LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-29-2012, 09:22 PM   #1
angelo.c
Member
 
Registered: Jul 2011
Location: Hong Kong
Distribution: Slackware 13.1,CentOS 6.4,Fedora 16
Posts: 56

Rep: Reputation: Disabled
Apache Attack


Hello,everyone!

I read my apache access log from time to time and discovered these this morning:

Quote:
118.123.240.176 - - [30/Mar/2012:04:22:34 +0800] "GET /w00tw00t.at.blackhats.romanian.anti-sec HTTP/1.1" 401 401 "-" "ZmEu"
118.123.240.176 - - [30/Mar/2012:04:22:34 +0800] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 401 401 "-" "ZmEu"
118.123.240.176 - - [30/Mar/2012:04:22:34 +0800] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 401 401 "-" "ZmEu"
118.123.240.176 - - [30/Mar/2012:04:22:34 +0800] "GET /pma/scripts/setup.php HTTP/1.1" 401 401 "-" "ZmEu"
118.123.240.176 - - [30/Mar/2012:04:22:35 +0800] "GET /myadmin/scripts/setup.php HTTP/1.1" 401 401 "-" "ZmEu"
118.123.240.176 - - [30/Mar/2012:04:22:35 +0800] "GET /MyAdmin/scripts/setup.php HTTP/1.1" 401 401 "-" "ZmEu"
I guess,this robot or any crap like that wanted to guess whether I have phpmyadmin in my web root.Except blocking this ip,is there any method which I can do to prevent any further attack?

Please drop me a line if you have any ideas.
 
Old 03-30-2012, 12:35 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,

You can use fail2ban. For blocking phpMyadmin requests, there is already a nice filter here

Regards
 
Old 03-30-2012, 01:07 AM   #3
angelo.c
Member
 
Registered: Jul 2011
Location: Hong Kong
Distribution: Slackware 13.1,CentOS 6.4,Fedora 16
Posts: 56

Original Poster
Rep: Reputation: Disabled
bathory,thanks for the reply.

It seems pretty promising.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to track DoS attack with Apache? ajayan Linux - Newbie 7 07-23-2011 06:19 AM
Is this Apache DDOS attack? saharabear Linux - Security 16 06-15-2011 10:09 AM
apache under attack shafey Linux - Security 2 04-21-2008 06:55 PM
apache log attack rino.caldelli Linux - Security 3 03-05-2006 05:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 11:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration