LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-12-2004, 10:41 PM   #1
shilo
Senior Member
 
Registered: Nov 2002
Location: Stockton, CA
Distribution: Slackware 11 - kernel 2.6.19.1 - Dropline Gnome 2.16.2
Posts: 1,132

Rep: Reputation: 50
apache access_log questions


I just started using apache a little while ago. I'm reading though the access log and I have questions about a few entries.

1)
Quote:
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 284
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 282
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 292
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 292
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 306
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 323
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 323
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 339
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
66.229.130.213 - - [07/Apr/2004:01:10:12 -0700] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 305
What's all this about? It looks to me like someone thinks I am running an NT server and they are trying to crack in. Is this correct? What should I do about it?

2)
Quote:
211.187.255.127 - - [12/May/2004:19:56:05 -0700] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1 \x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 \xb1\x02\xb1\x02\xb1\x02
(snip)
Quote:
x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90" 414 347
I've got no idea what this is. It appears all the time and the part I snipped out is REALLY long. Any ideas what that is and what I do about it?

Thanks in advance for any help,
 
Old 05-12-2004, 10:50 PM   #2
shilo
Senior Member
 
Registered: Nov 2002
Location: Stockton, CA
Distribution: Slackware 11 - kernel 2.6.19.1 - Dropline Gnome 2.16.2
Posts: 1,132

Original Poster
Rep: Reputation: 50
Damn, found the answer for #2. Looks like it's some hack for the Microsoft IIS or DAV server. Guess it's just annoying, that's all. Any ideas on #1?
 
Old 05-13-2004, 12:31 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Any ideas on #1?
Probably Nimda worm (targets IIS).
 
Old 05-13-2004, 12:49 PM   #4
shilo
Senior Member
 
Registered: Nov 2002
Location: Stockton, CA
Distribution: Slackware 11 - kernel 2.6.19.1 - Dropline Gnome 2.16.2
Posts: 1,132

Original Poster
Rep: Reputation: 50
Thanks unSpawn. I've been looking into this like mad. I think your right. Looks like it isn't any big deal to me, but it sure is annoying.

Thanks again.
 
Old 06-01-2004, 12:05 PM   #5
catalyst4000
LQ Newbie
 
Registered: Jun 2004
Location: Columbus, OH
Distribution: Fedora
Posts: 6

Rep: Reputation: 0
I've seen alot of these entries in my logs as well, I was just wondering if there is a simple way to block these requests.

mod_rewrite??? or something of the sort.
 
Old 06-01-2004, 12:27 PM   #6
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
I also have seen that second one in my logs. I assumed just by the looks of it that it was some sort or hack, but at least now I know that I don't have to worry about it.

It is of course annoying though. I hope catalyst4000 gets an answer on how to block this, I would like to configure my server to ignore this type of thing.
 
Old 06-01-2004, 12:32 PM   #7
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Rep: Reputation: 45
might not be a bad idea to tracert or whois the IP and send the domain an e-mail informing them that their crappy M$ IIS server is infected and attempted to infect your web server.

be a bit more polite then that, but you get the point. also copy/paste the log entry for them so they can see the details and can verify it at their end. well let me clerify that. they will at least have the information to verify it, but as they are infected by a virus that has had a fix out for well over a year they are probably to dumb to konw what to do about it. but at least they have been notified.

you could also just add their IP to your -J DROP in your iptables rules if you really want to be cruel about it.
 
Old 06-01-2004, 12:39 PM   #8
catalyst4000
LQ Newbie
 
Registered: Jun 2004
Location: Columbus, OH
Distribution: Fedora
Posts: 6

Rep: Reputation: 0
Well, I suppose it's time to write a script, I'd hate to have to look through my logs every day to block systems run by poor users/admins.
 
Old 06-01-2004, 02:33 PM   #9
Lleb_KCir
Senior Member
 
Registered: Nov 2003
Location: Orlando FL
Distribution: Debian
Posts: 1,765

Rep: Reputation: 45
tis one reason why i say M$ OS makes you dumb.

oh well. glad im learning linux and loving the power of it more and more. just wish it supported my games that i play nativly.
 
Old 06-07-2004, 02:40 PM   #10
andrewjschmidt
LQ Newbie
 
Registered: May 2004
Posts: 9

Rep: Reputation: 0
Mod_Rewrite

I'm having this problem too. Going to use config below. I assume this would prevent the logs from being trashed like that?

Taken from http://forums.macosxhints.com/showthread.php?t=22371

<IfModule mod_rewrite.c>
RedirectMatch permanent (.*)cmd.exe(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)root.exe(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/_vti_bin\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/scripts\/\.\.(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/_mem_bin\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/msadc\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/MSADC\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/c\/winnt\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/d\/winnt\/(.*)$ http://www.microsoft.com
RedirectMatch permanent (.*)\/x90\/(.*)$ http://www.microsoft.com
</IfModule>

Andy
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to read the access_log of Apache? Kayaker Slackware 12 06-02-2009 01:22 PM
apache access_log woes thew00t Linux - Software 1 02-23-2004 07:26 AM
apache access_log permissions mirage_3d Linux - Networking 2 12-06-2003 08:54 PM
Apache access_log question WorldBuilder Linux - Networking 7 11-01-2003 06:05 PM
apache access_log to printer plisken Linux - Software 4 02-11-2003 05:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 06:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration