Apache Development
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationApache Development

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old February 24th, 2002, 11:59 AM
CodE-E CodE-E is offline
<(>_~)>
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2002
Posts: 315 CodE-E User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Was someone trying to hax0r me?

Hi,

I noticed some weird stuff in my Apache log file...

Quote:
212.217.126.155 - - [20/Feb/2002:22:35:12 +0100] "GET /scripts/root.exe?/c+dir HTTP/1.0" 404 280
212.217.126.155 - - [20/Feb/2002:22:35:12 +0100] "GET /MSADC/root.exe?/c+dir HTTP/1.0" 404 278
212.217.126.155 - - [20/Feb/2002:22:35:12 +0100] "GET /c/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 288
212.217.126.155 - - [20/Feb/2002:22:35:12 +0100] "GET /d/winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 288
212.217.126.155 - - [20/Feb/2002:22:35:12 +0100] "GET /scripts/..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302
212.217.126.155 - - [20/Feb/2002:22:35:13 +0100] "GET /_vti_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 319
212.217.126.155 - - [20/Feb/2002:22:35:13 +0100] "GET /_mem_bin/..%255c../..%255c../..%255c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 319
212.217.126.155 - - [20/Feb/2002:22:35:13 +0100] "GET /msadc/..%255c../..%255c../..%255c/..%c1%1c../..%c1%1c../..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 335
212.217.126.155 - - [20/Feb/2002:22:35:13 +0100] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 301
212.217.126.155 - - [20/Feb/2002:22:35:14 +0100] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 301
212.217.126.155 - - [20/Feb/2002:22:35:14 +0100] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 301
212.217.126.155 - - [20/Feb/2002:22:35:14 +0100] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 301
212.217.126.155 - - [20/Feb/2002:22:35:14 +0100] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 285
212.217.126.155 - - [20/Feb/2002:22:35:15 +0100] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 285
212.217.126.155 - - [20/Feb/2002:22:35:15 +0100] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302
212.217.126.155 - - [20/Feb/2002:22:35:15 +0100] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 302


I am running on Linux, so why am I getting windows file names requests?

Was someone trying to access my Windows directory or something?

How safe is an Apache server when installing it on Linux? Do any of ya know some newbie-friendly Apache secutiry tutorials (if it's necessary)?

Reply With Quote
  #2  
Old February 24th, 2002, 01:00 PM
mezz mezz is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2001
Posts: 310 mezz User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
It's not someone... They are just things called CodeRed, CodeRedII and Ninada (sp?).. You don't have to worry about those, since this won't make any of effect but waste your bandwidth. There is nothing for you can done, but you can contact him/her ISP if this IP's viruses are attacking on your server too much then ISP can take the actions such as warning him/her to fix their computer or close the account and others..

Reply With Quote
  #3  
Old February 24th, 2002, 02:25 PM
AlCapone's Avatar
AlCapone AlCapone is offline
Mobbing Gangster
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Sep 2001
Location: "Best City" 2002 and 2003- Melbourne, Australia
Posts: 4,913 AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 h 36 m 31 sec
Reputation Power: 18
Send a message via ICQ to AlCapone Send a message via AIM to AlCapone Send a message via Yahoo to AlCapone
>>ISP can take the actions such as warning him/her to fix their computer
>>or close the account and others
They can but they won't - ip is registered for co in morocco, and I bet they dont give a damn thing about one of their customers infecting usa's servers.
You could always just block that ip/network if it bugs you too much...
__________________
And you know I mean that.

Reply With Quote
  #4  
Old February 24th, 2002, 02:32 PM
mezz mezz is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Oct 2001
Posts: 310 mezz User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
>> They can but they won't - ip is registered for co in morocco, and I bet they dont give a damn thing about one of their customers infecting usa's servers.

My ISP does take the action for me twice when three ips are attacking me tooooo much on my IP by those viruses. For just three IPs, they made my log over 2,000 lines in three days to a week with full of CodeRed's attack. I guess, I am luck to have this ISP service..

Reply With Quote
  #5  
Old February 24th, 2002, 02:57 PM
M.Hirsch M.Hirsch is offline
Contributing User
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: Oct 2000
Location: Back in the real world.
Posts: 5,969 M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level)M.Hirsch User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 1 Month 1 Day 22 h 42 m 50 sec
Reputation Power: 184
back to your question:
single entries like that are wannabe-haxors, a million of those are virii (seldom also script kiddies - i consider them being kinda virus too )

Reply With Quote
  #6  
Old February 25th, 2002, 10:51 AM
CodE-E CodE-E is offline
<(>_~)>
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2002
Posts: 315 CodE-E User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
And how safe is Apache?

If I just install Linux and then Apache (without really setting up any security features) on a clean system, will it be safe from crap like CodeRed, other virii and real hax0rs?

Reply With Quote
  #7  
Old February 25th, 2002, 11:15 AM
AlCapone's Avatar
AlCapone AlCapone is offline
Mobbing Gangster
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Sep 2001
Location: "Best City" 2002 and 2003- Melbourne, Australia
Posts: 4,913 AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level)AlCapone User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 5 h 36 m 31 sec
Reputation Power: 18
Send a message via ICQ to AlCapone Send a message via AIM to AlCapone Send a message via Yahoo to AlCapone
With apache/nix server you're cutting out most wannabies with scanners, and even though apache is 'safe' out of the box against most attacks, it is recommended to keep up with patches and mail lists if you really want to be on top of that. Of course, that is called security specialist and they get paid a lot, but doing some research won't hurt home server either.
CodeRed is a threat to only winxx machines, so it shouldn't bother you too much.

Reply With Quote
  #8  
Old February 25th, 2002, 11:42 AM
mitchell mitchell is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2001
Location: Bournemouth, England
Posts: 28 mitchell User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 15 m 23 sec
Reputation Power: 0
Send a message via ICQ to mitchell Send a message via MSN to mitchell
What you can do about CodeRed on Apache/Linux

Hiya

While CodeRed isn't harmful to apache/linux web servers this sort of attack does eat up your bandwidth which could limit access to ligitimate users of your site.

For a method to solve this try this link

http://screaming-penguin.com/main.php?storyid=1870

where they give u the php code and bash file code to stop this sort of thing.

Very useful stuff!

Hope this helps someone

Mitchell

Reply With Quote
  #9  
Old February 25th, 2002, 02:52 PM
CodE-E CodE-E is offline
<(>_~)>
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jan 2002
Posts: 315 CodE-E User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Neat, thanks for the info guys!

Reply With Quote
  #10  
Old March 11th, 2002, 01:35 PM
Bisifiniti Bisifiniti is offline
The Bisifiniti
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2001
Posts: 25 Bisifiniti User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Send a message via AIM to Bisifiniti
Yeah, I just checked my error log and saw all those things. I thought somebody was trying to hack me, too. And since I know jack about security, I'm not yet ready for a hacker =p

Still, it's creepy.
__________________

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationApache Development > Was someone trying to hax0r me?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 3 hosted by Hostway
Stay green...Green IT