Avatar billede 0xffff Nybegynder
08. juni 2007 - 13:26 Der er 3 kommentarer og
1 løsning

hack eller ikke hack?

Hejsa alle,

Nu er jeg ikke så stærk i hele webserver setup. Jeg har en WAMP server kørende sat op som default, ud over det har jeg ikke mere sat op.

Jeg bruger det til udvikling og til et par test sites som jeg leger lidt rundt med.

Jeg har nu kigget i apache log filerne, og hvad jeg ser syntes jeg ikke ser så godt ud. Jeg har en masse af den spam der står nedenfor i min log, fra en hel masse varierende IP adresser.

Spørgsmålene er så:
#1 Har jeg ret i at antage at det som min log viser er at der er en masse der forsøger at hacke min webserver ?

#2 Kan jeg antage at de ikke allerede har lavet noget?

#3 Hvilke sikringsmetoder, hvis nogle, kan jeg anvende, således at de ikke engang kan komme så vidt som de er kommet nu?



[Wed May 30 13:08:14 2007] [error] [client 218.150.108.236] client denied by server configuration: D:/wamp/www/index.htm
[Wed May 30 14:03:29 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/phpmyadmin/main.php
[Wed May 30 14:03:31 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin
[Wed May 30 14:03:32 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/PMA
[Wed May 30 14:03:34 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/admin
[Wed May 30 14:03:36 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/dbadmin
[Wed May 30 14:03:37 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/mysql
[Wed May 30 14:03:39 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/myadmin
[Wed May 30 14:03:41 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpmyadmin2
[Wed May 30 14:03:42 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin2
[Wed May 30 14:03:44 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2
[Wed May 30 14:03:45 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/php-my-admin
[Wed May 30 14:03:47 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.2.3
[Wed May 30 14:03:49 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.2.6
[Wed May 30 14:03:51 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.1
[Wed May 30 14:03:52 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.4
[Wed May 30 14:03:55 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.5-rc1
[Wed May 30 14:03:56 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.5-rc2
[Wed May 30 14:03:57 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.5
[Wed May 30 14:03:59 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.5-pl1
[Wed May 30 14:04:00 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.6-rc1
[Wed May 30 14:04:02 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.6-rc2
[Wed May 30 14:04:03 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.6
[Wed May 30 14:04:05 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.7
[Wed May 30 14:04:06 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.5.7-pl1
[Wed May 30 14:04:08 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-alpha
[Wed May 30 14:04:09 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-alpha2
[Wed May 30 14:04:11 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-beta1
[Wed May 30 14:04:12 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-beta2
[Wed May 30 14:04:13 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-rc1
[Wed May 30 14:04:14 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-rc2
[Wed May 30 14:04:15 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-rc3
[Wed May 30 14:04:17 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0
[Wed May 30 14:04:19 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-pl1
[Wed May 30 14:04:20 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-pl2
[Wed May 30 14:04:21 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.0-pl3
[Wed May 30 14:04:22 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.1-rc1
[Wed May 30 14:04:23 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.1-rc2
[Wed May 30 14:04:24 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.1
[Wed May 30 14:04:26 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.1-pl1
[Wed May 30 14:04:27 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.1-pl2
[Wed May 30 14:04:28 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.1-pl3
[Wed May 30 14:04:30 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.2-rc1
[Wed May 30 14:04:32 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.2-beta1
[Wed May 30 14:04:33 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.2-rc1
[Wed May 30 14:04:35 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.2
[Wed May 30 14:04:36 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.2-pl1
[Wed May 30 14:04:38 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.3
[Wed May 30 14:04:39 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.3-rc1
[Wed May 30 14:04:40 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.3
[Wed May 30 14:04:41 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.3-pl1
[Wed May 30 14:04:43 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.4-rc1
[Wed May 30 14:04:44 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.4-pl1
[Wed May 30 14:04:45 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.4-pl2
[Wed May 30 14:04:46 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.4-pl3
[Wed May 30 14:04:48 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.4-pl4
[Wed May 30 14:04:49 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.6.4
[Wed May 30 14:04:51 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.7.0-beta1
[Wed May 30 14:04:53 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.7.0-rc1
[Wed May 30 14:04:55 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.7.0-pl1
[Wed May 30 14:04:55 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.7.0-pl2
[Wed May 30 14:04:57 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.7.0
[Wed May 30 14:04:58 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0-beta1
[Wed May 30 14:05:00 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0-rc1
[Wed May 30 14:05:02 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0-rc2
[Wed May 30 14:05:03 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0
[Wed May 30 14:05:05 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0.1
[Wed May 30 14:05:06 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0.2
[Wed May 30 14:05:08 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0.3
[Wed May 30 14:05:09 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.0.4
[Wed May 30 14:05:10 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.1-rc1
[Wed May 30 14:05:12 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.1
[Wed May 30 14:05:13 2007] [error] [client 68.216.115.172] client denied by server configuration: D:/wamp/www/phpMyAdmin-2.8.2
Avatar billede bufferzone Praktikant
08. juni 2007 - 13:32 #1
1. Dette ligner en scanning med en applikations sårbarhedsscannet, f.eks. Nikto. Det er altså ikke et hack, men forberedelsen til det.

2. Nej det kan du aldrig.

3. Det ser indledningsvis ud som om du ikke er sårber over for det der her scannes efter, har du overhoved de forespurgte stier på serveren.

Du kan sikkert hardne din boks yderligere. Der findes masser af vejledninger på nettet til apache hardening se f.eks. www.nsa.gov
Avatar billede bufferzone Praktikant
08. juni 2007 - 13:33 #2
Ellers kan du overveje at tage IDS i brug, f.eks. Snort (www.snort.org) den vil kunne alarmmerer dig og sikkert også fortælle dig hvad der sker. Den kender f.eks. Nikto's signatur
Avatar billede 0xffff Nybegynder
08. juni 2007 - 14:54 #3
ok, takker. Vil prøve at kigge på de sites du har listet.
Avatar billede bufferzone Praktikant
08. juni 2007 - 14:59 #4
Hold også øje med dine logs og hvis du har forskellige web løsninger, det kunne f.eks. være phpmyadmin eller jomla så kik på http://www.securityfocus.com/bid og klik dig frem til om disse systemer er sårbare. om der er løsninger til disse sårbarheder
Avatar billede Ny bruger Nybegynder

Din løsning...

Tilladte BB-code-tags: [b]fed[/b] [i]kursiv[/i] [u]understreget[/u] Web- og emailadresser omdannes automatisk til links. Der sættes "nofollow" på alle links.

Loading billede Opret Preview
Kategori
Uanset kodesprog, så giver vi dig mulighederne for at udvikle det, du behøver.

Log ind eller opret profil

Hov!

For at kunne deltage på Computerworld Eksperten skal du være logget ind.

Det er heldigvis nemt at oprette en bruger: Det tager to minutter og du kan vælge at bruge enten e-mail, Facebook eller Google som login.

Du kan også logge ind via nedenstående tjenester