GRY-Online.pl --> Archiwum Forum

Serwer www - co jest grane?

03.02.2007
23:49
smile
[1]

req_ [ has aides ]

Serwer www - co jest grane?

Mam na swoim kompie postawiony serwer Apache (zewn. ip) i przez caly dzisiajszy dzien dzieje mi sie cos dziwnego. Oto fragmenty logw:

error.log, ktory ma az 20MB po jednej nocy:

[Sat Feb 03 23:34:51 2007] [error] [client 222.240.181.62] request failed: erroneous characters after protocol string: GET var pp_gemius_identifier = new String(/ HTTP/1.1
[Sat Feb 03 23:34:53 2007] [error] [client 218.76.89.55] request failed: erroneous characters after protocol string: GET var pp_gemius_identifier = new String(/ HTTP/1.1
[Sat Feb 03 23:34:53 2007] [error] (13)Permission denied: proxy: error deleting old cache file c:/usr/Apache/proxy/z/q/2/p0d01zehbgjkrao3r2ooeyc
[Sat Feb 03 23:34:55 2007] [error] [client 59.56.111.227] Invalid method in request \\x04\\x01
[Sat Feb 03 23:35:20 2007] [error] (13)Permission denied: proxy: error deleting old cache file c:/usr/Apache/proxy/1/2/o/ptz5qzleoha4ncvvnhn25pf
[Sat Feb 03 23:35:29 2007] [error] [client 222.240.181.62] request failed: erroneous characters after protocol string: GET var pp_gemius_identifier = new String(/ HTTP/1.1


access.log, rowniez ponad 20MB:

218.83.188.37 - - [03/Feb/2007:23:43:36 +0100] "GET HTTP/1.0" 200 220 " "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
211.175.163.17 - - [03/Feb/2007:23:43:37 +0100] "GET HTTP/1.1" 302 0 "http%3A%2F%2Fwww.sheknows.com%2Findex.html" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
220.227.148.10 - - [03/Feb/2007:23:43:37 +0100] "GET HTTP/1.1" 302 0 " "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 2.0.40"


Domylam si, e to jaki atak? Jak przed tym uchroni si? Dzieje si to non stop dzisiaj. Tylko wlacze apache to odrazu logi zapelniaja sie tymi dostpami...

03.02.2007
23:52
[2]

req_ [ has aides ]

Aha, a w katalogu "proxy" potworzyl mi sie caly alfabet folderowy. Od 0 do z i w kazdym z nich kolejne folderki tak samo nazwane. W nich pliki "lq3vkcainexeac0gmzgg3oh" z:

0000000045C50ACE 000000004579056A 0000000045C65C55 0000000000000001 0000000045C50AD2 0000000045C50AD5 0000000000000383
X-URL:
Accept: image/gif, image/jpeg, */*
Accept-Language: en-us
Cookie: PHPSESSID=165470c9f041e4eff802189373a6cd0a; __utma=1.1543519401.1170540964.1170540964.1170540964.1; __utmb=1; __utmc=1; __utmz=1.1170540964.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)
Host: www.bestgamearcade.com
Referer:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)

HTTP/1.1 200 OK
Date: Sat, 03 Feb 2007 22:21:02 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
Last-Modified: Fri, 08 Dec 2006 06:25:46 GMT
ETag: "1a64bfb-383-4579056a"
Accept-Ranges: bytes
Content-Length: 899
Content-Type: image/png
Via: 1.1 req.pl

PNG


IHDR   a gAMA 7 tEXtSoftware Adobe ImageReadyqe< IDATxڔS[hU9s۝MtslM6m@!A
&#131;x (&#136;›Ki"H_-AD&#131;ݗfJ$mZiMӴ1Iwg6;`IA9sÎ?&#131;R5|ж텬^?F18gx$2Ho&k
UIp0aϮw?rj)tдc(jК|`_‹2lJ[< ‹9 TIOz-yᖖ<vy-EFT P3&#131;2vbV9ƇBQJ(WRN E>1PyڠdIpDAh86d!GdK)9$p6 $EvֆKuh<o]5Z&#136;!@JQ&#131;I]!YW~½s>&#129;;sa&#136;+‹L9!9l! XO3؞- MnEڕ|\C›(LzF&#152;] J!1!iKw~96PLtMxk
uJeb›?<wX*e6`Bg2( S'Z
;3&#136;>﫽T=\*>›nBG~DB=r @]-k3uG+‹a[nvw $
&%vɸý2xNxN;4>Mw?&#136;l9q7gm&#152;O/H%"nHq~bS% Ca+Q IEND
B`

04.02.2007
01:07
[3]

Kozako2 [ Pretorianin ]

a nie miae przypadkiem ataku na serwer ??

widze e co jest od reklam i tym podobnych ale mog si myli.

chyba jest bd z wczytywaniem reklam i obrazkw z podanych adresw

© 2000-2026 GRY-OnLine S.A.