: My Apache access log contains weird GET and POST requests, what can I do? My Apache access log contains weird GET and POST requests, is it possible to examine which of these are harmful? For
My Apache access log contains weird GET and POST requests, is it possible to examine which of these are harmful?
For example:
114.232.151.185 - - [11/Jun/2014:20:11:33 +0200] "GET hotel.qunar.com/render/hoteldiv.jsp?&__jscallback=XQScript_4 HTTP/1.1" 404 1167
103.30.175.10 - - [12/Jun/2014:08:35:17 +0200] "GET /vtigercrm/ HTTP/1.1" 404 1034
69.174.245.163 - - [14/Jun/2014:01:22:38 +0200] "GET /w00tw00t.at.blackhats.romanian.anti-sec:) HTTP/1.1" 404 1034
69.174.245.163 - - [14/Jun/2014:01:22:38 +0200] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 1034
94.74.229.110 - - [16/Jun/2014:18:46:43 +0200] "GET www.msftncsi.com/ncsi.txt HTTP/1.1" 404 1037
80.73.11.164 - - [20/Jun/2014:01:52:14 +0200] "POST /cgi-bin/php?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%69%6F%6E%3D%6F%6E+%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%69%6E%70%75%74+%2D%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%6E HTTP/1.1" 404 1034
162.253.66.76 - - [24/Jun/2014:23:54:30 +0200] "GET /rutorrent HTTP/1.1" 400 226
122.226.223.69 - - [25/Jun/2014:01:14:27 +0200] "GET todd0738.gotoip4.com//hello.html HTTP/1.1" 404 1041
My Apache access log file: pastebin.com/2x0naQBK
More posts by @Becky754
1 Comments
Sorted by latest first Latest Oldest Best
These sort of entries are common with most websites. I get plenty of them in my apache logs. If you have a secure server configuration, there is nothing to worry about.
For example, the fourth entry was probably some bot looking for a phpmyadmin installation file on your server. The second entry was probably a purposeful stray entry for promotional purposes. If your server is properly configured to serve a 404 or an access denied to those requests (which it is doing at the moment), there is absolutely nothing to worry about.
Terms of Use Create Support ticket Your support tickets Stock Market News! © vmapp.org2024 All Rights reserved.