HELP Army of Tiawanese are hitting my webserver - VERY ODD

Discussion in 'Site & Server Administration' started by SERPalert, Jan 18, 2006.

  1. #1
    ok so im getting a army of Tiawanese hitting my site

    a php script is logging them

    apache logs nothing

    i'e done some poking around


    
    $http_host = $_SERVER['HTTP_HOST'];                                     //What url?
    $request_uri = $_SERVER['REQUEST_URI'];                                 //What url?
    $current_url = "$http_host"."$request_uri";                             //What url?
    
    echo $current_url
    
    PHP:
    and I get this:
    168.95.5.151:25


    ID | IP | TIME | Current_url variable


    Can anyone help me? What is it? What are they doing? How will it affect me/my server/sites?
     
    SERPalert, Jan 18, 2006 IP
  2. FeedBucket

    FeedBucket Well-Known Member

    Messages:
    159
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #2
    Looks like an attempt to poll your mail server.
     
    FeedBucket, Jan 18, 2006 IP
  3. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #3
    How can a php script be being run but not logged by apache?

    Why does it think the current page is randomipaddress: port25

    I'm baffled
     
    SERPalert, Jan 18, 2006 IP
  4. FeedBucket

    FeedBucket Well-Known Member

    Messages:
    159
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #4
    So am I. Where is that log you posted coming from?
     
    FeedBucket, Jan 18, 2006 IP
  5. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #5
    That's a php script i threw together off the index page on one of my sites.

    I noticed another script of mine was logging LOTS of traffic all of the sudden.

    So I knocked this custom script together to log things.
     
    SERPalert, Jan 18, 2006 IP
  6. FeedBucket

    FeedBucket Well-Known Member

    Messages:
    159
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #6
    Stupid question, but I have to ask. Is your webserver listening on port 25?
     
    FeedBucket, Jan 18, 2006 IP
  7. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #7
    Following ports are open

    21
    22
    25
    53
    80
    81
    110

    So yes is the answer.
     
    SERPalert, Jan 18, 2006 IP
  8. FeedBucket

    FeedBucket Well-Known Member

    Messages:
    159
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    108
    #8
    I mean, is Apache itself configured to show a web page if you connect to it on port 25 (usually the answer is no.) Like with a url like

    http://www.yourwebsite.com:25

    Still under the imprression that they're attempted mail server accesses. Try taking a look at your mail logs...

    May also want to kill Apache for a bit and check your processes for anything weird.
     
    FeedBucket, Jan 18, 2006 IP
  9. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #9
    My dedicated hosting provider weren't responding however they've now called me back.

    They're looking into the problem and will phone me back. I'll keep you updated if you're interested.

    Port 25 wasn't serving http.
     
    SERPalert, Jan 18, 2006 IP
  10. SERPalert

    SERPalert Guest

    Messages:
    1,003
    Likes Received:
    66
    Best Answers:
    0
    Trophy Points:
    0
    #10
    For now I've asked them to block the whole of Tiawan. The tech *thought* they were using my server to try and probe mail servers on other machines.

    He couldn't answer why my php script would log them but not apache.

    For now I'm not panicing as much. And I'm going to leave the office at last.

    TYVM for your help.
     
    SERPalert, Jan 18, 2006 IP