I have a danish IP 193.241.88.210 and there is only that record in the
logfile on both servers, i have been looking on the internet and found
another site with the link
http://www.incidents.org/archives/intrusions/msg01083.html
I don't know what is happen, and what i have to do to be safe??
Best regards
Tage Danielsen
Denmark
**************************************************************************
-----Oprindelig meddelelse-----
Fra: Jeffrey Taylor [mailto:jeff.taylor@ieee.org]
Sendt: 4. december 2001 17:22
Til: suse-linux-e@suse.com
Emne: Re: [SLE] [Apache] logfile
This is an access record. Someone at 217.227.118.117 requested a page
at port 8283 of the same IP address. The status was 200 (OK) and 2843
bytes were returned. Is the IP address yours? Either someone is
spoofing your address or Apache is talking to itself. Can you show
some more context? Running nslookup gives
pD9E37675.dip.t-dialin.net. I think that's a German ISP.
HTH,
Jeffrey
Quoting Tage
I have got ar record strange record in my logfile, i have two apache
servers
on the net and the record are on both server.
217.227.118.117 - - [04/Dec/2001:13:11:37 +0100] "GET http://217.227.118.117:8283/ HTTP/1.0" 200 2843
anybody know what this means?? Thanks
-- I don't do Windows and I don't come to work before nine. -- Johnny Paycheck -- To unsubscribe send e-mail to suse-linux-e-unsubscribe@suse.com For additional commands send e-mail to suse-linux-e-help@suse.com Also check the FAQ at http://www.suse.com/support/faq and the archives at http://lists.suse.com