LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-08-2014, 06:19 AM   #1
eudald
LQ Newbie
 
Registered: Apr 2014
Posts: 10

Rep: Reputation: 1
Requests from localhost (127.0.0.1) logged on access.log


Hello buddies,
I come here because I've been all the morning working around this with no solution at all.

It all has begun when one guy told me they found that we were trying to hack them. Their apache log told that the source IP where the attacks were coming from was one that belongs to one of our servers.

I started to check my logs and found that yesterday afternoon I had some logs on apache issued as:
127.0.0.1 - - [07/Sep/2014:18:39:07 +0200] "GET /mulberry-bag-collections.html?price=/proc/self/environ&style=56 HTTP/1.1" 404 497 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.2.14) Gecko/20110218 Firefox/3.6.14"

First, this folder doesn't exist. It's of course someone trying to exploit through php and get some data from the server, but what is concerning me the most is that it's being done in localhost! That means that somehow the server itself is executing the command (maybe through a script).

I checked all other logs (auth/syslog) and ensured there was no connection from other than my own IP address...
I also checked /tmp/ and all other places for any strange file
I also checked all crontabs

But in the end, nothing...
Is there anything else I could do?

Thanks!
Eudald
 
Old 09-09-2014, 03:14 PM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,149

Rep: Reputation: 1264Reputation: 1264Reputation: 1264Reputation: 1264Reputation: 1264Reputation: 1264Reputation: 1264Reputation: 1264Reputation: 1264
If they are going through php, then the request is most likely coming from a CGI hence it is running on localhost. Check the scripts in your webserver cgi-bin directory for any that can issue a request, and especially for any that should not be there.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh login requests from 127.0.0.1 dragon32 Linux - Security 6 06-02-2013 03:35 PM
localhost not working but 127.0.0.1 does xeross Linux - Networking 4 10-13-2008 03:30 PM
can't log into squirrelmail. error code "You must be logged in to access this page." rioguia Linux - Software 3 11-02-2004 10:47 AM
dns requests from localhost to localhost keex Linux - Networking 2 11-13-2003 01:47 PM
Localhost 127.0.0.1 may be forged ?? Mzee Linux - Networking 14 03-20-2003 01:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:29 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration