<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: am I being hacked? in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161977#M9072</link>
    <description>This concerns me a bit.&lt;BR /&gt;&lt;BR /&gt;What you should see in your apache access log is the google and other search engine bots logging on and trying to collect data on your public web sites.&lt;BR /&gt;&lt;BR /&gt;If you don't intend public access to these sites, I'd be very concerned and consider closing port 80 to the ourside world in iptables firewall.&lt;BR /&gt;&lt;BR /&gt;If you do allow public access to the websites in any way, then this stuff is normal. Google wants to know all about everything and its going to hit public websites for information on a regular basis.&lt;BR /&gt;&lt;BR /&gt;Does this help?&lt;BR /&gt;&lt;BR /&gt;I can dive deeper.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Mon, 12 Jan 2004 12:13:06 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2004-01-12T12:13:06Z</dc:date>
    <item>
      <title>am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161976#M9071</link>
      <description>Got RH Linux AS 2.1 and am running Apache 1.3 as a web server on the system.&lt;BR /&gt;&lt;BR /&gt;I am getting the following listings from the logwatch application (see snippet below). Is this trouble? I do have port 80 open in the ipchains so the web connection can be accomplished.&lt;BR /&gt;&lt;BR /&gt;As far as I know there should be no way to connect to a command line from http or https protocols. Has this changed? Or am I wrong?&lt;BR /&gt;&lt;BR /&gt;Many thanks!&lt;BR /&gt;&lt;BR /&gt;============================================================&lt;BR /&gt;Accepted packets from h24-87-195-143.vc.shawcable.net (24.87.195.143).&lt;BR /&gt;  Port http              (tcp,eth0,input): 6 packet(s).&lt;BR /&gt;Total of 6 packet(s).&lt;BR /&gt;&lt;BR /&gt;Accepted packets from crawler14.googlebot.com (64.68.82.168).&lt;BR /&gt;  Port http              (tcp,eth0,input): 2 packet(s).&lt;BR /&gt;Total of 2 packet(s).&lt;BR /&gt;&lt;BR /&gt;Accepted packets from h24-108-240-54.gv.shawcable.net (24.108.240.54).&lt;BR /&gt;  Port http              (tcp,eth0,input): 1 packet(s).&lt;BR /&gt;Total of 1 packet(s).&lt;BR /&gt;&lt;BR /&gt;Accepted packets from cpe002078cd2acf-cm014120006580.cpe.net.cable.rogers.com (24.157.154.174).&lt;BR /&gt;  Port http              (tcp,eth0,input): 1 packet(s).&lt;BR /&gt;Total of 1 packet(s).&lt;BR /&gt;&lt;BR /&gt;Accepted packets from c-24-8-74-89.client.comcast.net (24.8.74.89).&lt;BR /&gt;  Port http              (tcp,eth0,input): 8 packet(s).&lt;BR /&gt;Total of 8 packet(s).&lt;BR /&gt;&lt;BR /&gt;Accepted packets from drone7.sv.av.com (216.39.50.156).&lt;BR /&gt;  Port http              (tcp,eth0,input): 2 packet(s).&lt;BR /&gt;Total of 2 packet(s).</description>
      <pubDate>Mon, 12 Jan 2004 11:53:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161976#M9071</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2004-01-12T11:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161977#M9072</link>
      <description>This concerns me a bit.&lt;BR /&gt;&lt;BR /&gt;What you should see in your apache access log is the google and other search engine bots logging on and trying to collect data on your public web sites.&lt;BR /&gt;&lt;BR /&gt;If you don't intend public access to these sites, I'd be very concerned and consider closing port 80 to the ourside world in iptables firewall.&lt;BR /&gt;&lt;BR /&gt;If you do allow public access to the websites in any way, then this stuff is normal. Google wants to know all about everything and its going to hit public websites for information on a regular basis.&lt;BR /&gt;&lt;BR /&gt;Does this help?&lt;BR /&gt;&lt;BR /&gt;I can dive deeper.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 12 Jan 2004 12:13:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161977#M9072</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-01-12T12:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161978#M9073</link>
      <description>Hi SEP:&lt;BR /&gt;&lt;BR /&gt;I see the googlebot and understand the purpose of the *bot searches (I don't like them though)&lt;BR /&gt;but not all of the entries are from *bot searches.&lt;BR /&gt;&lt;BR /&gt;I also found a couple of entries stating the "ACCEPTED packets for port https" as well.&lt;BR /&gt;&lt;BR /&gt;My concern is that a hole (or holes) has been found in the apache http &amp;amp; https. Now it appears it is being exploited.&lt;BR /&gt;&lt;BR /&gt;Any other thoughts...</description>
      <pubDate>Mon, 12 Jan 2004 13:25:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161978#M9073</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2004-01-12T13:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161979#M9074</link>
      <description>Rick,&lt;BR /&gt;&lt;BR /&gt;I share your concerns.&lt;BR /&gt;&lt;BR /&gt;I am still running one apache 1.3.x web server fully patched.&lt;BR /&gt;&lt;BR /&gt;I'm running through the documentation and reports at &lt;A href="http://www.apache.org," target="_blank"&gt;http://www.apache.org,&lt;/A&gt; trying to find something on this.&lt;BR /&gt;&lt;BR /&gt;I'd say contact Berlene Herren at HP, but HP doesn't support that version of apache any more.&lt;BR /&gt;&lt;BR /&gt;For now consider this:&lt;BR /&gt;Block the source ip of the exploited inquirires. Here is a thread that shows how to do it.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=364287" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=364287&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 12 Jan 2004 13:40:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161979#M9074</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-01-12T13:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161980#M9075</link>
      <description>This entry is in the IP tables for access - this is a public webserver.&lt;BR /&gt;&lt;BR /&gt;Initially there were not any ACCEPTED packets from http, this while the webserver running on port 80.&lt;BR /&gt;&lt;BR /&gt;Now I am getting these entries.&lt;BR /&gt;&lt;BR /&gt;I have not made any changes to the IPTABLES but I'm trying to find out why all of the sudden I am getting these ACCEPTED packets.</description>
      <pubDate>Mon, 12 Jan 2004 13:50:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161980#M9075</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2004-01-12T13:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161981#M9076</link>
      <description>Hello Rick,&lt;BR /&gt;&lt;BR /&gt;if you do not like the bots crawling your server setup a robots.txt exclusion file. At least the well behaved bots honor the directives in there.&lt;BR /&gt;&lt;BR /&gt;Greetings, Martin</description>
      <pubDate>Mon, 12 Jan 2004 18:48:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161981#M9076</guid>
      <dc:creator>Martin P.J. Zinser</dc:creator>
      <dc:date>2004-01-12T18:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: am I being hacked?</title>
      <link>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161982#M9077</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;To determine whether this is exploit traffic , I want the apache logs access_log) for these source IP addresses.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;U.SivaKumar.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 12 Jan 2004 23:36:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/am-i-being-hacked/m-p/3161982#M9077</guid>
      <dc:creator>U.SivaKumar_2</dc:creator>
      <dc:date>2004-01-12T23:36:23Z</dc:date>
    </item>
  </channel>
</rss>

