LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-23-2007, 05:16 AM   #1
soroccoheaven
Member
 
Registered: Jul 2007
Distribution: mandrake Mandriva Redhat CentOS Slackware
Posts: 221

Rep: Reputation: 30
about httpd/error_log


hi,
This is about the log/httpd/access_log i am getting this almost on every hour or so..what does it mean ...
[Sun Sep 23 13:15:59 2007] [error] [client some_publicIp_address] client denied by server configuration: proxy:some_mailserver_ip:25
pls advice.

thanks
 
Old 09-23-2007, 01:31 PM   #2
raskin
Senior Member
 
Registered: Sep 2005
Location: France
Distribution: approximately NixOS (http://nixos.org)
Posts: 1,900

Rep: Reputation: 69
Try ncat-ting to your port 80, and telling
Code:
CONNECT <mailserver>:25
. Server will reject access and add similar log entry? Then all the remaining similar lines say about evil crackers trying to use you server as a free proxy for spam sending - and, fortunately, failing. What matters? You are not ignored by crackers, maybe there are more qualified amongst them, so keep an eye on your server.
 
Old 09-23-2007, 03:25 PM   #3
soroccoheaven
Member
 
Registered: Jul 2007
Distribution: mandrake Mandriva Redhat CentOS Slackware
Posts: 221

Original Poster
Rep: Reputation: 30
Thanks raskin..
yeah ..i was thinking somthing like this too ..but wanted to confirm ..well di i need execute this command ..connect mailserver :25 ..is it about the mail server who is trying to connect ..me ?..you want me check it exist or not..if it like that ..
i have got there IP , mail.server name ..and i tried the telnet mailserver 25 and 110 too..got responses ..it belongs to somwhere thailand..do i need to report span..for this ..??.

One more thing what are the security measures i need for this ?.

Thank you very much again
 
Old 09-23-2007, 11:54 PM   #4
raskin
Senior Member
 
Registered: Sep 2005
Location: France
Distribution: approximately NixOS (http://nixos.org)
Posts: 1,900

Rep: Reputation: 69
The mail server that is the target of CONNECT query is more like a victim. It has probably no will to send spam, and adheres to pre-spam best practices - which make it a target for relaying. The IP address from which you get connections is probably an infected box, participating - against the will of its owner - in trying to send spam. If the ISP is not just spam harbor, I think that finding out the ISP providing client IP and asking them to encourage "the users with the following IPs (filtered log follows)" to wipe malware from computer can clear world of nearly a half of infected machines listed in your log (by temporarily turning them into clean). Malware use HTTP CONNECT partly because providers find it suspicious when you try to send e-mail by port 25 too often.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Httpd restart-error_log report marius_vl Fedora 1 03-02-2006 03:23 AM
Apache error_log Sapient Linux - Software 1 12-31-2005 08:10 PM
httpd error_log SIGTERM, shutting down mnauta Linux - Security 2 05-02-2003 12:23 PM
My Error_log message ecroswell Linux - General 1 03-14-2003 05:18 PM
/var/log/httpd/error_log:Premature end of script headers! katana Linux - General 0 08-14-2001 06:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration