Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Our Archives > General Archives > Servers > My Apache Log is filling up fast!

 
My Apache Log is filling up fast!
Thread Tools
Addicted to MacNN
Join Date: Jan 2000
Location: Stoneham, MA, USA
Status: Offline
Mar 9, 2002, 11:05 AM
 
My Apache error log is filling up real fast! Its already at 1.5 Mb and its not that old. They are all requests to cmd.exe and root.exe. How can I stop this? I don't want these error to be logged, and I don't want attempts to load said files to even be attempted, i want an instant denial, so as to not waste my comptuers time. And what i think would be even nicer would be if I could somehow automatically block or even hack-back these assholes. Assuming these are hack attempts.
     
Mac Elite
Join Date: May 1999
Location: San Jose, CA
Status: Offline
Mar 9, 2002, 11:40 AM
 
These are various Windows hacks from the Nimda and CodeRed worms scanning for vulnerable Windows systems.

There are various ways of addressing the problem but none of the simple ones will resolve your primary complaint - namely the log file growth.

By default Apache is configured to log every request either in the access log or in the error log. Most of the simple fixes involve handling the request in some way which simply moves the log entry from the error log to the access log (i.e. you've gone from having an error to handling the request).

The only way to stop them altogether is to block them before they get to your machine.
Gods don't kill people - people with Gods kill people.
     
l008com  (op)
Addicted to MacNN
Join Date: Jan 2000
Location: Stoneham, MA, USA
Status: Offline
Mar 9, 2002, 11:47 AM
 
They're all from similar IPs than me too, but not the same ones all the time so it would be very hard to block/filter these things.
     
Mac Elite
Join Date: May 1999
Location: San Jose, CA
Status: Offline
Mar 9, 2002, 10:33 PM
 
I'm guessing you're using cable for your internet access. Cable networks are particularly vulnerable to Nimda and CodeRed due to the network architecture (one large subnet covering entire neighborhoods).

If this is the case, you should weigh the chances of there being legitimate traffic to your web server from your neighbors. If you don't think there's much chance of that you can use ipfw (the built-in Mac OS X firewall) to block the traffic.
Gods don't kill people - people with Gods kill people.
     
Junior Member
Join Date: Oct 2000
Location: Mtl. Can
Status: Offline
Mar 11, 2002, 03:33 AM
 
search for 'nimda apache block' on google. you can set your apache configuration to automatically filter out junk nimda-ish requests. i can't remember the exact instructions but i've seen it before
     
 
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 03:59 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2