LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-04-2010, 05:38 PM   #1
spezticle
Member
 
Registered: May 2010
Distribution: Ubuntu 10.04
Posts: 30

Rep: Reputation: 0
how serious is this 'file sniffing' ?


i'm in the finishing stages of setting up
a bunch of servers:
LAMP, a mailserver, etc, and in my access logs, i'm getting things like the following entries. copied/pasted directly from apache's access.log

i'm doing this to learn apache and the process is easy going for me, but unfortunately self teaching leaves me prime target for learning security mishaps and dangers the hard way.

what insight can anyone give me towards this sort of activity?

Quote:
92.243.17.132 - - [03/Jun/2010:18:33:38 -0500] "GET /roundcubemail/README HTTP/1.1" 404 474 "-" "Morfeus strikes again."
92.243.17.132 - - [03/Jun/2010:18:33:38 -0500] "GET /rc/README HTTP/1.1" 404 467 "-" "Morfeus strikes again."
92.243.17.132 - - [03/Jun/2010:18:33:38 -0500] "GET /webmail/README HTTP/1.1" 404 471 "-" "Morfeus strikes again."
92.243.17.132 - - [03/Jun/2010:18:33:38 -0500] "GET /roundcube/README HTTP/1.1" 404 471 "-" "Morfeus strikes again."
92.243.17.132 - - [03/Jun/2010:18:33:39 -0500] "GET /mail/README HTTP/1.1" 404 468 "-" "Morfeus strikes again."
92.243.17.132 - - [03/Jun/2010:18:33:39 -0500] "GET /README HTTP/1.1" 404 465 "-" "Morfeus strikes again."
in this instance, you notice the useragent hack changed to morfeus strikes again. sidenote: how does one do this?

Quote:
61.183.15.9 - - [04/Jun/2010:14:22:25 -0500] "GET http://www.wantsfly.com/prx2.php HTTP/1.0" 404 273 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
135.196.106.146 - - [04/Jun/2010:14:46:03 -0500] "GET //phpScheduleIt/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:03 -0500] "GET //phpscheduleit/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:03 -0500] "GET //sched/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:03 -0500] "GET //Scheduler/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:04 -0500] "GET //scheduler/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:04 -0500] "GET //scheduleit/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:04 -0500] "GET //schedule/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:05 -0500] "GET //phpschedule/ HTTP/1.1" 404 279 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
135.196.106.146 - - [04/Jun/2010:14:46:05 -0500] "GET // HTTP/1.1" 403 275 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
In this one i really doubt he's using win98. i'm guessing it's wine or a virtualbox?
 
Old 06-04-2010, 07:35 PM   #2
g0su
LQ Newbie
 
Registered: Sep 2007
Posts: 9

Rep: Reputation: 1
This isn't that serious. If you have a website your going to get plenty of automated attempts to find hidden files and vulnerabilities. As far as spoofing the user agent, it's very simple. It's not a hack it's just part of the HTTP protocol. Your allowed to set your user agent to anything you wish. You can set your user agent in a HTTP get request with the following string ""User-agent: MyUserAgent 1.0".

I recommend reading this tutorial on HTTP.
http://www.jmarshall.com/easy/http/
 
1 members found this post helpful.
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
sniffing urls? mraray Linux - Security 1 12-29-2006 04:13 AM
IP Sniffing, how? shrike_912 Slackware - Installation 1 06-06-2004 05:36 PM
Bonding and sniffing.... sdandeker Linux - Security 4 09-26-2003 06:53 AM
sniffing a switch darthczyz Linux - Software 2 07-23-2003 05:33 PM
sniffing question Di0de Linux - Networking 2 07-02-2003 08:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration