LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 06-07-2004, 01:57 PM   #1
Boss Hoss
Member
 
Registered: Sep 2003
Distribution: SuSe
Posts: 62

Rep: Reputation: 15
access_log entries & security


I'm seeing entries in my /var/log/httpd/access_log like this:

218.11.46.239 - - [07/Jun/2004:14:40:51 -0400] "GET http://surfcorp.com/s.php?uid=21030&...bmit=Go+now%21 HTTP/1.1" 404 305 "http://xxxadulthost.net/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows ME)"

So what exactly does this mean? Why is this showing up on my server logs? Is this the result of someone who has spyware on their browser? Can these "hits" result in high loading of my server?

Is this something I can stop with my firewall?
 
Old 06-09-2004, 06:06 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
218.11.46.239 - - [07/Jun/2004:14:40:51 -0400] "GET http://surfcorp.com/s.php?uid=21030...ubmit=Go+now%21 HTTP/1.1" 404 305 "http://xxxadulthost.net/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows ME)"
To read the line, read it like this (IIRC): remote_ip_address - - [date_format] "REQUEST_TYPE protocol://address" returncode request_size "referrer" "user_agent". Meaning (IIRC) someone tried to request something from surfcorp dot com (Surfcorp dot com being a pay per click search engine). See if you're not unwillingly opened up your Apache for proxying. Depending on what you serve for whom you can block access tru Apache, /etc/hosts.* and your firewall.
 
Old 06-09-2004, 10:05 PM   #3
Boss Hoss
Member
 
Registered: Sep 2003
Distribution: SuSe
Posts: 62

Original Poster
Rep: Reputation: 15
Quote:
See if you're not unwillingly opened up your Apache for proxying
So tell me what this means and how to check.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Odd security log entries while sleeping... aquaboot Ubuntu 3 08-21-2005 09:48 AM
apache access_log - connect & get xrado Linux - Networking 6 04-10-2005 07:07 AM
Maximum Number of Directory Entries & Performance aig Linux - General 1 07-09-2004 07:36 AM
Apache & IIS & security.... m_pahlevanzadeh Linux - Security 4 06-25-2003 01:51 PM
HTTP access_log: security breach? lhoff Linux - Security 3 02-16-2002 11:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 04:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration