Beginner Programming
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsOtherBeginner Programming

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 5th, 2003, 06:39 PM
stankOnIt stankOnIt is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2002
Location: la
Posts: 56 stankOnIt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 41 m 9 sec
Reputation Power: 7
wierd things in my apache logs

i have over 2000 entries that look like this

Quote:

[Wed Mar 5 15:59:53 2003] [error] [client 4.46.XXX.XXX] File does not exist: /usr/local/apache/htdocs/scripts/..%2f../winnt/system32/cmd.exe



all the requests are for cmd.exe or root.exe

a little diggin around and it looks as if it is that nimda p.o.s. tryin to get into my machine

http://www.cert.org/advisories/CA-2001-26.html

the IP that is listed is one within my provider's ip range (4.46.___.___)
so, being that im runing apache on redhat 8.0 im pretty sure that im not vulnerable to this bugger

but 2000 entries makes me a bit nervous as im really new to running a server or workin w/ *nix at all.............

so my question is: should I-

-tell my isp about the IP's that are listed here that are tryin to get into my machine (although theres over 2000 entries, it looks as if the requests are coming from just a handfull of machines)

-block the ips somehow (hosts.deny??? i dunno here plz help me out.)

-or just ignore it cuz nimda is a windoze bug and im not vulnerable (i think)



thanks for the help

-jc

Reply With Quote
  #2  
Old March 5th, 2003, 07:22 PM
Hero Zzyzzx's Avatar
Hero Zzyzzx Hero Zzyzzx is offline
11
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Jul 2001
Location: Lynn, MA
Posts: 4,635 Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level)Hero Zzyzzx User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 4 Days 23 h 44 m 19 sec
Reputation Power: 77
Send a message via AIM to Hero Zzyzzx
You're not vulnerable, I would ignore them.

You could block them at your firewall with ipchains, but that's more trouble than it's worth, as these requests don't do any harm other than the minute resources needed to return a 404.

Reporting them to your ISP will most likely get you nowhere either. I'd just ignore them and curse windows.

Reply With Quote
  #3  
Old March 5th, 2003, 07:27 PM
stankOnIt stankOnIt is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Apr 2002
Location: la
Posts: 56 stankOnIt User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 41 m 9 sec
Reputation Power: 7
thanks for the reply man...

good to know that theres no need to worry about them..




-jc

Reply With Quote
  #4  
Old March 5th, 2003, 09:07 PM
Onslaught's Avatar
Onslaught Onslaught is offline
/(bb|[^b]{2})/
Dev Shed Demi-God (4500 - 4999 posts)
 
Join Date: Nov 2001
Location: Somewhere in the great unknown
Posts: 4,840 Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level)Onslaught User rank is Second Lieutenant (5000 - 10000 Reputation Level) 
Time spent in forums: 2 Days 20 m 5 sec
Reputation Power: 88
Send a message via ICQ to Onslaught
The more you watch your log files the more you will see more windows exploits that have been tried against your linux box. Morons with infected computers and script kiddies will continue to try and exploit web servers, but pretty much all the exploits are a MS problem so you just don't have to worry.

Reply With Quote
  #5  
Old March 5th, 2003, 10:00 PM
Ctb's Avatar
Ctb Ctb is offline
An Ominous Coward
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jan 2002
Posts: 4,425 Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Weeks 10 h
Reputation Power: 0
Don't worry about it man. I had my one site up for 24 hours when, amused by the log, I decided to parse it and counted:

16 nimbda attempts
42 (I kid not: FOURTY TWO) attempts on formmail.pl
2 code red probes
1 googlebot (that was quick)
2 valid hits
A handful of 404s that I never managed to discern what the idiots were trying to do.

I don't use formmail.pl ... so I didn't have a thing to worry about. Apache log files usually look much worse than they really are thanks to Windoze

Disclaimer: it's been a while since I did that... so some numbers may not be accurate, but I'm pretty sure they're right.

Reply With Quote
  #6  
Old March 12th, 2003, 07:59 AM
trevHCS trevHCS is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2002
Posts: 80 trevHCS User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Just be careful you're not running formmail.pl or formmail.cgi as those are the most common ones we tend to get and they are apparently vunerable to spammers.

Trev

Reply With Quote
  #7  
Old March 12th, 2003, 10:15 AM
Ctb's Avatar
Ctb Ctb is offline
An Ominous Coward
Dev Shed Specialist (4000 - 4499 posts)
 
Join Date: Jan 2002
Posts: 4,425 Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level)Ctb User rank is Colonel (50000 - 60000 Reputation Level) 
Time spent in forums: 3 Weeks 10 h
Reputation Power: 0
It's a stupid Matt Wright script that allow nasty people to send 'anon' emails off your server. You can use it, just make sure you have the patched code, not the old, broken code.

Were you warning me, or him, BTW? Just curious, because I already said I don't use it.

Reply With Quote
  #8  
Old March 12th, 2003, 11:10 AM
trevHCS trevHCS is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2002
Posts: 80 trevHCS User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 7
Trouble with all these mailing scripts seems to be that they expose the e-mail address just ready for spam bots to pick up. Ended up rolling my own form script which holds it internally - seems to reduce the spam as well already...

Quote:
Were you warning me, or him, BTW? Just curious, because I already said I don't use it. [/B]


Partly the original poster and partly just anyone who hadn't heard about it - don't think many hosting companies would be too impressed if a spam run ran from a formmail.pl script.

Trev
--
http://www.aardvarksport.net/

Reply With Quote
Reply

Viewing: Dev Shed ForumsOtherBeginner Programming > wierd things in my apache logs


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway