Re: Apache logs filled with remote exploit trials

2006-01-16 Thread Joakim Aronius
Hi, Implemented these rewrite rules a while ago (think someone on this list suggested it): RewriteEngine on # RewriteLog "logs/rewrite.log" # RewriteLogLevel 1 RedirectMatch permanent (.*)cmd.exe(.*)$ http://www.dhs.gov RedirectMatch permanent (.*)root.exe(.*)$ http://www.dhs.gov Redi

Re: Apache logs filled with remote exploit trials

2006-01-16 Thread Alexander Bochmann
...on Mon, Jan 16, 2006 at 12:34:54PM +0100, Didier Wiroth wrote: > [Sun Jan 15 20:53:24 2006] [error] [client 69.60.121.159] File does not > exist: /htdocs/xmlsrv/xmlrpc.php > How do "you" handle these kind of attacks? Ignoring them, mostly. It's the attack script of the month. > How or wh

Apache logs filled with remote exploit trials

2006-01-16 Thread Didier Wiroth
Hello, My apache logs are filled with these kind of attacks: [Sun Jan 15 20:53:19 2006] [error] [client 69.60.121.159] File does not exist: /htdocs/drupal/xmlrpc.php [Sun Jan 15 20:53:20 2006] [error] [client 69.60.121.159] File does not exist: /htdocs/phpgroupware/xmlrpc.php [Sun Jan 15 20:53:21