[opensuse] Odd activity on my webserver
  • From: C <smaug42@xxxxxxxxx>
  • Date: Sat, 11 Dec 2010 10:07:47 +0100
I'm running an http server with two private-ish domains. The content
is nothing really... more or less there for my convenience... one
domain is just a single http landing page (a place holder) with a link
to another passworded page which has a few multimedia files of no real
interest to anyone but me (you need a valid username/password to get
to this page), the other is a copy of an old travel photo site I used
to have (just a couple dozen photos in a JAlbum). I've set robots.txt
to disallow any search indexing, and the major search engines respect
that - good enough for me anyway. The domains are tied to a DynDNS
subscription so that when my ISP changes my IP address, the domains
remain in sync.

Today I noticed an unusual level of activity on my NIC.... generally,
if I'm not doing anything, my NIC activity is zero. Instead today I'm
seeing at least 26kbps up and down... OK, not a lot, but that's more
than the usual zero, and it was a constant 1-1 on the up/down speed
ratio... quite unusual to me. Etherape showed me two IPs that were
very very active on my system. The apache logs show very little....

The last few lines of the error log are:
[Fri Dec 10 18:51:05 2010] [error] [client] Invalid
method in request
[Sat Dec 11 03:37:15 2010] [error] [client] request
failed: error reading the headers
[Sat Dec 11 03:48:22 2010] [error] [client] Invalid
method in request
[Sat Dec 11 09:25:51 2010] [error] [client] Invalid
method in request

The last few lines of the access log are:
------------------------ - - [11/Dec/2010:02:26:40 +0100] "GET /robots.txt
HTTP/1.1" 200 26 "-" "Mozilla/5.0 (compatible; Exabot/3.0;
+" - - [11/Dec/2010:02:26:40 +0100] "GET /menu.html
HTTP/1.1" 304 - "-" "Mozilla/5.0 (compatible; Exabot/3.0;
+" - - [11/Dec/2010:03:37:15 +0100] "GET / HTTP/1.0" 400 5599 "-" "-" - - [11/Dec/2010:03:48:22 +0100]
"B\xac\xcdb\xee\x8aC^4\xad\xd6\xf7\x17$\x04b\xd2\xd0\x13" 501 976 "-"
"-" - - [11/Dec/2010:03:49:07 +0100]
501 976 "-" "-" - - [11/Dec/2010:05:27:28 +0100] "GET /robots.txt
HTTP/1.1" 200 26 "-" "Mozilla/5.0 (compatible; bingbot/2.0;
+" - - [11/Dec/2010:05:34:41 +0100] "GET / HTTP/1.1" 304 -
"-" "Mozilla/5.0 (compatible; bingbot/2.0;
+" - - [11/Dec/2010:06:38:08 +0100] "{\xec/Qo/" 501 976 "-" "-" - - [11/Dec/2010:07:17:04 +0100] "GET / HTTP/1.1" 200 812
"-" "Feedfetcher-Google; (+;
feed-id=6557159989255775444)" - - [11/Dec/2010:09:25:51 +0100]
501 976 "-" "-"

The bot activity is known, and normal... and I don't see anything that
really indicates anyone accessing my passworded directory (when
someone, myself or my brother, logs into the secure area it's recorded
in the access log, and I also see/log what is downloaded/accessed),
nor any other "real" activity. The strange character strings seem to
be... I don't know... someone probing for a security hole in apache?
I am not sure since the string means nothing to me and a Google search
on it returns nothing useful. It appears though that they never got
very far.... I think... maybe...

I stopped my apache server and disabled the secure area, and
immediately the NIC activity dropped to zero. I've since restarted
apache (without the secure area enabled), and the NIC activity hasn't
picked up again.

I've seen this activity a few times recently... noticeable activity on
my network tied to apache, but no traces (that I can see) of what is
actually going on.

Does anyone have any idea what this might be? Am I being paranoid? or
could there be something more to this? Is there somewhere else I
should be looking to figure out what's going on?

