LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-30-2012, 03:04 AM   #1
ramecare
Member
 
Registered: Feb 2011
Posts: 179

Rep: Reputation: 0
Server log


Dear all,

In my server iam the below log in /var/log/messages and i doubt that some unautherized user is accessing my server and can any one give explain about the below log

/var/log/messages

Mar 29 18:21:33 p2234270 zmeu: gethostby*.getanswer: asked for "ip134.67-202-114.static.steadfast.net IN A", got type "39"
Mar 29 18:21:33 p2234270 zmeu: gethostby*.getanswer: asked for "ip52.67-202-124.static.steadfast.net IN A", got type "39"

In /var/log/httpd/access_log

207.44.254.242 - - [30/Mar/2012:02:48:36 -0500] "GET /cs/Satellite/index.html HTTP/1.0" 403 302 "-" "-"
207.44.254.242 - - [30/Mar/2012:02:51:05 -0500] "GET /.ba/ba.php HTTP/1.0" 403 298 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:42 -0500] "GET //mysqladmin/scripts/setup.php HTTP/1.1" 403 255 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:42 -0500] "GET //pHpMyAdMiN/scripts/setup.php HTTP/1.1" 403 255 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:42 -0500] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 403 253 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:42 -0500] "GET //phpMyAdmin1/scripts/setup.php HTTP/1.1" 403 255 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:43 -0500] "GET //phpmy/scripts/setup.php HTTP/1.1" 403 250 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:43 -0500] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 404 251 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:43 -0500] "GET //dbadmin/scripts/setup.php HTTP/1.1" 403 252 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:43 -0500] "GET //MySQLAdmin/scripts/setup.php HTTP/1.1" 403 256 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:43 -0500] "GET //SQL/scripts/setup.php HTTP/1.1" 403 250 "-" "-"
127.0.0.1 - - [30/Mar/2012:02:03:43 -0500] "GET //web/phpmyadmin/scripts/setup.php HTTP/1.1" 403 257 "-" "-"
::1 - - [30/Mar/2012:02:03:44 -0500] "OPTIONS * HTTP/1.0" 403 297 "-" "Apache/2.2.3 (CentOS) (internal dummy connection)"
::1 - - [30/Mar/2012:02:03:45 -0500] "OPTIONS * HTTP/1.0" 403 297 "-" "Apache/2.2.3 (CentOS) (internal dummy connection)"
::1 - - [30/Mar/2012:02:03:46 -0500] "OPTIONS * HTTP/1.0" 403 297 "-" "Apache/2.2.3 (CentOS) (internal dummy connection)
66.150.14.182 - - [30/Mar/2012:01:54:40 -0500] "GET /ATutor/content/paypallogin/de/webscr.htm?cmd=SignIn&co_partnerId=2&pUserId=&siteid=0&pageType=&pa1=&i1=&bshowgif=&UsingSSL=&ru=&pp =&pa2=&errmsg=&runameMessage-ID: HTTP/1.1" 403 319 "-" "Mozilla/6.0 (compatible; MSIE 7.01; Windows NT)"
99.41.69.231 - - [30/Mar/2012:02:46:35 -0500] "GET /.ii/ii.php HTTP/1.1" 403 299 "-" "curl/7.18.0 (x86_64-pc-linux-gnu) libcurl/7.18.0 OpenSSL/0.9.8g zlib/1.2.3.3 libidn/1.1"
207.44.254.242 - - [30/Mar/2012:02:48:36 -0500] "GET /cs/Satellite/index.html HTTP/1.0" 403 302 "-" "-"
207.44.254.242 - - [30/Mar/2012:02:51:05 -0500] "GET /.ba/ba.php HTTP/1.0" 403 298 "-" "-"
61.139.105.164 - - [30/Mar/2012:03:06:14 -0500] "GET http://proxyjudge3.proxyfire.net/fastenv HTTP/1.1" 403 299 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0)"

127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpMyAdmin/scripts/setup.php HTTP/1.1" 403 250 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpMyAdmin1/scripts/setup.php HTTP/1.1" 403 251 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpMyAdmin2/scripts/setup.php HTTP/1.1" 403 251 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpadmin/scripts/setup.php HTTP/1.1" 403 248 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpmy/scripts/setup.php HTTP/1.1" 403 246 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpmyadmin/scripts/setup.php HTTP/1.1" 404 246 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //pma/scripts/setup.php HTTP/1.1" 403 245 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //phpAdmin/scripts/setup.php HTTP/1.1" 403 248 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //dbadmin/scripts/setup.php HTTP/1.1" 403 248 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //MySQLAdmin/scripts/setup.php HTTP/1.1" 403 252 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //MyAdmin/scripts/setup.php HTTP/1.1" 403 249 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //sql/scripts/setup.php HTTP/1.1" 403 246 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //SQL/scripts/setup.php HTTP/1.1" 403 246 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //web/phpmyadmin/scripts/setup.php HTTP/1.1" 403 253 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //dbg/scripts/setup.php HTTP/1.1" 403 246 "-" "-"
127.0.0.1 - - [30/Mar/2012:03:10:33 -0500] "GET //libs/scripts/setup.php HTTP/1.1" 403 246 "-" "-"
::1 - - [30/Mar/2012:03:10:34 -0500] "OPTIONS * HTTP/1.0" 403 297 "-" "Apache/2.2.3 (CentOS) (internal dummy connection)"
::1 - - [30/Mar/2012:03:10:35 -0500] "OPTIONS * HTTP/1.0" 403 297 "-" "Apache/2.2.3 (CentOS) (internal dummy connection)"
::1 - - [30/Mar/2012:03:10:36 -0500] "OPTIONS * HTTP/1.0" 403 297 "-" "Apache/2.2.3 (CentOS) (internal dummy connection)"[/COLOR]



In my server I have not installed php and phpmyadmin but some body is accessing my server with phpmyadmin and can anyone explain for the above access_log and messages log

Thanks,

Last edited by ramecare; 03-30-2012 at 03:25 AM.
 
Old 03-30-2012, 03:27 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
All this kind of stuff is standard in the log files for anyone running a public facing web server, the internet if full of little skript kiddiez trying to exploit servers.

Failed access attempts since Monday on my main server:

Code:
# grep "Failed password" /var/log/secure | wc -l
28260

Last edited by TenTenths; 03-30-2012 at 03:33 AM.
 
Old 03-30-2012, 03:47 AM   #3
colucix
LQ Guru
 
Registered: Sep 2003
Location: Bologna
Distribution: CentOS 6.5 OpenSuSE 12.3
Posts: 10,509

Rep: Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983Reputation: 1983
Moved: This thread is more suitable in Linux - Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 03-30-2012, 03:53 AM   #4
ramecare
Member
 
Registered: Feb 2011
Posts: 179

Original Poster
Rep: Reputation: 0
I cannot understand can u pls explain

Thanks,
 
Old 03-30-2012, 04:23 AM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
There's nothing to explain. it's just noise from trojans on other machines etc. keep your system secure and just laugh at them.
 
1 members found this post helpful.
Old 03-30-2012, 04:28 AM   #6
ramecare
Member
 
Registered: Feb 2011
Posts: 179

Original Poster
Rep: Reputation: 0
How virus can enter into the server ?
 
Old 03-30-2012, 04:33 AM   #7
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
huh? where did anyone say there was a virus on your server?
 
Old 03-30-2012, 08:04 AM   #8
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
For the most part those entries are simply records of what was asked for from your server. When someone makes a connection, they typically use the HTTP GET method. There are other commands in HTTP such as OPTIONS, PUT, and HEAD. Notice that you have an entry trying to use the OPTIONS command too. One of the key pieces of information in the log entry is the response code, which follows the request. In most of your example entries, the code is 403, which means Forbidden.

Trying to access PhpMyAdmin is very common and there are undoubtedly many automated scripts and worms looking for sites that allow it to face the public so that they can try to exploit it. To give you an example, here is a snippet from one of my servers:
[/code]
58.30.6.85 - - [21/Mar/2012:15:11:22 -0400] "GET /admin/phpmyadmin/index.php HTTP/1.1" 404 224
58.30.6.85 - - [21/Mar/2012:15:11:25 -0400] "GET /typo3/phpmyadmin/index.php HTTP/1.1" 404 224
58.30.6.85 - - [21/Mar/2012:15:11:26 -0400] "GET /phpMyAdmin/index.php HTTP/1.1" 404 218
58.30.6.85 - - [21/Mar/2012:15:11:27 -0400] "GET /phpmyadmin/index.php HTTP/1.1" 404 218
58.30.6.85 - - [21/Mar/2012:15:11:27 -0400] "GET /phpmyadmin1/index.php HTTP/1.1" 404 219
211.68.122.12 - - [29/Mar/2012:15:46:56 -0400] "GET /admin/phpmyadmin/index.php HTTP/1.1" 404 224
211.68.122.12 - - [29/Mar/2012:15:47:06 -0400] "GET /typo3/phpmyadmin/index.php HTTP/1.1" 404 224
211.68.122.12 - - [29/Mar/2012:15:47:09 -0400] "GET /phpMyAdmin/index.php HTTP/1.1" 404 218
[/code]

**From your logs, there are two things that are slightly troubling to me, at least to where I would recommend looking for them. One, the fact that the access is coming from 127.0.0.1. This means that something is executing on THAT MACHINE and is trying to access the myadmin site. Two, the fact that you are returning a 403 error code, which means forbidden instead of 404 - Not Found, when you say that you do not have PhpMyAdmin installed. I would suggest that you determine what is executing on that machine or is using it for a proxy and trying to access it, and two verify that it is not installed and confirm that 403-Forbidden is the intended response code. The event logs seem to indicate that it is installed on the server and someone has taken steps to protect the resource.
 
1 members found this post helpful.
Old 03-30-2012, 08:56 AM   #9
ramecare
Member
 
Registered: Feb 2011
Posts: 179

Original Poster
Rep: Reputation: 0
Fist php and phpmyadmin was installed on that server and after seeing the log in uninstalled php and removed phpmyadmin

Thanks,
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
In Apache server, How to change log file location and log format for access log fil? since1993 Linux - Server 1 08-19-2009 04:14 PM
the significance and name of the 5th column of /var/log/auth.log (ubuntu server)? CoffeeKing!!! Linux - Security 4 02-05-2009 07:32 AM
Can Samhain log my entries in /var/log/secure and /var/log/mesage to a central server abefroman Linux - Software 2 04-13-2008 04:13 PM
Bash script for server log (namely var/log/messages) tenaciousbob Programming 17 05-24-2007 10:43 AM
How to log conversation between server in /var/log/messages? juris Linux - Software 1 11-23-2004 09:54 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration