LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-26-2012, 09:59 PM   #1
angelo.c
Member
 
Registered: Jul 2011
Location: Hong Kong
Distribution: Slackware 13.1,CentOS 6.4,Fedora 16
Posts: 56

Rep: Reputation: Disabled
Weird apache access log


Hello,everyone.

I looked up the apache access log from time to time and recently, I found something which is weird and don't know what it means in terms of server security.

As you can see in attachment 1,there was a connection from tomcat requesting manager/html folder.However,I don't have the tomcat activated with apache so does it mean that the remote pc/server trying to access a folder which doesn't exist and disguised us as an tomcat server?

In attachment 2,you can see that there was a request from a pc/server requested proxyjudge1.proxyfire.net/fastenv and failed.What does it mean?Is my server being hijacked or something?

I hope you guys can shed me some light on this one.
Thanks.
Attached Thumbnails
Click image for larger version

Name:	Capture.JPG
Views:	23
Size:	77.5 KB
ID:	9144   Click image for larger version

Name:	Capture2.JPG
Views:	17
Size:	25.1 KB
ID:	9145  
 
Old 02-27-2012, 07:49 AM   #2
bathory
LQ Guru
 
Registered: Jun 2004
Location: Piraeus
Distribution: Slackware
Posts: 13,163
Blog Entries: 1

Rep: Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032Reputation: 2032
Hi,

Are you requesting user authentication in order to access your server?
Because in both cases the response code was 401, meaning "Authorization Required". In fact in the 1st screenshot the username "tomcat" was used for authentication but failed.
The 2nd log was an attempt to see if your webserver is also configured as a proxy server.
Anyway if you don't have apache connected to tomcat and your server is not working as a proxy, there is nothing to worry about. It's usual scan attempts, trying to find servers running these services.
You can check the error_log and see that apache denied access.

Regards
 
Old 02-27-2012, 08:57 PM   #3
angelo.c
Member
 
Registered: Jul 2011
Location: Hong Kong
Distribution: Slackware 13.1,CentOS 6.4,Fedora 16
Posts: 56

Original Poster
Rep: Reputation: Disabled
Thanks for the reply.Your answer is simple and pertinent.

I do have my website with login required so I know what the log means now after your clear explanation.

Thanks again for the help.
 
Old 02-28-2012, 04:00 AM   #4
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Rep: Reputation: 62
Have a look into mod_security to help secure your server, it's an application firewall for apache
 
Old 02-28-2012, 04:03 AM   #5
angelo.c
Member
 
Registered: Jul 2011
Location: Hong Kong
Distribution: Slackware 13.1,CentOS 6.4,Fedora 16
Posts: 56

Original Poster
Rep: Reputation: Disabled
Thanks for the reply,fotoguy.

I'm looking into mod_security to tweak with the server name recently. but will look into the feature which you mentioned.

Thanks for a head up.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
In Apache server, How to change log file location and log format for access log fil? since1993 Linux - Server 1 08-19-2009 04:14 PM
Apache question, weird log justanothersteve Linux - Security 2 02-26-2006 06:13 PM
Weird in Apache log: recipientid sessionid ?? nerdstat Linux - Networking 0 10-01-2004 02:59 AM
Strange results in /var/log/apache/access.log subt13 Linux - Security 2 08-03-2004 01:21 PM
weird Apache log entry ScreeminChikin Linux - Security 8 01-10-2003 09:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 03:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration