[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

How to prevent IPs from probing web server ?

Asked by sacombank-sbs in Internet Security, Intrusion Detection Systems (IDS), WebApplications

Tags: Linux Cent OS 5.3, Apache Tomcat

Dear Sir/Madam,
    I check my server and receive the logwatch notification as below :

-----------------------------
Connection attempts using mod_proxy:
    220.231.83.199 -> long-name-with-some-inexistent-host:443: 1 Time(s)
    220.231.83.199 -> testphpinvalid.acunetix.com:80: 2 Time(s)

A total of 4 sites probed the server
    123.20.65.244
    220.231.83.199
    221.121.18.170
    222.253.79.154

A total of 2 possible successful probes were detected (the following URLs
contain strings that match one or more of a listing of strings that
indicate a possible exploit):

    /chart?symbol=STB&type=line&width=617&height=377&range=3m&scale=linear&ma_periods_1=0&ma_periods
_2=0&bb_periods=0&bb_deviations=0&symbols=H\xc3\x81&markets=&percentType=true
HTTP Response 200
    /chart?symbol=STB&type=line&width=617&height=377&range=3m&scale=linear&ma_periods_1=0&ma_periods
_2=0&bb_periods=0&bb_deviations=0&symbols=H\xc3\x81T&markets=&percentType=true
HTTP Response 200

Requests with error response codes
    400 Bad Request
       /: 4 Time(s)
       /..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c/boot.ini: 1 Time(s)
       /images/pins/pinQ.gif: 1 Time(s)
       /ipriceboard/images/flag_en.gif: 1 Time(s)
       /ipriceboard/initAction.do?page=hastc: 1 Time(s)
       /search.do: 1 Time(s)
       /web_scanner_test_file.txt: 1 Time(s)
       /wvs_test_for_inexistent_file.txt: 1 Time(s)
    403 Forbidden
       /: 4 Time(s)
       /TRACE_test: 1 Time(s)
       /TRACK_test: 1 Time(s)
       /css/: 3 Time(s)
       /css/images/: 3 Time(s)
       /css/img/: 2 Time(s)
       /css/img/tabs/: 2 Time(s)
       /css/screener/: 3 Time(s)
       /images/: 3 Time(s)
       /img/: 2 Time(s)
       /js/: 3 Time(s)
       /js/ajax/: 2 Time(s)
       /js/screener/: 3 Time(s)
       /portal/sbsfiles/: 6 Time(s)
       /portal/sbsfiles/ACL/: 3 Time(s)
       /portal/sbsfiles/ACL/others/: 3 Time(s)
       /portal/sbsfiles/ALT/: 3 Time(s)
       /portal/sbsfiles/ALT/others/: 3 Time(s)
       /portal/sbsfiles/ASP/: 3 Time(s)
       /portal/sbsfiles/ASP/others/: 3 Time(s)
       /portal/sbsfiles/ATA/: 3 Time(s)
       /portal/sbsfiles/ATA/others/: 3 Time(s)
       /portal/sbsfiles/BCC/: 2 Time(s)
       /portal/sbsfiles/BCC/others/: 2 Time(s)
       /portal/sbsfiles/BPC/: 2 Time(s)
       /portal/sbsfiles/BPC/others/: 2 Time(s)
       /portal/sbsfiles/BTH/: 2 Time(s)
       /portal/sbsfiles/BTH/others/: 2 Time(s)
       /portal/sbsfiles/BTS/: 3 Time(s)
       /portal/sbsfiles/BTS/others/: 3 Time(s)
       /portal/sbsfiles/BVH/: 3 Time(s)
       /portal/sbsfiles/BVH/others/: 3 Time(s)
       /portal/sbsfiles/BVS/: 3 Time(s)
       /portal/sbsfiles/BVS/others/: 3 Time(s)
       /portal/sbsfiles/CCM/: 3 Time(s)
       /portal/sbsfiles/CCM/others/: 3 Time(s)
       /portal/sbsfiles/CDC/: 2 Time(s)
       /portal/sbsfiles/CDC/others/: 2 Time(s)
       /portal/sbsfiles/CJC/: 3 Time(s)
       /portal/sbsfiles/CJC/others/: 3 Time(s)
       /portal/sbsfiles/CNT/: 3 Time(s)
       /portal/sbsfiles/CNT/others/: 3 Time(s)
       /portal/sbsfiles/CTB/: 2 Time(s)
       /portal/sbsfiles/CTB/others/: 2 Time(s)
--------------------------------------------------------------
 
 As I check day after day, there are a lot of Ips which probed our server and I can't simply deny all by firewall with source Ip . So , please guide me how to prevent these IPs from probing our web server . We use apache tomcat + Linux Cent OS 5.3 + JDK 1.6.0.12 .
 Best regards,
 Hien Huynh
[+][-]10/27/09 05:09 AM, ID: 25671428Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/28/09 06:29 PM, ID: 25689905Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091118-EE-VQP-93 - Hierarchy / EE_QW_3_20080625