmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:45 +0200] "GET /admin/sysadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:45 +0200] "GET /admin/sqladmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:45 +0200] "GET /admin/db/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:46 +0200] "GET /admin/web/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:46 +0200] "GET /admin/pMA/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:46 +0200] "GET /admin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:47 +0200] "GET /admin/mysql/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:47 +0200] "GET /admin/myadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:48 +0200] "GET /admin/webadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:48 +0200] "GET /admin/sqlweb/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:48 +0200] "GET /admin/websql/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:49 +0200] "GET /admin/webdb/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:49 +0200] "GET /admin/mysqladmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:49 +0200] "GET /admin/mysql-admin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:50 +0200] "GET /admin/phpmyadmin2/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:50 +0200] "GET /admin/php-my-admin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:50 +0200] "GET /admin/phpMyAdmin-2.2.3/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:51 +0200] "GET /admin/phpMyAdmin-2.2.6/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:51 +0200] "GET /admin/phpMyAdmin-2.5.1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:51 +0200] "GET /admin/phpMyAdmin-2.5.4/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:52 +0200] "GET /admin/phpMyAdmin-2.5.6/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:52 +0200] "GET /admin/phpMyAdmin-2.6.0/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:52 +0200] "GET /admin/phpMyAdmin-2.6.0-pl1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:53 +0200] "GET /admin/phpMyAdmin-2.6.2-rc1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:53 +0200] "GET /admin/phpMyAdmin-2.6.3/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:53 +0200] "GET /admin/phpMyAdmin-2.6.3-pl1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:54 +0200] "GET /admin/phpMyAdmin-2.6.3-rc1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:54 +0200] "GET /phpmyadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:55 +0200] "GET /phpMyAdmin/main.php HTTP/1.0" 500 1195 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:55 +0200] "GET /db/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:55 +0200] "GET /web/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:56 +0200] "GET /PMA/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:56 +0200] "GET /admin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:56 +0200] "GET /mysql/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:57 +0200] "GET /myadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:57 +0200] "GET /webadmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:57 +0200] "GET /sqlweb/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:58 +0200] "GET /websql/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:58 +0200] "GET /webdb/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:58 +0200] "GET /mysqladmin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:59 +0200] "GET /mysql-admin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:59 +0200] "GET /phpmyadmin2/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:24:59 +0200] "GET /php-my-admin/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:00 +0200] "GET /phpMyAdmin-2.2.3/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:00 +0200] "GET /phpMyAdmin-2.2.6/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:00 +0200] "GET /phpMyAdmin-2.5.1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:01 +0200] "GET /phpMyAdmin-2.5.4/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:01 +0200] "GET /phpMyAdmin-2.5.6/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:01 +0200] "GET /phpMyAdmin-2.6.0/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:02 +0200] "GET /phpMyAdmin-2.6.0-pl1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:02 +0200] "GET /phpMyAdmin-2.6.2-rc1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:02 +0200] "GET /phpMyAdmin-2.6.3/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:03 +0200] "GET /phpMyAdmin-2.6.3-pl1/main.php HTTP/1.0" 404 242 "-" "-"
meine.ip :: 66.46.87.202 - - [08/Oct/2006:01:25:03 +0200] "GET /phpMyAdmin-2.6.3-rc1/main.php HTTP/1.0" 404 242 "-" "-"
www.ebay.com :: 124.8.9.113 - - [08/Oct/2006:01:36:33 +0200] "GET http://www.ebay.com/ HTTP/1.1" 200 1052 "-" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98)"
die phpmyadmin-scans kannst Du ignorieren (solange Du keinen phpmyadmin ungesichert irgendwo laufen hast ;)cirox wrote:hier ein Auszug:
Code: Select all
telnet 127.0.0.1 80
GET http://www.ebay.com/ HTTP/1.1
Code: Select all
srv4:~# telnet 127.0.0.1 80
Trying 127.0.0.1...
Connected to 127.0.0.1.
Escape character is '^]'.
GET http://www.ebay.com/ HTTP/1.1
HTTP/1.1 400 Bad Request
Date: Sun, 08 Oct 2006 00:44:22 GMT
Server: Apache/2.0.54 (Debian GNU/Linux) mod_fastcgi/2.4.2 mod_python/3.1.3 Python/2.3.5 mod_ssl/2.0.54 OpenSSL/0.9.7e mod_perl/1.999.21 Perl/v5.8.4
Content-Length: 422
Connection: close
Content-Type: text/html; charset=iso-8859-1
<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">
<html><head>
<title>400 Bad Request</title>
</head><body>
<h1>Bad Request</h1>
<p>Your browser sent a request that this server could not understand.<br />
</p>
<hr>
<address>Apache/2.0.54 (Debian GNU/Linux) mod_fastcgi/2.4.2 mod_python/3.1.3 Python/2.3.5 mod_ssl/2.0.54 OpenSSL/0.9.7e mod_perl/1.999.21 Perl/v5.8.4 Server at www.ebay.com Port 80</address>
</body></html>
Connection closed by foreign host.
Code: Select all
<Location />
<Limit CONNECT>
Order deny,allow
Deny from all
</Limit>
</Location>
Falscher ISO/OSI-Layer. Die FORWARD-Policy von netfilter hat mit dem Apache httpd nichts zu tun und würde in diesem Fall nichts bringen.bad_brain wrote:ummm....weiss jetzt nicht ob ich daneben liege, aber könnte man das nicht auch unterbinden indem man die FORWARD-policy einfach auf DROP setzt?