LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-28-2005, 09:04 AM   #1
Matikas
LQ Newbie
 
Registered: Mar 2004
Distribution: Fedora Core 3
Posts: 4

Rep: Reputation: 0
Malacious Access Log Entry?


Hi all,

I was parsing my apache log and notice these entries that look suspicous.

Line #11614 : 219.134.178.199 - - [22/Jun/2005:11:12:44 -0500] "CONNECT 216.109.118.68:80 HTTP/1.1" 200 3386
Line #11615 : 219.134.178.199 - - [22/Jun/2005:11:12:46 -0500] "GET / HTTP/1.1" 200 3386
Line #11616 : 219.134.178.199 - - [22/Jun/2005:11:12:47 -0500] "GET http://www.yahoo.com/ HTTP/1.1" 200 3565
Line #18663 : 219.140.162.197 - - [28/Jun/2005:11:17:54 -0500] "GET http://cn.yahoo.com/ HTTP/1.1" 200 4436

If this some sort of hack, how do I prevent them from happening again? I did a whois and those IP addresses are from China.

Thanks

Last edited by Matikas; 06-28-2005 at 11:28 AM.
 
Old 06-28-2005, 12:19 PM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
It appears they were trying to use your system as a proxy. Are you running apache on port 8080 by any chance?
 
Old 06-28-2005, 12:34 PM   #3
Matikas
LQ Newbie
 
Registered: Mar 2004
Distribution: Fedora Core 3
Posts: 4

Original Poster
Rep: Reputation: 0
Matir,

No, apache is on port 80 and my router is set to forward port 80 only. Is this also called http tunneling? I've read some on sites that this can be done somehow.

Besides blocking every IP address that does this, is there another solution to prevent this sort of attack?

Thanks,
Matikas
 
Old 06-28-2005, 01:13 PM   #4
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
I don't really consider this a serious attack, especially since I doubt they are getting anywhere.
 
Old 06-28-2005, 04:01 PM   #5
Matikas
LQ Newbie
 
Registered: Mar 2004
Distribution: Fedora Core 3
Posts: 4

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by Matir
I don't really consider this a serious attack, especially since I doubt they are getting anywhere.
Matir,

Alright, I'll consider these as failed attempts and ignore them like all those window hack attempts that I see.

Thanks for the help.

Matikas
 
Old 06-28-2005, 04:23 PM   #6
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
No problem. Those 'attacks' are just hunting for open proxies... and you're not running a proxy, so it should be no big deal.
 
Old 07-27-2005, 11:55 PM   #7
barnamos
LQ Newbie
 
Registered: Apr 2005
Location: colorado
Distribution: mandriva
Posts: 27

Rep: Reputation: 15
if its mandrake..

I was getting slammed through port 80 thanks to mandy's default httpd.conf

http://www.linuxquestions.org/questi...ght=open+proxy

I also commented this in httpd.conf

<IfDefine APACHEPROXIED>
# Listen 8080
</IfDefine>
<IfDefine !APACHEPROXIED>
# Listen 80
</IfDefine>
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Log entry: can someone explain this? future assassin Slackware 3 11-22-2005 02:46 AM
suspicious entry in /var/log/auth.log buehler Linux - Security 5 04-27-2005 05:11 PM
giFTcurs log entry lapthorn Linux - Software 1 12-05-2003 07:44 AM
iptables log entry??? bulliver Linux - Security 2 02-15-2003 10:54 PM
Odd Log Entry mikeyt_333 Linux - General 0 06-12-2002 04:45 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration