Worrying Server Log After Possible Attack (sites probed the server)

Discussion in 'Site & Server Administration' started by joujoba, Jun 24, 2012.

  1. #1
    Hello,

    an attack (most probably) has taken my server online for more then 24h, the logwatch of CentOS showed me this:
    should I be worried? what should i do? I have never gotten this kind of log ever before until this last incident.
    thank you
    --------------------- Selinux Audit Begin ------------------------ 
     
      Number of audit daemon stops: 2 
     
     **Unmatched Entries** 
      Error sending signal_info request (Operation not supported)
      Error sending signal_info request (Operation not supported)
     
     ---------------------- Selinux Audit End ------------------------- 
     
     
     --------------------- Automount Begin ------------------------ 
     
     
     **Unmatched Entries**
     lookup_read_master: lookup(nisplus): couldn't locate nis+ table auto.master: 4 Time(s)
     
     ---------------------- Automount End ------------------------- 
     
     
     --------------------- httpd Begin ------------------------ 
    
    
    
    A total of 77 sites probed the server 
    XXXXXXXXXXXXX
    list of IP's here
    XXXXXXXXXXXXX
    
    Requests with error response codes
        400 Bad Request
           /: 2 Time(s)
           /announce?info_hash=%85%09%d1%5edE%88D%01% ... =1&no_peer_id=1: 2 Time(s)
           /scrape?info_hash=%B0%EE%0D%D9%B7%07%05%9E ... 3F%E4o%C7%E7%E3: 1 Time(s)
           /w00tw00t.at.ISC.SANS.DFind:): 1 Time(s)
        404 Not Found
           /404.html: 718 Time(s)
           /404.html?info_hash=%07%F5%8A%B5%3EmWM%1A% ... requirecrypto=0: 4 Time(s)
           /404.html?info_hash=%13%10%B0%94%01%7D%E9% ... requirecrypto=0: 3 Time(s)
           /404.html?info_hash=%15%b0%c0%31%a6%94%16% ... t=200&compact=1: 5 Time(s)
           /404.html?info_hash=%18%90N%9D%08%1F%C0P%D ... requirecrypto=0: 1 Time(s)
           /404.html?info_hash=%7B%0E%A0Wz%BE%1Ck5%EE ... requirecrypto=0: 2 Time(s)
           /404.html?info_hash=%84%26%D9%26A%7E%F0%D0 ... requirecrypto=0: 4 Time(s)
           /404.html?info_hash=%88%F6%2E%8C%0B%A4%F8% ... t=1&numwant=100: 3 Time(s)
           /404.html?info_hash=%8A%20%D2%F9%D9%1B%AF% ... requirecrypto=0: 2 Time(s)
           /404.html?info_hash=%8C%1A%05%87oh%8E8%EB% ... requirecrypto=0: 9 Time(s)
           /404.html?info_hash=%B0%B1%23%1F%D9%9E%99q ... requirecrypto=0: 5 Time(s)
           /404.html?info_hash=%B0%E0%F9%3F%B0L%B8%1E ... requirecrypto=0: 2 Time(s)
           /404.html?info_hash=%B5dR%D3Fl%0FA%C8%A3%1 ... t=1&numwant=100: 4 Time(s)
           /404.html?info_hash=%B6Y%2Af%20M%BC%F9%B9% ... t=1&numwant=100: 6 Time(s)
           /404.html?info_hash=%D9%10%80%CB%7F%0D%A4% ... requirecrypto=0: 6 Time(s)
           /404.html?info_hash=%DC%9B%E9%99B%BB%08%24 ... t=1&numwant=100: 1 Time(s)
           /404.html?info_hash=%E5N%21%A5%40%CD%04%D8 ... requirecrypto=0: 2 Time(s)
           /404.html?info_hash=%F4%C3%3B9%95%E0%D7c%9 ... event=completed: 1 Time(s)
           /404.html?info_hash=%F4%C3%3B9%95%E0%D7c%9 ... requirecrypto=0: 4 Time(s)
           /404.html?info_hash=%b0%11%36%4a%cb%9a%28% ... t=200&compact=1: 16 Time(s)
           /404.html?info_hash=%d1%89%1b%95%00%ac%9d% ... t=200&compact=1: 6 Time(s)
           /404.html?info_hash=%d3%6d%c4%68%42%5a%3e% ... t=200&compact=1: 14 Time(s)
           /404.html?info_hash=%ed%bc%a1%41%11%ba%e7% ... t=200&compact=1: 13 Time(s)
           /404.html?info_hash=J%D8%06%87V%21%B5%26%6 ... requirecrypto=0: 5 Time(s)
           /404.html?info_hash=N%81%5D%C5%1A%8B%A6%C2 ... t=1&numwant=100: 1 Time(s)
           /404.html?info_hash=l%E4%B3F%8F%D90QP%E9%8 ... requirecrypto=0: 2 Time(s)
           /404.html?info_hash=r%D9%B3%F5%3DN%15%9CE% ... requirecrypto=0: 7 Time(s)
           /Edu.jar: 2 Time(s)
           /REST.jar: 2 Time(s)
           /Set.jar: 4 Time(s)
           /announce: 1 Time(s)
           /announce%200%2011?info_hash=%c6%2b%ac%20% ... ff%3afeb0%3aabf: 1 Time(s)
           /announce.php?info_hash=%60%A7%FA%7D%9F_%A ... ct=1&key=-.X1aD: 14 Time(s)
           /announce/Star%20Trek%20Enterprise%20Seaso ... 20[Absolon].avi: 5 Time(s)
           /announce?compact=1&uploaded=0&downloaded= ... %81%D42&left=-1: 1 Time(s)
           /announce?info_hash=!%02KxW%9c%01n%0bo%d7% ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%1f%ec%07%fba%1aBn%d4 ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%25%db%97G%f8p%3cn%ed ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%5bi%1f%88%c6%3d%88%5 ... 1&event=started: 2 Time(s)
           /announce?info_hash=!%7d%19q%1d%60F%ac%fb9 ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%80%7b%f9%1e%3c%db%f5 ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%8fv%1d%faZxE9%9cbA0% ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%91%ec8%7b%60kL%be%bc ... 1&event=started: 6 Time(s)
           /announce?info_hash=!%91%ec8%7b%60kL%be%bc ... 1&event=stopped: 1 Time(s)
           /announce?info_hash=!%9fh%bbI1%1b%1f%f2%f4 ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%b0%d4%5c%f6Rr%c9l%9b ... =84.123.171.112: 1 Time(s)
           /announce?info_hash=!%b5%fa%0f%1d%fd%de%e3 ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%d9%14%0f%9d%c9!%98%8 ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%e1%60%92%bc3%edf%f4% ... 1&event=started: 1 Time(s)
           /announce?info_hash=!%e4%e3%11%99%cf%f9YI% ... 1&event=started: 1 Time(s)
    
    and it continue forever.. more then 4MB of text file
    Code (markup):
     
    joujoba, Jun 24, 2012 IP
  2. SolidShellSecurity

    SolidShellSecurity Banned

    Messages:
    262
    Likes Received:
    3
    Best Answers:
    1
    Trophy Points:
    45
    #2
    Looks like nothing more then a bot scan. You can just block IPs or config mod_sec or another service to block the attack.
     
    SolidShellSecurity, Jun 24, 2012 IP
  3. joujoba

    joujoba Peon

    Messages:
    100
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    that what resulted in the A total of 77 sites probed the server?
    thank you Solid!
     
    joujoba, Jun 25, 2012 IP
  4. SolidShellSecurity

    SolidShellSecurity Banned

    Messages:
    262
    Likes Received:
    3
    Best Answers:
    1
    Trophy Points:
    45
    #4
    We get and see them all the time on some sites we host. More annoying then anything else.
     
    SolidShellSecurity, Jun 25, 2012 IP