Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

Access log?

 
   Web Hosting and Web Master Forums (Home) -> Apache RSS
Next:  CGI vhost  
Author Message
garyarm

External


Since: Aug 29, 2003
Posts: 2



(Msg. 1) Posted: Fri Aug 29, 2003 2:57 pm
Post subject: Access log?
Archived from groups: alt>apache>configuration (more info?)

Sorry if this is the wrong group, but it appears the most appropriate.

I've noticed a couple of entries in my access log that look like this:
61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
http://www.alltheweb.com/ HTTP/1.1" 200 294


61.144.100.66 doesn't resolve and I'm not alltheweb.com


Am I being abused?
What's the most appropriate doc?

TIA
Gary

 >> Stay informed about: Access log? 
Back to top
Login to vote
r_buecheler

External


Since: Jun 26, 2003
Posts: 17



(Msg. 2) Posted: Fri Aug 29, 2003 7:44 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Gary Armstrong wrote:
 > Sorry if this is the wrong group, but it appears the most appropriate.
 >
 > I've noticed a couple of entries in my access log that look like this:

 > 61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> HTTP/1.1" 200 294

Attempt from 61.144.100.66 to use your system as a proxy and reach
<a style='text-decoration: underline;' href="http://www.alltheweb.com" target="_blank">www.alltheweb.com</a> with your IP address.
BUT.
If you look at lines where your root directory "GET / HTTP/1.1" is being
accessed, you might notice that the size passed is the same: 294 bytes

i.e.
12.123.123.12 - - [31/Jul/2003:13:51:43 -0700] "GET / HTTP/1.1" 200 294

this means that all the hijacker is getting is the root directory (or the
index page thereof)

If the size is not the same, then there is a problem.
I have several of those in my logs. They all get my homepage ;o)
besides that I usually send a message to the ISP that holds the
IP# block
in your case for [61.144.100.66]:

whois.apnic.net:
inetnum: 61.144.0.0 - 61.144.255.255
netname: CHINANET-GD
(addresses in whois record)
hostmaster RemoveThis @ns.chinanet.cn.net
anti-spam RemoveThis @ns.chinanet.cn.net
ipadm RemoveThis @gddc.com.cn

whois.abuse.net:
anti-spam RemoveThis @ns.chinanet.cn.net (for chinanet.cn.net)
postmaster RemoveThis @chinanet.cn.net (for chinanet.cn.net)
ct-abuse RemoveThis @sprint.net (for chinanet.cn.net)


and (with spamcop.net)
ipadm RemoveThis @gddc.com.cn
ct-abuse RemoveThis @sprint.net


HTH

--
Robi<!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Access log? 
Back to top
Login to vote
ian4

External


Since: Jul 30, 2003
Posts: 35



(Msg. 3) Posted: Fri Aug 29, 2003 10:12 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Fri, 29 Aug 2003 11:57:10 -0700 in
<message-id:3F4FA206.70505@testedgeinc.com>
Gary Armstrong <garyarm DeleteThis @testedgeinc.com> wrote:

 > Sorry if this is the wrong group, but it appears the most appropriate.
 >
 > I've noticed a couple of entries in my access log that look like this:
 > 61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
 > <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> HTTP/1.1" 200 294
 >
 >
 > 61.144.100.66 doesn't resolve and I'm not alltheweb.com
 >
 >
 > Am I being abused?
 > What's the most appropriate doc?
 >
 > TIA
 > Gary
 >


The 'all the web' part you're seeing is just a referrer.



Regards,

Ian

--
Ian.H [Design & Development]
digiServ Network - Web solutions
<a style='text-decoration: underline;' href="http://www.digiserv.net" target="_blank">www.digiserv.net</a> | irc.digiserv.net | forum.digiserv.net
Programming, Web design, development & hosting.<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
ian4

External


Since: Jul 30, 2003
Posts: 35



(Msg. 4) Posted: Fri Aug 29, 2003 10:13 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Fri, 29 Aug 2003 19:12:48 GMT in
<message-id:20030829201307.27150f91.ian@WINDOZEdigiserv.net>
"Ian.H [dS]" <ian DeleteThis @WINDOZEdigiserv.net> wrote:

 > On Fri, 29 Aug 2003 11:57:10 -0700 in
 > <message-id:3F4FA206.70505@testedgeinc.com>
 > Gary Armstrong <garyarm DeleteThis @testedgeinc.com> wrote:
 >
  > > Sorry if this is the wrong group, but it appears the most
  > > appropriate.
  > >
  > > I've noticed a couple of entries in my access log that look like
  > > this: 61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
  > > <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> HTTP/1.1" 200 294
  > >
  > >
  > > 61.144.100.66 doesn't resolve and I'm not alltheweb.com
  > >
  > >
  > > Am I being abused?
  > > What's the most appropriate doc?

 >
 > The 'all the web' part you're seeing is just a referrer.


Oops.. apologies.. misread your snippet.

It's a proxy / relay attempt.



Regards,

Ian

--
Ian.H [Design & Development]
digiServ Network - Web solutions
<a style='text-decoration: underline;' href="http://www.digiserv.net" target="_blank">www.digiserv.net</a> | irc.digiserv.net | forum.digiserv.net
Programming, Web design, development & hosting.<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
davideyeahsure

External


Since: Nov 03, 2003
Posts: 2907



(Msg. 5) Posted: Fri Aug 29, 2003 10:25 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Gary Armstrong <garyarm.RemoveThis@testedgeinc.com> wrote:
 > I've noticed a couple of entries in my access log that look like this:
 > 61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
 > <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> HTTP/1.1" 200 294

Someone is using your system as an open proxy. Check that he can't
be done and add that IP to your firewall.

Davide<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
garyarm

External


Since: Aug 29, 2003
Posts: 2



(Msg. 6) Posted: Fri Aug 29, 2003 10:25 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Davide Bianchi wrote:
 > Gary Armstrong <garyarm DeleteThis @testedgeinc.com> wrote:
 >
  >>I've noticed a couple of entries in my access log that look like this:
  >>61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
  >>http://www.alltheweb.com/ HTTP/1.1" 200 294
 >
 >
 > Someone is using your system as an open proxy. Check that he can't
 > be done and add that IP to your firewall.
 >
 > Davide

That is what I feared. Looking at httpd.conf, I see:

#ProxyRequests On

This line is commented out and the doc states that, I should uncomment
it too turn on the proxy server. Yet the access log shows the server
returned 200. What Am I missing?

TIA
Gary<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
nospam180

External


Since: Aug 28, 2003
Posts: 4



(Msg. 7) Posted: Sat Aug 30, 2003 12:27 am
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hmm, in addition to my last email i just tried a block on my friends
ip address ( 81.128.235.54) but it doesnt work, he can still access my
websites without any problem.

Any ideas?




#
# This should be changed to whatever you set DocumentRoot to.
#
<Directory "/usr/local/apache2/htdocs">
#
# Possible values for the Options directive are "None", "All",
# or any combination of:
# Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews
#
# Note that "MultiViews" must be named *explicitly* --- "Options All"
# doesn't give it to you.
#
# The Options directive is both complicated and important. Please see
# http://httpd.apache.org/docs-2.0/mod/core.html#options
# for more information.
#
Options Indexes FollowSymLinks
#
# AllowOverride controls what directives may be placed in .htaccess files.
# It can be "All", "None", or any combination of the keywords:
# Options FileInfo AuthConfig Limit
#
AllowOverride None

#
# Controls who can get stuff from this server.
#
Order allow,deny
Allow from all
Deny from 81.128.235.54

</Directory>

=======================
 >> Stay informed about: Access log? 
Back to top
Login to vote
r_buecheler

External


Since: Jun 26, 2003
Posts: 17



(Msg. 8) Posted: Sat Aug 30, 2003 12:27 am
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Andy wrote:
 > Hmm, in addition to my last email i just tried a block on my friends
 > ip address ( 81.128.235.54) but it doesnt work, he can still access my
 > websites without any problem.
 >
 > Any ideas?

 > <Directory "/usr/local/apache2/htdocs">
[...]
 > Options Indexes FollowSymLinks
[...]
 > AllowOverride None
[...]
 > Order allow,deny
 > Allow from all
 > Deny from 81.128.235.54
 >
 > </Directory>

you are denying him access to the htdocs directory.
I ran into that problem too ;o)

look for the following entry a few lines above
<Directory "/usr/local/apache2/htdocs">

<Directory />
Options FollowSymLinks
AllowOverride None
</Directory>

and modify it to
<Directory />
Options FollowSymLinks
AllowOverride None
Order allow,deny
Allow from all
Deny from 81.128.235.54
</Directory>


your friend will be cast out ;o)


HTH

--
Robi<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
user2450

External


Since: Aug 29, 2003
Posts: 10



(Msg. 9) Posted: Sat Aug 30, 2003 2:31 am
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Robi" <r_buecheler.RemoveThis@remove.yahoo.com> wrote in message
news:vkvjqomrdiu58f@corp.supernews.com...
 > Andy wrote:
  > > Hmm, in addition to my last email i just tried a block on my friends
  > > ip address ( 81.128.235.54) but it doesnt work, he can still access my
  > > websites without any problem.
  > >
  > > Any ideas?
 >
  > > <Directory "/usr/local/apache2/htdocs">
 > [...]
  > > Options Indexes FollowSymLinks
 > [...]
  > > AllowOverride None
 > [...]
  > > Order allow,deny
  > > Allow from all
  > > Deny from 81.128.235.54
  > >
  > > </Directory>
 >
 > you are denying him access to the htdocs directory.
 > I ran into that problem too ;o)
 >
 > look for the following entry a few lines above
 > <Directory "/usr/local/apache2/htdocs">
 >
 > <Directory />
 > Options FollowSymLinks
 > AllowOverride None
 > </Directory>
 >
 > and modify it to
 > <Directory />
 > Options FollowSymLinks
 > AllowOverride None
 > Order allow,deny
 > Allow from all
 > Deny from 81.128.235.54
 > </Directory>
 >
 >
 > your friend will be cast out ;o)
 >
 >
 > HTH
 >
 > --
 > Robi



Ah ok, thats where you have to add the ip's for deny. Thanks Robi.
It wasn't clear, i imagine alot of people must make that mistake.
You expect it to go under
# Controls who can get stuff from this server.

Thanks again<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
r_buecheler

External


Since: Jun 26, 2003
Posts: 17



(Msg. 10) Posted: Sat Aug 30, 2003 2:31 am
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Andy wrote:

 > Ah ok, thats where you have to add the ip's for deny. Thanks Robi.

you're welcome Smile

 > It wasn't clear, i imagine alot of people must make that mistake.

everybody learns. I did ;o)

 > You expect it to go under
 > # Controls who can get stuff from this server.

And precisely that line made me make the mistake.

A little story of my mistake:
I added a PC address in the LAN to the deny command and always had access.
I also added the hostname to the list and still no beef.
I then started looking more closely what <directory> I das denying access to
and that's when I realized the mistake, so I moved the deny to the root
directory and I had success, the PC was denied access, but now I suddenly
had hostnames in my logs, and I only wanted simple IP addresses in them.
Following the thread "Blocking visitors from a certain country?" I saw the
mentioning of the hostname in djs' post and I realized what was getting my
logs filled with hostnames instead of IP numbers.

So, as I already said, everybody learns Smile.

--
Robi<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
michiel

External


Since: Aug 27, 2003
Posts: 3



(Msg. 11) Posted: Sat Aug 30, 2003 3:30 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Gary Armstrong wrote:
 >
 >
 > Davide Bianchi wrote:
 >
  >> Gary Armstrong <garyarm.RemoveThis@testedgeinc.com> wrote:
  >>
   >>> I've noticed a couple of entries in my access log that look like this:
   >>> 61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
   >>> <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> HTTP/1.1" 200 294
  >>
  >>
  >>
  >> Someone is using your system as an open proxy. Check that he can't
  >> be done and add that IP to your firewall.
  >>
  >> Davide
 >
 >
 > That is what I feared. Looking at httpd.conf, I see:
 >
 > #ProxyRequests On
 >
 > This line is commented out and the doc states that, I should uncomment
 > it too turn on the proxy server. Yet the access log shows the server
 > returned 200. What Am I missing?
 >

Ah well, it means they can still TRY to use ite as an open proxy, but it doesn't mean they succeed with it. Someone is probably just scanning a whole lot of ip adresses in order to find someone as stupid as I once was. Trust me, if you have an open proxy, your internet connection will soon be flooded and you WILL notice. If you have only a few of those entries in your log files, don't worry about it.

<rip>
+ <p>If your server is configured properly, then the attempt to
+ proxy through your server will fail. If you see a status
+ code of <code>404</code> (file not found) in the log, then
+ you know that the request failed. If you see a status code
+ of <code>200</code> (success), that does not necessarily mean
+ that the attempt to proxy succeeded. RFC2616 section 5.1.2
+ mandates that Apache must accept requests with absolute URLs
+ in the request-URI, even for non-proxy requests. Since
+ Apache has no way to know all the different names that your
+ server may be known under, it cannot simply reject hostnames
+ it does not recognize. Instead, it will serve requests for
+ unknown sites locally by stripping off the hostname and using
+ the default server or virtual host. Therefore you can
+ compare the size of the file (1456 in the above example) to
+ the size of the corresponding file in your default server.
+ If they are the same, then the proxy attempt failed, since a
+ document from your server was delivered, not a document from
+ <code>www.yahoo.com</code>.</p>
</rip>


i.e. instead of serving <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> through a proxy, apache served <a style='text-decoration: underline;' href="http://www.yourdomain.com/" target="_blank">http://www.yourdomain.com/</a> with status 400.

Michiel.<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
r_buecheler

External


Since: Jun 26, 2003
Posts: 17



(Msg. 12) Posted: Sat Aug 30, 2003 3:30 pm
Post subject: Re: Access log? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Michiel wrote:
 > Gary Armstrong wrote:
   > >>> I've noticed a couple of entries in my access log that look like this:
   > >>> 61.144.100.66 - - [31/Jul/2003:13:51:43 -0700] "GET
   > >>> <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> HTTP/1.1" 200 294
^^^
[...]
 > instead of serving <a style='text-decoration: underline;' href="http://www.alltheweb.com/" target="_blank">http://www.alltheweb.com/</a> through a proxy, apache served
 > <a style='text-decoration: underline;' href="http://www.yourdomain.com/" target="_blank">http://www.yourdomain.com/</a> with status 400.
^^^
make this a 200 ;o)

--
Robi<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Access log? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Access from only one, changing IP - Hi, i want to give access only one person via the internet to my apache server. The problem is, that his ip adresse is changing once a day. I have no problem getting his ip. When i put this ip into the httpd.conf file with the <allow from <ip>...

how to only allow access for localhost - Hi, Is it possible to set up Apache to only allow localhost access to my web files so no one else can gain access? Reason is I am developing some web pages but my computer is always online so I dont want anyone being able to find a web site here when..

restricting/allowing access to directories - Hello, I've got question about restricting access to directories. I,ve got a few Alias directories in my httpd.conf. These can only from my lokal network be seen with thse lines: -order deny,allow -deny from all -allow from 192.168.100 Now I want one..

Problem with access to password protected area - I have a directory selected with a .htaccess file in it. The following is the contents of the file AuthType Basic AuthName "Restricted Directory" AuthUserFile /usr/local/etc-http/.htpasswd Require valid-user I ...

controlling access to Apache based on string in URL - Hey there! Server version: Apache/1.3.23 (Unix) (Red-Hat/Linux) I am running Apache and I would like to limit altogether the hits for the "default.ida" string. Right now default.ida resolves to a nearly empty file. But I would like the reque...
   Web Hosting and Web Master Forums (Home) -> Apache All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]