Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Strange httpd and TCP/135 logs...
- Date: Fri, 29 Aug 2003 12:02:21 +0900
- From: Michael Doughty <tlug@example.com>
- Subject: Re: [tlug] Strange httpd and TCP/135 logs...
- References: <20030828213357.154957f6.br@example.com>
- User-agent: Mutt/1.4i
On Thu, Aug 28, 2003 at 09:33:57PM +0900, Bruno Raoult wrote: > Since Aug 18th, my apache logs show a huge number of requests, coming from different IPs, > and always asking the home page (but not the images inside). <SNIP!> > Do you have an idea of what it could be? I would assume that this is the welchia worm trying to find out if it can exploit you or not. From what you said in your post, it seems that you think the same, but dismissed it because: > At the same moment, my router filter logs show a huge number of > requests on all my IP addresses on both ports 80 & 135. But I > cannot find any link between the source addresses (some addresses > scan port 80, and others port 135). I haven't looked at the source, but IIRC the worm is set to choose an IP address range randomly. I wouldn't be surprised if the two scans (RPC&HTTP) are done on different ranges. Not sure about the different sized returns from the home page. How large is the home page? Larger or smaller than the amount being transferred? Michael
- References:
- [tlug] Strange httpd and TCP/135 logs...
- From: Bruno Raoult
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] Strange httpd and TCP/135 logs...
- Next by Date: [tlug] setting up gateway on redhat 9
- Previous by thread: Re: [tlug] Strange httpd and TCP/135 logs...
- Next by thread: Re: [tlug] Strange httpd and TCP/135 logs...
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links