On a SuSe box and trolling the mail logs of Apache 2. One of our biggest hits is something that perplexes me:
18.104.22.168 - - [14/Feb/2006:12:28:59 -0500] "GET http://5=www.mydomain.net/guestbook/...over/index.php HTTP/1.0" 404 4155 "-" "akp niqfhmf0bjd opgf mddpeayotavpaotq"
22.214.171.124 - - [14/Feb/2006:12:28:59 -0500] "GET http://5=www.mydomain.net/guestbook/...ches/index.php HTTP/1.0" 200 9259 "-" "yoyhMdgsytimtdyqfhlsspfqss"
126.96.36.199 - - [14/Feb/2006:12:28:59 -0500] "GET http://5=www.mydomain.net/guestbook/...live/index.php HTTP/1.0" 200 10075 "-" "qpsf4lbuetpy4xtxsxbixfuOiofg"
188.8.131.52 - - [14/Feb/2006:12:29:00 -0500] "GET http://5=www.mydomain.net/guestbook/...../-/index.php HTTP/1.0" 404 4155 "-" "xqlsut7hrmihpbw uesoawvpfmm"
What exactly is this IP trying to do? It hasnt reappeared since the 14th, but I would like to at least know what's going on. As you can see the path it's trying changes constantly as well as the referrer, which is gibberish. Anyone ever seen this?
It's probably a script or worm looking for a php page it can exploit...
Can u help me please.
Haiii, when i had seen ur post i was much interested on whats happening. I dont understand where u had seen messages whether in log files. I dont have any problem currently but i was interested to know so that i can check it out. since we are having an web server and i have to maintain its security.
Please help me and even post what u had done to come out of it.
@kiran ky: i don't understand what you are asking but ...
To check your errorlog try (as root): This shows you where the errorlog is located. Also i think ejdbroker was posting bits from the accesslog.
On my machine the errorlog and accesslog are in the same folder: /var/log/apache2/
@kiran ky: can you put your distribution in your profile (in this forum) so we can see what you are using, thanks :D