Messages in HTTPD log

This is a discussion on Messages in HTTPD log within the Linux Security forums, part of the System Security and Security Related category; I'm running apache 2.0 on RH Linux behind a firewall. I have setup DNAT to enable port 80 ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-31-2003
Mica
 
Posts: n/a
Default Messages in HTTPD log

I'm running apache 2.0 on RH Linux behind a firewall. I have setup
DNAT to enable port 80 requests to be forwarded to my httpd server in
the internal n/w.

I found this line in my httpd access_log .

xx.xx.xx.xx - - [31/Aug/2003:01:28:45 -0400] "GET
/scripts/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.1" 404
1050 "-" "-"

and the following lines in error_log

[Sun Aug 31 01:28:44 2003] [error] [client xx.xx.xx.x] File does not
exist: /var/www/html/scripts

[Sun Aug 31 01:28:45 2003] [error] [client xx.xx.xx.xx] File does not
exist: /var/www/html/scripts


What was the person trying to accomplish ? I guess he didn't find much
success .
Can I do anything more to prevent such requests coming to my webserver
..

TIA
Navin.
Reply With Quote
  #2 (permalink)  
Old 09-01-2003
Mica
 
Posts: n/a
Default Re: Messages in HTTPD log

<snip>
> >
> > What was the person trying to accomplish ? I guess he didn't find much
> > success .
> > Can I do anything more to prevent such requests coming to my webserver
> > .
> >
> > TIA
> > Navin.
> >

>
> It is a user looking for a windows machine running IIS, and attempting to
> list the directory in hopes of hacking you. Not any consideration to a
> *nix machine, and *probably* will not work even if you are running Apache
> on Windows.

<snip>

Thanks for the pointers Mark.

Seems like packet filtering alone would not be a good solution. Since
I serve out only html pages and run no server-side stuff ,
I'm planning to setup a squid reverse proxy to filter out all unknown
URL's .

Regards,
Navin.
Reply With Quote
  #3 (permalink)  
Old 09-24-2003
Julien Pourchez
 
Posts: n/a
Default Re: Messages in HTTPD log

Mica wrote:

> I'm running apache 2.0 on RH Linux behind a firewall. I have setup
> DNAT to enable port 80 requests to be forwarded to my httpd server in
> the internal n/w.
>
> I found this line in my httpd access_log .
>
> xx.xx.xx.xx - - [31/Aug/2003:01:28:45 -0400] "GET
> /scripts/.%252e/.%252e/winnt/system32/cmd.exe?/c+dir+c:\ HTTP/1.1" 404
> 1050 "-" "-"
>
> and the following lines in error_log
>
> [Sun Aug 31 01:28:44 2003] [error] [client xx.xx.xx.x] File does not
> exist: /var/www/html/scripts
>
> [Sun Aug 31 01:28:45 2003] [error] [client xx.xx.xx.xx] File does not
> exist: /var/www/html/scripts
>
>
> What was the person trying to accomplish ? I guess he didn't find much
> success .
> Can I do anything more to prevent such requests coming to my webserver
> .
>
> TIA
> Navin.


This user is stupid ! he wanted to use Unicode Windows servers Bug ;)
to know if the host is APACHE OR use Telnet
open www.site.org 80
and type GET 1.0 / HTTP

the responce is:
HTTP/1.1 400 Bad Request
Date: Wed, 24 Sep 2003 13:59:55 GMT
Server: Apache
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:31 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0