Frage zu access.log und error.log
Posted: 2006-11-16 08:40
Hallo Community,
was zeigen mir folgende Einträge in meinen apache2 lgos:
error.log:
[Sat Nov 11 20:05:43 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde
[Sat Nov 11 20:05:43 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde2
[Sat Nov 11 20:05:44 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde3
[Sat Nov 11 20:05:45 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde-3.0.9
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.0
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.0-pl1
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.3-pl1
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.3
[Thu Nov 16 05:05:14 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/default.asp, referer: http://stmaryseattle.com/
[Thu Nov 16 05:05:17 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/fhome.asp, referer: http://stmaryseattle.com/
[Thu Nov 16 05:05:17 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/search.asp, referer: http://stmaryseattle.com/
[Thu Nov 16 05:05:18 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/search.asp, referer: http://stmaryseattle.com/
Komisch auch diese Einträge im access.log:
167.206.44.100 - - [16/Nov/2006:05:05:11 +0100] "GET http://www.murki.net/ HTTP/1.1" 200 679 "-" "-"
167.206.44.100 - - [16/Nov/2006:05:05:12 +0100] "GET http://www.selbsthilfe-lot.de/index2.ph ... &Itemid=46 HTTP/1.1" 404 1042 "-" "-"
167.206.44.100 - - [16/Nov/2006:05:05:14 +0100] "POST http://stmaryseattle.com/default.asp HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
167.206.44.100 - - [16/Nov/2006:05:05:17 +0100] "POST http://stmaryseattle.com/fhome.asp HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
167.206.44.100 - - [16/Nov/2006:05:05:17 +0100] "POST http://stmaryseattle.com/search.asp?mode=DoIt HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
167.206.44.100 - - [16/Nov/2006:05:05:18 +0100] "POST http://stmaryseattle.com/search.asp?mode=DoIt HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
Versucht hier ein Script Löcher zu finden? Einmal wird versucht auf Horde zuzugreifen, dann - der zweite Block - auf phpMyAdmin-Installationen. Ist hier Vorsicht geboten - waren das normale Scans - oder eine Vorbereitung für einen Angriff?
was zeigen mir folgende Einträge in meinen apache2 lgos:
error.log:
[Sat Nov 11 20:05:43 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde
[Sat Nov 11 20:05:43 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde2
[Sat Nov 11 20:05:44 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde3
[Sat Nov 11 20:05:45 2006] [error] [client 83.14.239.101] File does not exist: /home/httpd/vhosts/default/htdocs/horde-3.0.9
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.0
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.0-pl1
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.3-pl1
[Sun Nov 12 02:13:22 2006] [error] [client 213.251.166.26] File does not exist: /home/httpd/vhosts/default/htdocs/phpMyAdmin-2.6.3
[Thu Nov 16 05:05:14 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/default.asp, referer: http://stmaryseattle.com/
[Thu Nov 16 05:05:17 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/fhome.asp, referer: http://stmaryseattle.com/
[Thu Nov 16 05:05:17 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/search.asp, referer: http://stmaryseattle.com/
[Thu Nov 16 05:05:18 2006] [error] [client 167.206.44.100] File does not exist: /home/httpd/vhosts/default/htdocs/search.asp, referer: http://stmaryseattle.com/
Komisch auch diese Einträge im access.log:
167.206.44.100 - - [16/Nov/2006:05:05:11 +0100] "GET http://www.murki.net/ HTTP/1.1" 200 679 "-" "-"
167.206.44.100 - - [16/Nov/2006:05:05:12 +0100] "GET http://www.selbsthilfe-lot.de/index2.ph ... &Itemid=46 HTTP/1.1" 404 1042 "-" "-"
167.206.44.100 - - [16/Nov/2006:05:05:14 +0100] "POST http://stmaryseattle.com/default.asp HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
167.206.44.100 - - [16/Nov/2006:05:05:17 +0100] "POST http://stmaryseattle.com/fhome.asp HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
167.206.44.100 - - [16/Nov/2006:05:05:17 +0100] "POST http://stmaryseattle.com/search.asp?mode=DoIt HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
167.206.44.100 - - [16/Nov/2006:05:05:18 +0100] "POST http://stmaryseattle.com/search.asp?mode=DoIt HTTP/1.1" 404 1172 "http://stmaryseattle.com/" "-"
Versucht hier ein Script Löcher zu finden? Einmal wird versucht auf Horde zuzugreifen, dann - der zweite Block - auf phpMyAdmin-Installationen. Ist hier Vorsicht geboten - waren das normale Scans - oder eine Vorbereitung für einen Angriff?