-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
I was playing some time ago with a little server, running Apache, in a
dynamic home address.
And using a very high port, to avoid scans.
I forgot about it.
Then the other day, I wanted to share a file using my server, and noticed
that Apache was being hit, with "stupid" requests. Well, not stupid, they
are probably probing vulnerabilities.
What it surprises me is that they hit such a high port, they have to be
probing every port.
(The router is set to redirect incoming tcp on that high port to the inside
server at the same high port)
My IP address changed on the 7 and 8 of February, the hits increase on the
10th. It is possible that the previous user of that IP had a known domain.
Should I worry?
Should I try to implement something in the firewall that blocks IPs that attempt on
vulnerabilities, somehow? If there is such a tool.
Can I know if they are attempting to access the URL by domain name or by IP
address? Ie, what do they write exactly on the "browser". Or script.
Excerpt from /var/log/apache2/access_log:
167.248.133.54 - - [15/Feb/2021:17:20:14 +0100] "GET / HTTP/1.1" 403 972 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
193.27.228.23 - - [15/Feb/2021:21:13:58 +0100] "\x03" 400 911 "-" "-"
185.202.2.149 - - [15/Feb/2021:21:43:39 +0100] "\x03" 400 911 "-" "-"
185.156.72.7 - - [15/Feb/2021:21:59:50 +0100] "\x03" 400 911 "-" "-"
185.202.2.149 - - [15/Feb/2021:23:00:41 +0100] "\x03" 400 911 "-" "-"
185.202.2.149 - - [16/Feb/2021:01:49:38 +0100] "\x03" 400 911 "-" "-"
185.176.220.106 - - [16/Feb/2021:05:00:32 +0100] "\x03" 400 911 "-" "-"
194.61.55.248 - - [16/Feb/2021:05:10:43 +0100] "\x03" 400 911 "-" "-"
94.102.49.193 - - [16/Feb/2021:09:28:17 +0100] "GET / HTTP/1.1" 403 972 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36"
94.102.49.193 - - [16/Feb/2021:09:28:17 +0100] "GET /favicon.ico HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:80.0) Gecko/20100101 Firefox/80.0"
72.251.228.107 - - [16/Feb/2021:11:39:07 +0100] "GET //admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:07 +0100] "GET //ippbx/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:08 +0100] "GET //apps/ippbx/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:08 +0100] "GET //admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:09 +0100] "GET //freepbx/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:09 +0100] "GET //html/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:10 +0100] "GET //fpbx/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:10 +0100] "GET //www/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:10 +0100] "GET //asterisk/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:11 +0100] "GET //myasterisk/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:11 +0100] "GET //pbx/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:12 +0100] "GET //html/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:12 +0100] "GET //fpbx/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:12 +0100] "GET //www/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:13 +0100] "GET //asterisk/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:13 +0100] "GET //myasterisk/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:13 +0100] "GET //pbx/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:14 +0100] "GET //recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:14 +0100] "GET //freepbx/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:15 +0100] "GET //html/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:15 +0100] "GET //fpbx/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:15 +0100] "GET //www/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:16 +0100] "GET //asterisk/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:16 +0100] "GET //myasterisk/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:17 +0100] "GET //pbx/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:17 +0100] "GET //admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:18 +0100] "GET //freepbx/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:18 +0100] "GET //html/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:19 +0100] "GET //fpbx/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:19 +0100] "GET //www/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:20 +0100] "GET //asterisk/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:20 +0100] "GET //myasterisk/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:21 +0100] "GET //pbx/admin/modules/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:21 +0100] "GET //user/admin/images/ HTTP/1.1" 403 972 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:21 +0100] "GET //user/admin/config.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:22 +0100] "GET //user/recordings/index.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
72.251.228.107 - - [16/Feb/2021:11:39:22 +0100] "GET //user/recordings.php HTTP/1.1" 403 958 "-" "python-requests/2.25.1"
122.228.19.79 - - [16/Feb/2021:12:17:06 +0100] "-" 408 - "-" "-"
122.228.19.79 - - [16/Feb/2021:12:17:52 +0100] "GET / HTTP/1.1" 403 972 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:47.0) Gecko/20100101 Firefox/47.0"
122.228.19.79 - - [16/Feb/2021:12:18:58 +0100] "GET / HTTP/1.1" 403 972 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE"
122.228.19.79 - - [16/Feb/2021:12:18:58 +0100] "GET /favicon.ico HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE"
194.61.55.248 - - [16/Feb/2021:14:45:02 +0100] "\x03" 400 911 "-" "-"
117.157.71.16 - - [16/Feb/2021:16:11:56 +0100] "-" 408 - "-" "-"
72.251.228.107 - - [16/Feb/2021:19:23:13 +0100] "\x16\x03\x01" 400 911 "-" "-"
78.128.112.14 - - [17/Feb/2021:10:20:15 +0100] "\x03" 400 911 "-" "-"
185.202.2.149 - - [17/Feb/2021:18:13:10 +0100] "\x03" 400 911 "-" "-"
185.202.2.149 - - [17/Feb/2021:22:20:23 +0100] "\x03" 400 911 "-" "-"
94.232.47.170 - - [17/Feb/2021:22:54:01 +0100] "\x03" 400 911 "-" "-"
185.202.2.149 - - [17/Feb/2021:23:36:37 +0100] "\x03" 400 911 "-" "-"
94.232.47.170 - - [18/Feb/2021:06:31:02 +0100] "\x03" 400 911 "-" "-"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "HEAD / HTTP/1.0\n" 400 911 "-" "-"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /system_api.php HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /system_api.php HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /c/version.js HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /streaming/clients_live.php HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /stalker_portal/c/version.js HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /client_area/ HTTP/1.1" 403 972 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /stalker_portal/c/ HTTP/1.1" 403 972 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.99.129.160 - - [18/Feb/2021:09:38:58 +0100] "GET /stream/rtmp.php HTTP/1.1" 403 958 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
167.248.133.37 - - [18/Feb/2021:19:44:05 +0100] "GET / HTTP/1.1" 403 972 "-" "Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)"
185.202.2.149 - - [18/Feb/2021:23:26:24 +0100] "\x03" 400 911 "-" "-"
185.176.220.106 - - [19/Feb/2021:07:51:23 +0100] "\x03" 400 911 "-" "-"
- --
Cheers
Carlos E. R.
(from 15.2 x86_64 at Telcontar)
-----BEGIN PGP SIGNATURE-----
iHoEARECADoWIQQZEb51mJKK1KpcU/W1MxgcbY1H1QUCYDFkexwccm9iaW4ubGlz
dGFzQHRlbGVmb25pY2EubmV0AAoJELUzGBxtjUfV3YIAn3Pm3hBMPaVD91DnnVAG
lldoQ6rzAJ9VaZstpPUvRkD9Vr5fUZHjy1IOJA==
=VXHj
-----END PGP SIGNATURE-----