LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-16-2004, 07:26 PM   #1
s34n
Member
 
Registered: Jun 2003
Distribution: Slackware 9.1 / Debian Sid
Posts: 57

Rep: Reputation: 15
Apache acting as proxy ?


I've noticed a couple of entries in my apache access.log that make me suspicious .

This is my log format:
LogFormat "%h %l %u %t \"%!414r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" \"%{forensic-id}n\"" combined

Here are some snippits from the log,

218.150.163.30 - - [10/Oct/2004:16:57:01 -0400] "GET http://umsky.com/sproxy.php HTTP/1.0" 404 270 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)" "-"
68.33.241.67 - - [10/Oct/2004:18:09:55 -0400] "-" 414 337 "-" "-" "-"
68.33.241.67 - - [10/Oct/2004:19:50:01 -0400] "-" 414 337 "-" "-" "-"
68.51.99.132 - - [10/Oct/2004:20:27:15 -0400] "-" 414 337 "-" "-" "-"
218.66.37.66 - - [10/Oct/2004:23:30:41 -0400] "GET http://www.xlrwb.com/ HTTP/1.1" 200 2967 "-" "Mozilla/5.0 (compatible; MSIE 5.01; Win2000)" "-"
208.40.36.216 - - [11/Oct/2004:00:56:54 -0400] "CONNECT 1.3.3.7:1337 HTTP/1.0" 405 295 "-" "-" "-"


60.25.111.88 - - [16/Oct/2004:08:03:43 -0400] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600" "-"
68.206.181.112 - - [16/Oct/2004:08:12:52 -0400] "-" 414 337 "-" "-" "-"
200.73.65.5 - - [16/Oct/2004:08:33:00 -0400] "GET http://www.yahoo.com/ HTTP/1.0" 200 2967 "-" "Mozilla/4.0 [en] (Windows NT 5.0; I)" "-"
167.21.1.228 - - [16/Oct/2004:14:24:17 -0400] "GET / HTTP/1.1" 304 - "-" "Mozilla/4.0 (compatible" "-"

The ones that makes me curious are the "GET http://www.yahoo.com/ HTTP/1.0" and the "GET http://www.xlrwb.com/ HTTP/1.1" because they returned a status code of 200. Also the "OPTIONS /HTTP/1.1" returning a status of 200 doesn't seem right either, shouldn't they give something like a 404.

I should also note that the 2967 bytes is the size of my index page, and what is displayed in the log when someone requests it.

Would really appreciate if someone could shed some light on this.
 
Old 10-16-2004, 08:40 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
This is the default behavior when someone attempts to proxy and Apache has proxying off (which it is by default). The client attempting to proxy gets *your* default homepage instead of whatever content they were trying to get via proxy. The 200 status code can be confusing though.
 
Old 10-16-2004, 09:13 PM   #3
s34n
Member
 
Registered: Jun 2003
Distribution: Slackware 9.1 / Debian Sid
Posts: 57

Original Poster
Rep: Reputation: 15
Thanks for the reply Capt_Caveman, that eases my mind a bit.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
apache acting weird Red Squirrel Linux - Software 2 08-19-2005 08:47 PM
apache and proxy Mr.Ampersand() Linux - Software 3 03-03-2005 08:20 AM
VPN'ing through a RHL9 acting proxy nigelb Linux - Newbie 0 05-17-2004 05:24 AM
apache acting weird... Red Squirrel Linux - Newbie 1 03-03-2004 08:29 PM
Apache acting weird with index pages BlurredWeasel Linux - Software 1 11-30-2003 01:05 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration