Apache Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationApache Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old November 30th, 2001, 12:45 PM
estrabd's Avatar
estrabd estrabd is offline
o0o.o0o
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2001
Location: m00n
Posts: 184 estrabd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 4 m 48 sec
Reputation Power: 8
Send a message via ICQ to estrabd Send a message via AIM to estrabd Send a message via Yahoo to estrabd
Lightbulb blocking ips based on apache logs

I am new to setting up apache, and I was utterly amazed at how many times I saw the the nimba(?) virus was attacking my machine looking for vulnerable M$ IIS.

Anyway, I was wondering if it was feasible to set up a perl script that periodically scanned the apache access/error logs to gather the ips that the attacks came from. Then, it would do what ever it is you do to apache or your file wall to block these certain ip addresses from even wasting apache's time to look for the non existant files.

I am sure it would be interesting to make a collection of these ips, but would it be worth it to do something like this? I know it would sure minimize the size of the damn log files!

Just curious,
Brett

Reply With Quote
  #2  
Old November 30th, 2001, 01:07 PM
Pointman Pointman is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 1999
Posts: 52 Pointman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 10
Post Worm Registry

There are a couple of tools here that may be of interest.

http://worm.jungnickel.com/tools.php

Reply With Quote
  #3  
Old November 30th, 2001, 01:18 PM
Hero Zzyzzx's Avatar
Hero Zzyzzx Hero Zzyzzx is offline
11
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2001
Location: Lynn, MA
Posts: 4,635 Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 4 Days 23 h 44 m 19 sec
Reputation Power: 77
Send a message via AIM to Hero Zzyzzx
The problem hee is that most of the nimda attacks are coming from machines with dynamically assigned IPs (e.g. broadband connected windoze machines).

If you block the IP a nimda attack string comes from, you're going to be blocking all future users of that IP, unless the blocker is intellgently written.

Really, what's the big deal about your log files filling up? Are you that strapped for HDD space?

A safer way might be to set up a squid proxy that only forwards non-attack string looking requests to your apache server.

Reply With Quote
  #4  
Old November 30th, 2001, 01:20 PM
estrabd's Avatar
estrabd estrabd is offline
o0o.o0o
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2001
Location: m00n
Posts: 184 estrabd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 4 m 48 sec
Reputation Power: 8
Send a message via ICQ to estrabd Send a message via AIM to estrabd Send a message via Yahoo to estrabd
no, not strapped for space; just curious.

Brett

Reply With Quote
  #5  
Old November 30th, 2001, 01:22 PM
estrabd's Avatar
estrabd estrabd is offline
o0o.o0o
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Feb 2001
Location: m00n
Posts: 184 estrabd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 4 m 48 sec
Reputation Power: 8
Send a message via ICQ to estrabd Send a message via AIM to estrabd Send a message via Yahoo to estrabd
Re: Worm Registry

Quote:
Originally posted by Pointman
There are a couple of tools here that may be of interest.

http://worm.jungnickel.com/tools.php


That looks pretty cool...I was actually going to play with doing something like that...

Brett

Reply With Quote
  #6  
Old November 30th, 2001, 02:06 PM
Pointman Pointman is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 1999
Posts: 52 Pointman User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 10
Net-Block Owner Notification

I would have to agree with Hero Zzyzzx that actually blocking isn't a great idea.

But there is a nimda-notify script at the Worm Registry that notifies the net-block owner. And as long as this thing (Nimda) has been floating around I think this is the next step toward getting some of these lazy admins to fix their boxes.

By pressuring their service providers.

Reply With Quote
  #7  
Old December 1st, 2001, 06:21 AM
freebsd freebsd is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2001
Posts: 5 freebsd User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
>> I would have to agree with Hero Zzyzzx that actually blocking isn't a great idea

I too agree but with different thinking. Blocking those IPs at packet filtering level (firewall) doesn't help in a long run, as they will continue to waste your bandwidth and perhaps filling up your logs.
IMHO, contacting their ISPs and inform them to investigate, perhaps to suspend or terminate those accounts is the only way to fix the problem.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationApache Development > blocking ips based on apache logs


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway
Stay green...Green IT