Dear Sir/Madam,
I check my server and receive the logwatch notification as below :
--------------------------
---
Connection attempts using mod_proxy:
220.231.83.199 -> long-name-with-some-inexis
tent-host:
443: 1 Time(s)
220.231.83.199 -> testphpinvalid.acunetix.co
m:80: 2 Time(s)
A total of 4 sites probed the server
123.20.65.244
220.231.83.199
221.121.18.170
222.253.79.154
A total of 2 possible successful probes were detected (the following URLs
contain strings that match one or more of a listing of strings that
indicate a possible exploit):
/chart?symbol=STB&type=lin
e&width=61
7&height=3
77&range=3
m&scale=li
near&ma_pe
riods_1=0&
ma_periods
_2=0&bb_periods=0&bb_devia
tions=0&sy
mbols=H\xc
3\x81&mark
ets=&perce
ntType=tru
e
HTTP Response 200
/chart?symbol=STB&type=lin
e&width=61
7&height=3
77&range=3
m&scale=li
near&ma_pe
riods_1=0&
ma_periods
_2=0&bb_periods=0&bb_devia
tions=0&sy
mbols=H\xc
3\x81T&mar
kets=&perc
entType=tr
ue
HTTP Response 200
Requests with error response codes
400 Bad Request
/: 4 Time(s)
/..%5c..%5c..%5c..%5c..%5c
..%5c..%5c
..%5c..%5c
..%5c/boot
.ini: 1 Time(s)
/images/pins/pinQ.gif: 1 Time(s)
/ipriceboard/images/flag_e
n.gif: 1 Time(s)
/ipriceboard/initAction.do
?page=hast
c: 1 Time(s)
/search.do: 1 Time(s)
/web_scanner_test_file.txt
: 1 Time(s)
/wvs_test_for_inexistent_f
ile.txt: 1 Time(s)
403 Forbidden
/: 4 Time(s)
/TRACE_test: 1 Time(s)
/TRACK_test: 1 Time(s)
/css/: 3 Time(s)
/css/images/: 3 Time(s)
/css/img/: 2 Time(s)
/css/img/tabs/: 2 Time(s)
/css/screener/: 3 Time(s)
/images/: 3 Time(s)
/img/: 2 Time(s)
/js/: 3 Time(s)
/js/ajax/: 2 Time(s)
/js/screener/: 3 Time(s)
/portal/sbsfiles/: 6 Time(s)
/portal/sbsfiles/ACL/: 3 Time(s)
/portal/sbsfiles/ACL/other
s/: 3 Time(s)
/portal/sbsfiles/ALT/: 3 Time(s)
/portal/sbsfiles/ALT/other
s/: 3 Time(s)
/portal/sbsfiles/ASP/: 3 Time(s)
/portal/sbsfiles/ASP/other
s/: 3 Time(s)
/portal/sbsfiles/ATA/: 3 Time(s)
/portal/sbsfiles/ATA/other
s/: 3 Time(s)
/portal/sbsfiles/BCC/: 2 Time(s)
/portal/sbsfiles/BCC/other
s/: 2 Time(s)
/portal/sbsfiles/BPC/: 2 Time(s)
/portal/sbsfiles/BPC/other
s/: 2 Time(s)
/portal/sbsfiles/BTH/: 2 Time(s)
/portal/sbsfiles/BTH/other
s/: 2 Time(s)
/portal/sbsfiles/BTS/: 3 Time(s)
/portal/sbsfiles/BTS/other
s/: 3 Time(s)
/portal/sbsfiles/BVH/: 3 Time(s)
/portal/sbsfiles/BVH/other
s/: 3 Time(s)
/portal/sbsfiles/BVS/: 3 Time(s)
/portal/sbsfiles/BVS/other
s/: 3 Time(s)
/portal/sbsfiles/CCM/: 3 Time(s)
/portal/sbsfiles/CCM/other
s/: 3 Time(s)
/portal/sbsfiles/CDC/: 2 Time(s)
/portal/sbsfiles/CDC/other
s/: 2 Time(s)
/portal/sbsfiles/CJC/: 3 Time(s)
/portal/sbsfiles/CJC/other
s/: 3 Time(s)
/portal/sbsfiles/CNT/: 3 Time(s)
/portal/sbsfiles/CNT/other
s/: 3 Time(s)
/portal/sbsfiles/CTB/: 2 Time(s)
/portal/sbsfiles/CTB/other
s/: 2 Time(s)
--------------------------
----------
----------
----------
------
As I check day after day, there are a lot of Ips which probed our server and I can't simply deny all by firewall with source Ip . So , please guide me how to prevent these IPs from probing our web server . We use apache tomcat + Linux Cent OS 5.3 + JDK 1.6.0.12 .
Best regards,
Hien Huynh