icecoldkilla
Registered User
Hallo,
Ein ausschnitt aus meiner apache error.log
Es scheint so als würde jemand versuchen unsere PHPMyAdmin Version ausfindig zu machen, ohne jetzt paranoid klingen zu wollen, aber wer sie herausfinden möchte, möchte sie warscheinlich nicht bestaunen und bewundern sondern exploiten.
desweiteren wird immer wieder mit DFind gescannt...
Viele ähnliche Threads fand ich über die Suche, keines wurde aber entgültig geklärt.
Meine schritte waren :
- Update im Plesk manager
- Hosts.deny : ALL: w00tw00t.at
Diese Scans treiben unsern Server in die Knie, das wirkt schon fast Ddos Like.
Bitte um hilfe.
Ein ausschnitt aus meiner apache error.log
Code:
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/pma
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/web
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/xampp
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/web
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/php-my-admin
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/websql
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpmyadmin
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/php-my-admin
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.2.3
[Wed Sep 01 14:23:56 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.2.6
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.1
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.4
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.5-rc1
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.5-rc2
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.5
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.5-pl1
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.6-rc1
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.6-rc2
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.6
[Wed Sep 01 14:23:57 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.7
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.5.7-pl1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-alpha
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-alpha2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-beta1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-beta2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-rc1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-rc2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-rc3
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-pl1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-pl2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.0-pl3
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.1-rc1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.1-rc2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.1-pl1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.1-pl2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.1-pl3
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.2-rc1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.2-beta1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.2-rc1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.2-pl1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.3
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.3-rc1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.3
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.3-pl1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.4-rc1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.4-pl1
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.4-pl2
[Wed Sep 01 14:23:58 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.4-pl3
[Wed Sep 01 14:23:59 2010] [error] [client 62.193.249.180] File does not exist: /var/www/vhosts/default/htdocs/phpMyAdmin-2.6.4-pl4
Es scheint so als würde jemand versuchen unsere PHPMyAdmin Version ausfindig zu machen, ohne jetzt paranoid klingen zu wollen, aber wer sie herausfinden möchte, möchte sie warscheinlich nicht bestaunen und bewundern sondern exploiten.
desweiteren wird immer wieder mit DFind gescannt...
Code:
[Thu Sep 02 14:30:32 2010] [error] [client 93.97.181.104] client sent HTTP/1.1 request without hostname (see RFC2616 section 14.23): /w00tw00t.at.ISC.SANS.DFind:)
[Thu Sep 02 16:26:50 2010] [error] [client 94.231.190.46] client sent HTTP/1.1 request without hostname (see RFC2616 section 14.23): /w00tw00t.at.ISC.SANS.test0:)
Viele ähnliche Threads fand ich über die Suche, keines wurde aber entgültig geklärt.
Meine schritte waren :
- Update im Plesk manager
- Hosts.deny : ALL: w00tw00t.at
Diese Scans treiben unsern Server in die Knie, das wirkt schon fast Ddos Like.
Bitte um hilfe.