PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > alt.apache.configuration > strange httpd get requests
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
alt.apache.configuration Apache web server configuration issues.

strange httpd get requests

Réponse
 
LinkBack Outils de la discussion
Vieux 13/10/2006, 12h51   #1
rowlando
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut strange httpd get requests

Hi

I am getting strange http requests logged in my apache logs for sites
that do not exist on my server.

"GET http://www.bdsmreality.com/cgi-bin/r...cgi?id=maxbdsm HTTP/1.0"
200 199 "http://www.maxbdsm.com/linkspage.html" "Mozilla/4.7 (Macintosh;
U; PPC)"


Anyone come across this before??

rowlando
  Réponse avec citation
Vieux 13/10/2006, 13h09   #2
rowlando
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: strange httpd get requests

Davide Bianchi wrote:
> On 2006-10-13, rowlando <rowlando@spamtrap.co.uk> wrote:
>
>>I am getting strange http requests logged in my apache logs for sites
>>that do not exist on my server.
>>"GET http://www.bdsmreality.com/cgi-bin/r...cgi?id=maxbdsm HTTP/1.0"
>>200 199 "http://www.maxbdsm.com/linkspage.html" "Mozilla/4.7 (Macintosh;

>
>
> Someone is trying to use your system as an open relay to 'hide' his
> own IP. The size of the returned page (199 bytes) make me think that he
> is getting your standard homepage or nothing at all. Put his IP
> in your firewall and (if you're a real bastard) drop a mail to his ISP
> or employer.
>
> Davide
>


Thanks Davide.

Isnt this person succeeding??? After all the get requests return a 200 code.


rowlando
  Réponse avec citation
Vieux 13/10/2006, 14h58   #3
Davide Bianchi
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: strange httpd get requests

On 2006-10-13, rowlando <rowlando@spamtrap.co.uk> wrote:
> I am getting strange http requests logged in my apache logs for sites
> that do not exist on my server.
> "GET http://www.bdsmreality.com/cgi-bin/r...cgi?id=maxbdsm HTTP/1.0"
> 200 199 "http://www.maxbdsm.com/linkspage.html" "Mozilla/4.7 (Macintosh;


Someone is trying to use your system as an open relay to 'hide' his
own IP. The size of the returned page (199 bytes) make me think that he
is getting your standard homepage or nothing at all. Put his IP
in your firewall and (if you're a real bastard) drop a mail to his ISP
or employer.

Davide

--
Linux: transforms your microcomputer in a workstation.
Windows NT: transforms your workstation in a microcomputer.
-- Paulo F. Sedrez
  Réponse avec citation
Vieux 13/10/2006, 15h12   #4
rowlando
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: strange httpd get requests

Davide Bianchi wrote:
> On 2006-10-13, rowlando <rowlando@spamtrap.co.uk> wrote:
>
>>>>200 199 "http://www.maxbdsm.com/linkspage.html" "Mozilla/4.7 (Macintosh;
>>>

>>Isnt this person succeeding??? After all the get requests return a 200 code.

>
>
> Yes, and 199 bytes of data. That is a little too short for a full size
> homepage... as I said: put his IP in your firewall.
>
> Davide
>

Excellent stuff.

thanks
  Réponse avec citation
Vieux 13/10/2006, 15h17   #5
Davide Bianchi
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: strange httpd get requests

On 2006-10-13, rowlando <rowlando@spamtrap.co.uk> wrote:
>>>200 199 "http://www.maxbdsm.com/linkspage.html" "Mozilla/4.7 (Macintosh;

>>

> Isnt this person succeeding??? After all the get requests return a 200 code.


Yes, and 199 bytes of data. That is a little too short for a full size
homepage... as I said: put his IP in your firewall.

Davide

--
If you can read this your hard drive is about this rooted!
  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 10h47.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,11454 seconds with 13 queries