Thank you for the quick reply. The httpd access log is huge, and there are several iterations (access_log.1, access_log.2... over the last month).
The current access log is over 630 meg and the previous one has a date stamp of June 7th (only four days ago).
I have a feeling I'm a bit in over my head...
Here is just a very little bit of the access log:
Code:
61.139.105.162 - - [07/Jun/2009:21:50:37 -0700] "GET http://ad.scanmedios.com/rw?title=&qs=iframe3%3FAAAAAPKoBwBPwh8AO%2EgJAAIAAAAAAP8AAAABFgIBAAP17QsAl3oJANA7DgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAANYnBA0AAAAAAAAAAAAAAgAGddhBAAAAAAAAAAAAAAIACW3AbQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnsE%2Eprh7dQZVn6Qa3Te9L0QKf%2EUS2c38PJBOSgAAAAA%3D%2C%2Chttp%253a%252f%252fwww%2Eflashgamehome%2Ecom%252findex%2Ehtml HTTP/1.1" 200 557 "http%3A%2F%2Fwww.flashgamehome.com%2Findex.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
61.139.105.166 - - [07/Jun/2009:21:50:38 -0700] "GET http://ad.yieldmanager.com/iframe3?AAAAAEWaCAB6xyQAGQELAAIAAAAAAP8AAAABFgIBAAMV5AwAbakMACyxDwAAAAAAAAAAAAAAAAAAAAAAAAAAADMzMzMzM9M.MzMzMzMz0z8AAAAAAADgPwAAAAAAAOA.AAAAAAAA4D8AAAAAAADgPwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAALTDiu7x7dQYWOlTR37jXnKcgHjTEsvZU0tIBxgAAAAA=,,http%3a%2f%2fwww.flashopping.net%2findex.html HTTP/1.1" 302 - "http%3A%2F%2Fwww.flashopping.net%2Findex.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 2.0.40"
74.52.177.210 - - [07/Jun/2009:21:50:38 -0700] "GET http://www.isisrecovery.com/service_treatment_plan.php HTTP/1.1" 200 5861 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
174.120.24.242 - - [07/Jun/2009:21:50:36 -0700] "GET http://www.virginnigeria.com/eagleflier/ HTTP/1.1" 200 17792 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
67.159.44.143 - - [07/Jun/2009:21:50:35 -0700] "POST http://game.sun116.com/vdgame/msglist.aspx?act=add&ClipID=21084 HTTP/1.1" 302 150 "http://game.sun116.com/vdgame/msglist.aspx?clipid=21084&currpage=510" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
174.133.15.50 - - [07/Jun/2009:21:50:37 -0700] "GET http://www.pique.at/project/countries.html HTTP/1.1" 200 7325 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
174.133.15.50 - - [07/Jun/2009:21:50:37 -0700] "GET http://www.hepmed.com/f-info.htm HTTP/1.1" 200 51019 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
74.52.177.210 - - [07/Jun/2009:21:50:38 -0700] "GET http://www.isisrecovery.com/service_mental_health.php HTTP/1.1" 200 5691 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
174.120.24.242 - - [07/Jun/2009:21:50:38 -0700] "GET http://www.mycalabasas.com/html/main/classifieds_display/msgID/5006990/index.html HTTP/1.1" 200 20053 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
67.159.45.10 - - [07/Jun/2009:21:50:38 -0700] "GET http://www.cnet.com/4360-5_7-6563606.html?key=samsung_cellphones&ttag=cnetfd.aisledir-samsung-cellphones HTTP/1.1" 301 320 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
74.52.177.210 - - [07/Jun/2009:21:50:38 -0700] "GET http://take-shape-share.fenc.org.uk/ HTTP/1.1" 302 150 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
174.133.15.50 - - [07/Jun/2009:21:50:37 -0700] "GET http://www.thetrailmaster.com/content/trail-sign-language HTTP/1.1" 200 21394 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
I'm going to try to hone in on the exact time they said the spam was sent. Anything I should specifically look for?
As far as traffic I expect on the site-- I don't expect any yet as I haven't sent the URL to anyone (though I know that doesn't mean anything with crawlers out there). I'm simply working on a demonstration of my technical writing capabilities with an Eclipse Standalone help system (running in /usr/bin/info_online2 ) which is acccessed via port 8082. (And that is not even ready for prime time.)
I don't believe I have logwatch setup (as there is nothing in the \etc\logwatch\conf\logfiles\ folder).
I'm going to go wrestle with the large access log.
Meanwhile I can at least open the httpd error log. Here is a sampling of that log below.
Code:
[Thu Jun 11 12:05:46 2009] [error] [client 174.120.24.242] proxy: error reading status line from remote server www.jungangsijang.co.kr
[Thu Jun 11 12:05:46 2009] [error] [client 174.120.24.242] proxy: Error reading from remote server returned by http://www.jungangsijang.co.kr/gallery/del_comment.php?no=53&menu_id=18&c_no=405560&start=0
[Thu Jun 11 12:06:15 2009] [error] [client 67.159.45.10] proxy: error reading status line from remote server www.lanbook.com
[Thu Jun 11 12:06:15 2009] [error] [client 67.159.45.10] proxy: Error reading from remote server returned by http://www.lanbook.com/publish/news.php
[Thu Jun 11 12:07:40 2009] [error] [client 67.159.45.10] proxy: error reading status line from remote server www.mil.be
[Thu Jun 11 12:07:40 2009] [error] [client 67.159.45.10] proxy: Error reading from remote server returned by http://www.mil.be/def/index.asp?LAN=nl
[Thu Jun 11 12:07:57 2009] [error] proxy: client 174.120.24.226 given Content-Length did not match number of body bytes read
[Thu Jun 11 12:07:57 2009] [error] (70014)End of file found: proxy: pass request body failed to 222.92.117.45:80 (dict.hjenglish.com) from 174.120.24.226 ()
[Thu Jun 11 12:07:59 2009] [error] [client ::1] Directory index forbidden by Options directive: /var/www/html/
[Thu Jun 11 12:08:02 2009] [error] [client ::1] Directory index forbidden by Options directive: /var/www/html/
[Thu Jun 11 12:08:07 2009] [error] [client 74.52.177.210] proxy: error reading status line from remote server slashdot.org
[Thu Jun 11 12:08:07 2009] [error] [client 74.52.177.210] proxy: Error reading from remote server returned by http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.slideboom.com%2Fpresentations%2F9677%2FDigital-Printing-Company&title=Digital%20Printing%20Company
[Thu Jun 11 12:08:18 2009] [error] [client 174.120.24.242] proxy: error reading status line from remote server www.kroniquent.com
[Thu Jun 11 12:08:18 2009] [error] [client 174.120.24.242] proxy: Error reading from remote server returned by http://www.kroniquent.com/blog/ginette.html
[Thu Jun 11 12:10:29 2009] [notice] caught SIGTERM, shutting down
[Thu Jun 11 12:10:30 2009] [notice] suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Thu Jun 11 12:10:30 2009] [notice] Digest: generating secret for digest authentication ...
[Thu Jun 11 12:10:30 2009] [notice] Digest: done
[Thu Jun 11 12:10:30 2009] [notice] mod_python: Creating 4 session mutexes based on 256 max processes and 0 max threads.
[Thu Jun 11 12:10:30 2009] [error] [client 174.120.24.242] File does not exist: /var/www/html/about_4.html
[Thu Jun 11 12:10:30 2009] [notice] Apache/2.2.3 (Red Hat) configured -- resuming normal operations
[Thu Jun 11 12:10:31 2009] [error] [client 74.55.95.250] File does not exist: /var/www/html/emailthispage.aspx, referer: http://www.treatmentactiongroup.org/emailthispage.aspx
[Thu Jun 11 12:10:32 2009] [error] [client 67.159.44.143] File does not exist: /var/www/html/phynea
[Thu Jun 11 12:10:32 2009] [error] [client 74.55.95.250] File does not exist: /var/www/html/Subscribe.aspx, referer: http://www.yourhealth.net.au/Subscribe.aspx?id=118
[Thu Jun 11 12:10:34 2009] [error] [client 67.159.45.10] File does not exist: /var/www/html/iotw
[Thu Jun 11 12:10:34 2009] [error] [client 71.56.95.140] File does not exist: /var/www/html/servlet
[Thu Jun 11 12:10:35 2009] [error] [client 67.159.45.10] Directory index forbidden by Options directive: /var/www/html/
From what I can tell the numerous 'File does not exist:' lines starting at Jun 11 12:10:30 coincide with my restarting of apache after commenting out the proxy stuff within the httpd.conf file. Hopefully that helped.... but from the sheer immensity of this, I doubt that it helped much.
I'm thinking I should shut down my server... or better yet limit the viewing of my Eclipse help demo to just my home machine (if possible) until I know what to do. (Especially since my demo isn't ready to view anyway.)
Thanks again for any thoughts.