Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | My webserver security

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion
Register FAQ Community Calendar

My webserver security
Reply
 
Thread Tools
Old 20-07-2010, 22:27   #1
mr_bo
Inactive
 
Join Date: Nov 2005
Location: Going sideways :)
Services: V+ | o2 BB
Posts: 522
mr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful one
Question My webserver security

I am running a www server and all is well except for Awstats on one of the domains is logging hits on:
Code:
/webmail/src/left_main.php
/webmail/src/right_main.php
/webmail/src/login.php
/webmail/src/webmail.php
/webmail/src/read_body.php
/webmail/src/compose.php
There is only 2 email accounts on this domain for which both have imap disabled and passwords have been changed, robots.txt is also covering these but still receiving 140 hits in 3 days!

Another domin is logging hits on:
Code:
/mysqladmin/scripts/setup.php
/phpmyadmin/scripts/setup.php
/phpMyAdmin/scripts/setup.php
Am I being targeted? Am I safe or should I be worried?

Thanks in advance.
mr_bo is offline   Reply With Quote
Advertisement
Old 20-07-2010, 22:48   #2
Xaccers
Inactive
 
Join Date: Jun 2003
Location: Milling around Milton Keynes
Age: 48
Posts: 12,969
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Xaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny starsXaccers has a pair of shiny stars
Re: My webserver security

My web sites often get brute force attacks, and my ftp site had nothing but attacks.
None got it, and I shunted things around so the ftp was locked down to just the IP address which needed access.

They do a port scan, find a potentially vulnerable service running and start hammering it.
Xaccers is offline   Reply With Quote
Old 21-07-2010, 00:05   #3
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: My webserver security

Quote:
Originally Posted by mr_bo View Post
I am running a www server and all is well except for Awstats on one of the domains is logging hits on:
Code:
/webmail/src/left_main.php
/webmail/src/right_main.php
/webmail/src/login.php
/webmail/src/webmail.php
/webmail/src/read_body.php
/webmail/src/compose.php
There is only 2 email accounts on this domain for which both have imap disabled and passwords have been changed, robots.txt is also covering these but still receiving 140 hits in 3 days!

Another domin is logging hits on:
Code:
/mysqladmin/scripts/setup.php
/phpmyadmin/scripts/setup.php
/phpMyAdmin/scripts/setup.php
Am I being targeted? Am I safe or should I be worried?

Thanks in advance.
Check the httpd logs and see if they're getting responses back from those hits or just 404 (or similar errors)
Kymmy is offline   Reply With Quote
Old 21-07-2010, 00:20   #4
mr_bo
Inactive
 
Join Date: Nov 2005
Location: Going sideways :)
Services: V+ | o2 BB
Posts: 522
mr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful one
Re: My webserver security

Quote:
Originally Posted by Kymmy View Post
Check the httpd logs and see if they're getting responses back from those hits or just 404 (or similar errors)
A snip from the logs shows plenty of 404's but also a few 200's which I'll pick the bones out of tomorrow

"morfeus-strikes-again" also shows up and a quick google gives:

Quote:
They are automated attempts to find potential exploits on your system. Bots will probe your webserver for things the owner might be able to exploit like forums, phpmyadmin etc. There's nothing you can do about it, really, just keep the software you do have up to date.
Also looks like fail2ban is not working properly so something else to look at!

ooh so much to do with so little time!
Attached Files
File Type: txt New Text Document.txt (32.7 KB, 5 views)
mr_bo is offline   Reply With Quote
Old 21-07-2010, 00:25   #5
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: My webserver security

Is the PMA install one of your own? If so get rid of the setup.php file and even update to a version 3
Kymmy is offline   Reply With Quote
Old 21-07-2010, 09:32   #6
mr_bo
Inactive
 
Join Date: Nov 2005
Location: Going sideways :)
Services: V+ | o2 BB
Posts: 522
mr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful one
Re: My webserver security

Quote:
Originally Posted by Kymmy View Post
Is the PMA install one of your own? If so get rid of the setup.php file and even update to a version 3
I think I did delete it, do you know the directory where it's stored so I can check?
mr_bo is offline   Reply With Quote
Old 21-07-2010, 09:38   #7
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: My webserver security

Check the logs, they should all be from the web root. Just that PMA could be installed anywhere on any web folder..

I normally have it on a subfolder of a domain that way it's not in the usual place because if you look at the logs it's probing for default locations of various version 2s of PMA
Kymmy is offline   Reply With Quote
Old 21-07-2010, 09:44   #8
mr_bo
Inactive
 
Join Date: Nov 2005
Location: Going sideways :)
Services: V+ | o2 BB
Posts: 522
mr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful one
Re: My webserver security

Thanks, I'll look this evening and I also need to look at fail2ban.
mr_bo is offline   Reply With Quote
Old 23-07-2010, 00:28   #9
mr_bo
Inactive
 
Join Date: Nov 2005
Location: Going sideways :)
Services: V+ | o2 BB
Posts: 522
mr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful onemr_bo is the helpful one
Re: My webserver security

PMA now on 3.3.4, no setup.php, fail2ban configured ok and tested.
Will need to keep an eye on awstats now but should be ok (fingers crossed)
Thanks
mr_bo is offline   Reply With Quote
Old 23-07-2010, 10:39   #10
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: My webserver security

Kymmy is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 10:19.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum