Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

What should i look for in NT apache logs?

Status
Not open for further replies.

razey

Technical User
Oct 22, 2001
14
US
hi!
one of my friends had his site recently defaced. this is making me kind of jittery. i went and looked at my apache log files, and notices a few odd lines. i am runnin Winnt/2k/Xp.
What should i be looking for in my logs that will give me a direct indication if someone is trying to root me? mabey error #'s or requests of certain files?
thank you,
steve
 
If you are seeing anything that looks like this, it ain't a good thing.

[Fri Oct 26 11:17:50 2001] [error] [client 24.19.12.133] File does not exist: /var/[Fri Oct 26 12:11:05 2001] [error] [client 24.19.218.51] File does not exist: /var/[Fri Oct 26 12:11:05 2001] [error] [client 24.19.218.51] File does not exist: /var/[Fri Oct 26 12:11:06 2001] [error] [client 24.19.218.51] File does not exist: /var/[Fri Oct 26 12:11:06 2001] [error] [client 24.19.218.51] File does not exist: /var/[Fri Oct 26 12:11:06 2001] [error] [client 24.19.218.51] File does not exist: /var/[Fri Oct 26 12:11:06 2001] [error] [client 24.19.218.51] File does not exist: /var/[Fri Oct 26 12:11:07 2001] [error] [client 24.19.218.51] File does not exist: /var/
If you are running windows, I would check with microsoft to see what they have for the NIMDA virus. Linux users don't have to worry but it does fill up a log file fast.
 
oh i see plenty of those lines in my error and access log. i was told that this was the effects of nimda, so i did a scan and came up with nothing. should i still be worrying at the moment?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top