
req_ [ has aides ]
Serwer www - co jest grane?
Mam na swoim kompie postawiony serwer Apache (zewn. ip) i przez caly dzisiajszy dzien dzieje mi sie cos dziwnego. Oto fragmenty logw:
error.log, ktory ma az 20MB po jednej nocy:
[Sat Feb 03 23:34:51 2007] [error] [client 222.240.181.62] request failed: erroneous characters after protocol string: GET var pp_gemius_identifier = new String(/ HTTP/1.1
[Sat Feb 03 23:34:53 2007] [error] [client 218.76.89.55] request failed: erroneous characters after protocol string: GET var pp_gemius_identifier = new String(/ HTTP/1.1
[Sat Feb 03 23:34:53 2007] [error] (13)Permission denied: proxy: error deleting old cache file c:/usr/Apache/proxy/z/q/2/p0d01zehbgjkrao3r2ooeyc
[Sat Feb 03 23:34:55 2007] [error] [client 59.56.111.227] Invalid method in request \\x04\\x01
[Sat Feb 03 23:35:20 2007] [error] (13)Permission denied: proxy: error deleting old cache file c:/usr/Apache/proxy/1/2/o/ptz5qzleoha4ncvvnhn25pf
[Sat Feb 03 23:35:29 2007] [error] [client 222.240.181.62] request failed: erroneous characters after protocol string: GET var pp_gemius_identifier = new String(/ HTTP/1.1
access.log, rowniez ponad 20MB:
218.83.188.37 - - [03/Feb/2007:23:43:36 +0100] "GET HTTP/1.0" 200 220 " "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
211.175.163.17 - - [03/Feb/2007:23:43:37 +0100] "GET HTTP/1.1" 302 0 "http%3A%2F%2Fwww.sheknows.com%2Findex.html" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
220.227.148.10 - - [03/Feb/2007:23:43:37 +0100] "GET HTTP/1.1" 302 0 " "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR 2.0.40"
Domylam si, e to jaki atak? Jak przed tym uchroni si? Dzieje si to non stop dzisiaj. Tylko wlacze apache to odrazu logi zapelniaja sie tymi dostpami...
req_ [ has aides ]
Aha, a w katalogu "proxy" potworzyl mi sie caly alfabet folderowy. Od 0 do z i w kazdym z nich kolejne folderki tak samo nazwane. W nich pliki "lq3vkcainexeac0gmzgg3oh" z:
0000000045C50ACE 000000004579056A 0000000045C65C55 0000000000000001 0000000045C50AD2 0000000045C50AD5 0000000000000383
X-URL:
Accept: image/gif, image/jpeg, */*
Accept-Language: en-us
Cookie: PHPSESSID=165470c9f041e4eff802189373a6cd0a; __utma=1.1543519401.1170540964.1170540964.1170540964.1; __utmb=1; __utmc=1; __utmz=1.1170540964.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none)
Host: www.bestgamearcade.com
Referer:
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
HTTP/1.1 200 OK
Date: Sat, 03 Feb 2007 22:21:02 GMT
Server: Apache/1.3.37 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.4 FrontPage/5.0.2.2635.SR1.2 mod_ssl/2.8.28 OpenSSL/0.9.7a
Last-Modified: Fri, 08 Dec 2006 06:25:46 GMT
ETag: "1a64bfb-383-4579056a"
Accept-Ranges: bytes
Content-Length: 899
Content-Type: image/png
Via: 1.1 req.pl
PNG
IHDR a gAMA 7 tEXtSoftware Adobe ImageReadyqe< IDATxڔS[hU9sMtslM6m@!A
ƒx (ˆKi"H_-ADƒݗfJ$mZiMӴ1Iwg6;`IA9sÎ?ƒR5|ж텬^?F18gx$2Ho&k
UIp0aϮw?rj)tдc(jК|`_2lJ[<9TIOz-yᖖ<vy-EFTP3ƒ2vbV9ƇBQJ(WRN E>1PyڠdIpDAh86d!GdK)9$p6 $EvֆKuh<o]5Zˆ!@JQƒI]!YW~½s>;saˆ+L9!9l!XO3؞-MnEڕ|\C(LzF˜] J!1!iKw~96PLtMxk
uJeb?<wX*e6`Bg2( S'Z
;3ˆ>T=\*>nBG~DB=r @]-k3uG+a[nvw$
&%vɸý2xNxN;4>Mw?ˆl9q7gm˜O/H%"nHq~bS% Ca+Q IENDB`
Kozako2 [ Pretorianin ]
a nie miae przypadkiem ataku na serwer ??
widze e co jest od reklam i tym podobnych ale mog si myli.
chyba jest bd z wczytywaniem reklam i obrazkw z podanych adresw