IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Re: That explains my apache error log.
Snippets from the Apache 1.3.34-1 error log for my main domain:
[Tue Dec  6 07:34:55 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/awstats/awstats.pl\n[Tue Dec  6 07:34:57 2005] [error] /usr/www/mikevitale/cgi-bin/awstats.pl not found or unable to stat\n[Tue Dec  6 07:34:58 2005] [error] [client 80.81.122.177] script not found or unable to stat: /usr/www/mikevitale/cgi-bin/awstats\n[Tue Dec  6 07:35:00 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/xmlrpc.php\n[Tue Dec  6 07:35:02 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/blog/xmlrpc.php\n[Tue Dec  6 07:35:03 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/blog/xmlsrv/xmlrpc.php\n[Tue Dec  6 07:35:04 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/blogs/xmlsrv/xmlrpc.php\n[Tue Dec  6 07:35:05 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/drupal/xmlrpc.php\n[Tue Dec  6 07:35:07 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/phpgroupware/xmlrpc.php\n[Tue Dec  6 07:35:08 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/wordpress/xmlrpc.php\n[Tue Dec  6 07:35:09 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/xmlrpc.php\n[Tue Dec  6 07:35:10 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/xmlrpc/xmlrpc.php\n[Tue Dec  6 07:35:12 2005] [error] [client 80.81.122.177] File does not exist: /usr/www/mikevitale/xmlsrv/xmlrpc.php\n[Sun Dec 11 13:45:36 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/webcalendar/tools/send_reminders.php\n[Sun Dec 11 13:45:37 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/WebCalendar/tools/send_reminders.php\n[Sun Dec 11 13:45:37 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/cacti/include/config_settings.php\n[Sun Dec 11 13:45:37 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/calendar/tools/send_reminders.php\n[Sun Dec 11 13:45:38 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/webcalendar/ws/get_reminders.php\n[Sun Dec 11 13:45:38 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/WebCalendar/ws/get_reminders.php\n[Sun Dec 11 13:45:38 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/calendar/ws/get_reminders.php\n[Sun Dec 11 13:45:39 2005] [error] [client 65.203.134.100] File does not exist: /usr/www/mikevitale/events/tools/send_reminders.php\n[Thu Dec 15 11:02:22 2005] [error] [client 195.250.24.66] File does not exist: /usr/www/mikevitale/index2.php\n[Thu Dec 15 11:02:23 2005] [error] [client 195.250.24.66] File does not exist: /usr/www/mikevitale/index.php\n[Thu Dec 15 11:02:25 2005] [error] [client 195.250.24.66] File does not exist: /usr/www/mikevitale/mambo/index2.php\n[Thu Dec 15 11:02:26 2005] [error] [client 195.250.24.66] File does not exist: /usr/www/mikevitale/cvs/mambo/index2.php
Dunno if that provides any insight, but more information never hurts...
-YendorMike

"They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety."
- Benjamin Franklin, 1759 Historical Review of Pennsylvania
New probably a script trying the following
[link|http://www.html4.com/mime/markup/php/how_to_en/how_to_system_en/how_to_system_4.php|http://www.html4.com...w_to_system_4.php]

IN THE FOLLOWING LINES, THE SPAMMER HAS TRIED TO PASS ORDERS TO THE AWSTATS PROGRAM.
SEE THE .htaccess FILE TO BLOCK THE "DataCha0s/2.0" USER-AGENT STRING.
131.220.68.66 - - [04/Aug/2005:22:24:17 +0200] "GET /awstats/awstats.pl?configdir=|echo;echo;id;%00 HTTP/1.0" 404 176125 "-" "DataCha0s/2.0"
131.220.68.66 - - [04/Aug/2005:22:24:26 +0200] "GET /cgi-bin/awstats.pl?configdir=|echo;echo;id;%00 HTTP/1.0" 404 1725 "-" "DataCha0s/2.0"
131.220.68.66 - - [04/Aug/2005:22:24:16 +0200] "GET /cgi-bin/awstats/awstats.pl?configdir=|echo;echo;id;%00 HTTP/1.0" 404 1725 "-" "DataCha0s/2.0"
"the reason people don't buy conspiracy theories is that they think conspiracy means everyone is on the same program. Thats not how it works. Everybody has a different program. They just all want the same guy dead. Socrates was a gadfly, but I bet he took time out to screw somebodies wife" Gus Vitelli

Any opinions expressed by me are mine alone, posted from my home computer, on my own time as a free american and do not reflect the opinions of any person or company that I have had professional relations with in the past 49 years. meep
questions, help? [link|mailto:pappas@catholic.org|email pappas at catholic.org]
New Well, whatever the reason...
I'd think that preventing spamd from starting 7000 processes would be a good thing...
Regards,

-scott anderson

"Welcome to Rivendell, Mr. Anderson..."
New turn off sendmail and spamd till issue found
"the reason people don't buy conspiracy theories is that they think conspiracy means everyone is on the same program. Thats not how it works. Everybody has a different program. They just all want the same guy dead. Socrates was a gadfly, but I bet he took time out to screw somebodies wife" Gus Vitelli

Any opinions expressed by me are mine alone, posted from my home computer, on my own time as a free american and do not reflect the opinions of any person or company that I have had professional relations with in the past 49 years. meep
questions, help? [link|mailto:pappas@catholic.org|email pappas at catholic.org]
New It is not spamd with 7K pids.
it is the direct calling of "sendmail" and alias to exim4 with user perms, that is causing the unhealthy load.
--
[link|mailto:greg@gregfolkert.net|greg],
[link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
Freedom is not FREE.
Yeah, but 10s of Trillions of US Dollars?
SELECT * FROM scog WHERE ethics > 0;

0 rows returned.
New That has a familiar look.
I can't fish it out now, but there were a lot of attempts to xmlrpc.php, like you have there. So we know it's the same type of attack. :-)

I checked my email logs and there were no mass-outbound emails, so they never got in to do that.

Wade.
"Insert crowbar. Apply force."
     Z's *really* sluggish for me - elsewhere's OK. Something up? -NT - (Another Scott) - (22)
         Ditto here. -NT - (a6l6e6x) - (3)
             That...makes...three...of...us......... -NT - (jb4) - (2)
                 Everything is sluggish for me - (bepatient) - (1)
                     Yup, even my RFC-1149g pigeons have slack-wing today :( -NT - (Ashton)
         nailed by spamd - (Yendor) - (17)
             ouch. - (Steve Lowe)
             virilent Sobor making the rounds, hotmail on its knees -NT - (boxley)
             Could bird flu be mutated Windoze? - (Ashton)
             There is an undiscovered by me... - (folkert) - (13)
                 can you post/send associated data of a "sent" email please? -NT - (boxley) - (2)
                     Maybe tomorrow. -NT - (folkert) - (1)
                         we are seeing a large push of stuff at the moment - (boxley)
                 That explains my apache error log. - (static) - (6)
                     Re: That explains my apache error log. - (Yendor) - (5)
                         probably a script trying the following - (boxley) - (3)
                             Well, whatever the reason... - (admin) - (2)
                                 turn off sendmail and spamd till issue found -NT - (boxley)
                                 It is not spamd with 7K pids. - (folkert)
                         That has a familiar look. - (static)
                 In the meantime... - (admin) - (2)
                     It already is being limited. (And problems fixed) - (folkert) - (1)
                         Thankee sai. -NT - (Another Scott)

Let's ask the Magic Conch Shell!
67 ms