Hello, an attack (most probably) has taken my server online for more then 24h, the logwatch of CentOS showed me this: should I be worried? what should i do? I have never gotten this kind of log ever before until this last incident. thank you --------------------- Selinux Audit Begin ------------------------ Number of audit daemon stops: 2 **Unmatched Entries** Error sending signal_info request (Operation not supported) Error sending signal_info request (Operation not supported) ---------------------- Selinux Audit End ------------------------- --------------------- Automount Begin ------------------------ **Unmatched Entries** lookup_read_master: lookup(nisplus): couldn't locate nis+ table auto.master: 4 Time(s) ---------------------- Automount End ------------------------- --------------------- httpd Begin ------------------------ A total of 77 sites probed the server XXXXXXXXXXXXX list of IP's here XXXXXXXXXXXXX Requests with error response codes 400 Bad Request /: 2 Time(s) /announce?info_hash=%85%09%d1%5edE%88D%01% ... =1&no_peer_id=1: 2 Time(s) /scrape?info_hash=%B0%EE%0D%D9%B7%07%05%9E ... 3F%E4o%C7%E7%E3: 1 Time(s) /w00tw00t.at.ISC.SANS.DFind:): 1 Time(s) 404 Not Found /404.html: 718 Time(s) /404.html?info_hash=%07%F5%8A%B5%3EmWM%1A% ... requirecrypto=0: 4 Time(s) /404.html?info_hash=%13%10%B0%94%01%7D%E9% ... requirecrypto=0: 3 Time(s) /404.html?info_hash=%15%b0%c0%31%a6%94%16% ... t=200&compact=1: 5 Time(s) /404.html?info_hash=%18%90N%9D%08%1F%C0P%D ... requirecrypto=0: 1 Time(s) /404.html?info_hash=%7B%0E%A0Wz%BE%1Ck5%EE ... requirecrypto=0: 2 Time(s) /404.html?info_hash=%84%26%D9%26A%7E%F0%D0 ... requirecrypto=0: 4 Time(s) /404.html?info_hash=%88%F6%2E%8C%0B%A4%F8% ... t=1&numwant=100: 3 Time(s) /404.html?info_hash=%8A%20%D2%F9%D9%1B%AF% ... requirecrypto=0: 2 Time(s) /404.html?info_hash=%8C%1A%05%87oh%8E8%EB% ... requirecrypto=0: 9 Time(s) /404.html?info_hash=%B0%B1%23%1F%D9%9E%99q ... requirecrypto=0: 5 Time(s) /404.html?info_hash=%B0%E0%F9%3F%B0L%B8%1E ... requirecrypto=0: 2 Time(s) /404.html?info_hash=%B5dR%D3Fl%0FA%C8%A3%1 ... t=1&numwant=100: 4 Time(s) /404.html?info_hash=%B6Y%2Af%20M%BC%F9%B9% ... t=1&numwant=100: 6 Time(s) /404.html?info_hash=%D9%10%80%CB%7F%0D%A4% ... requirecrypto=0: 6 Time(s) /404.html?info_hash=%DC%9B%E9%99B%BB%08%24 ... t=1&numwant=100: 1 Time(s) /404.html?info_hash=%E5N%21%A5%40%CD%04%D8 ... requirecrypto=0: 2 Time(s) /404.html?info_hash=%F4%C3%3B9%95%E0%D7c%9 ... event=completed: 1 Time(s) /404.html?info_hash=%F4%C3%3B9%95%E0%D7c%9 ... requirecrypto=0: 4 Time(s) /404.html?info_hash=%b0%11%36%4a%cb%9a%28% ... t=200&compact=1: 16 Time(s) /404.html?info_hash=%d1%89%1b%95%00%ac%9d% ... t=200&compact=1: 6 Time(s) /404.html?info_hash=%d3%6d%c4%68%42%5a%3e% ... t=200&compact=1: 14 Time(s) /404.html?info_hash=%ed%bc%a1%41%11%ba%e7% ... t=200&compact=1: 13 Time(s) /404.html?info_hash=J%D8%06%87V%21%B5%26%6 ... requirecrypto=0: 5 Time(s) /404.html?info_hash=N%81%5D%C5%1A%8B%A6%C2 ... t=1&numwant=100: 1 Time(s) /404.html?info_hash=l%E4%B3F%8F%D90QP%E9%8 ... requirecrypto=0: 2 Time(s) /404.html?info_hash=r%D9%B3%F5%3DN%15%9CE% ... requirecrypto=0: 7 Time(s) /Edu.jar: 2 Time(s) /REST.jar: 2 Time(s) /Set.jar: 4 Time(s) /announce: 1 Time(s) /announce%200%2011?info_hash=%c6%2b%ac%20% ... ff%3afeb0%3aabf: 1 Time(s) /announce.php?info_hash=%60%A7%FA%7D%9F_%A ... ct=1&key=-.X1aD: 14 Time(s) /announce/Star%20Trek%20Enterprise%20Seaso ... 20[Absolon].avi: 5 Time(s) /announce?compact=1&uploaded=0&downloaded= ... %81%D42&left=-1: 1 Time(s) /announce?info_hash=!%02KxW%9c%01n%0bo%d7% ... 1&event=started: 1 Time(s) /announce?info_hash=!%1f%ec%07%fba%1aBn%d4 ... 1&event=started: 1 Time(s) /announce?info_hash=!%25%db%97G%f8p%3cn%ed ... 1&event=started: 1 Time(s) /announce?info_hash=!%5bi%1f%88%c6%3d%88%5 ... 1&event=started: 2 Time(s) /announce?info_hash=!%7d%19q%1d%60F%ac%fb9 ... 1&event=started: 1 Time(s) /announce?info_hash=!%80%7b%f9%1e%3c%db%f5 ... 1&event=started: 1 Time(s) /announce?info_hash=!%8fv%1d%faZxE9%9cbA0% ... 1&event=started: 1 Time(s) /announce?info_hash=!%91%ec8%7b%60kL%be%bc ... 1&event=started: 6 Time(s) /announce?info_hash=!%91%ec8%7b%60kL%be%bc ... 1&event=stopped: 1 Time(s) /announce?info_hash=!%9fh%bbI1%1b%1f%f2%f4 ... 1&event=started: 1 Time(s) /announce?info_hash=!%b0%d4%5c%f6Rr%c9l%9b ... =84.123.171.112: 1 Time(s) /announce?info_hash=!%b5%fa%0f%1d%fd%de%e3 ... 1&event=started: 1 Time(s) /announce?info_hash=!%d9%14%0f%9d%c9!%98%8 ... 1&event=started: 1 Time(s) /announce?info_hash=!%e1%60%92%bc3%edf%f4% ... 1&event=started: 1 Time(s) /announce?info_hash=!%e4%e3%11%99%cf%f9YI% ... 1&event=started: 1 Time(s) and it continue forever.. more then 4MB of text file Code (markup):
Looks like nothing more then a bot scan. You can just block IPs or config mod_sec or another service to block the attack.