C
C
crossfire2014-11-17 01:06:38
linux
crossfire, 2014-11-17 01:06:38

How to understand nginx logs on the server (sent by logwatch)? What is the type of attack?

Ubuntu Server 12.10 LTS
How to understand nginx logs on the server (logwatch sent)? What do the headings mean? What kind of attacks are these? How dangerous is this and how to deal with it?

Attempts to use known hacks by 5 hosts were logged 5 time(s) from:
109.73.246.238: 1 Time(s)
140.130.204.23: 1 Time(s)
198.20.69.74: 1 Time(s)
203.172.198.166: 1 Time (s) 218.164.22.93
: 1 Time(s) A total of 5
sites probed the
server 404 Not Found /myadmin/scripts/setup.php: 4 Time(s) /phpMyAdmin/scripts/setup.php: 4 Time(s) /pma/scripts/setup.php: 4 Time(s) /js/ignition/ themes/classic/img/logo.png: 2 Time(s)
/js/ignition/themes/classic/img/lx.jpg: 2 Time(s)
/checkupdate.asmx: 1 Time(s)
/evev/eve/ev.php: 1 Time(s)
/knkn/knk/kn .php: 1 Time(s)
/qoqo/qoq/qo.php: 1 Time(s)
/trtr/trt/tr.php: 1 Time(s)
/wp: 1 Time(s)
6.url.cn/ zc/chs/img/body.png: 1 Time(s)

Answer the question

In order to leave comments, you need to log in

2 answer(s)
E
Ergil Osin, 2014-11-17
@Ernillew

12.10 is not LTS. Moreover, 12.10 is no longer supported. Either downgrade to 12.04, which is really LTS, or upgrade to 14.04
. That's whatever the logs are.

D
Dmitry, 2014-11-17
@zmeyjr

In appearance, you were simply scanned for the presence of standard utilities and CMS. Cover admin area with your IP limit if possible yes fail2ban

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question