LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-07-2002, 01:02 AM   #1
rioguia
Member
 
Registered: Jun 2002
Posts: 411

Rep: Reputation: 30
should i be paranoid about 108 hits in 5 hours?


I want to know if I should be worried about being targeted for hacking. I've just installed an apache server and a firewall so I have no basis of comparison. I've recorded 108 individual hits on my apache web server in the past 5 hours pm [ports 1025, 1026, 8875, 3274]. I have a domain name but have not registered with any search engines. the hits are coming from taiwan, korea, china, germany, and france. i have an old box i'm running a smoothwall firewall which seems to be doing ok but I was wondering if this is an unusual number of hits.

Last edited by rioguia; 10-07-2002 at 01:47 AM.
 
Old 10-07-2002, 01:26 AM   #2
neo77777
LQ Addict
 
Registered: Dec 2001
Location: Brooklyn, NY
Distribution: *NIX
Posts: 3,704

Rep: Reputation: 56
As you probably already know you can get everything from logs
access.log and error.log in apache log directory, if you'd see any reference to cmd.exe or any other stuff relating to MS they are most probably woms floating around net targeted to MS IIS servers, you can just ignore them or if the IP's are repetetive you can just block them, watch out for Slapper Worm if you are using SSL, and other *NIX+Apache worms still dwelling on the net, make sure you are running the latest stable apache webserver or you've applied all the security related patches for your current Apache webserver and you have latest openssl package installed if you're using Apache+mod_ssl. Happy linuxing!
P.S. Make sure if you are using any DB's that their versions are up2date with all security patches and configuration applied, also if you are using PHP make sure it is configured properly, and there is no config files sitting around wide-open for easy access, read up the Security Weekly updates posted by unSpawn every week for the latest info on the linux security front. I included no links due to high volume of them, but if you search here you'll find all the info you need to keep your penguin in a cool place, without sharks threatening his life.

Last edited by neo77777; 10-07-2002 at 01:32 AM.
 
Old 10-07-2002, 01:34 AM   #3
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Ah don't worry about it. I like laughing at my ftp and ssh server log files I have. I've seen a few from Microsoft trying to login as root or something on my FTP server and ssh, many from Japan.. but that many hits, nothing to worry about really. Mine isn't even set up with a actual name, they have to type my IP address to get to mine.. I think I had about 30 to 50 hits about an hour or so after I had mine up with just ssh and ftp services running on it.

But its good to always be cautious though. Just keep good security in mind and you should be ok. Always keep updated and always look out for anything fishy, not for sure about something, take it off the network until you know for sure.

Last edited by trickykid; 10-07-2002 at 01:35 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ms-sql-m hits dareino Fedora 1 08-10-2005 04:57 AM
PARANOID, Have I been hacked? statmobile Linux - Security 5 04-23-2004 03:18 AM
Am I being hacked? or just paranoid piratebiter Linux - Security 4 10-17-2003 07:59 PM
Paranoid security raybcher Linux - Security 3 08-29-2003 07:54 AM
Paranoid about SSH Crashed_Again Linux - Security 7 02-02-2003 03:37 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration