Strange Apache logs - maybe DDOS?

From: Christian Schwede (cschwede@delphi-gmbh.de)
Date: 11/15/02

  • Next message: H C: "re: Help - a possible bot"
    Date: 15 Nov 2002 09:31:30 -0000
    From: Christian Schwede <cschwede@delphi-gmbh.de>
    To: incidents@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Hi everybody,
    I have a little problem with our apache server. This is
    what my logs show me:

    access_log:

    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:28 +0100]
    "\xe3I" 501 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:28 +0100] "-" 408 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:29 +0100]
    "\xe3;" 501 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:29 +0100]
    "\xe37" 501 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:29 +0100]
    "\xe3I" 501 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:30 +0100] "-" 408 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:31 +0100] "-" 408 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:31 +0100] "-" 408 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:32 +0100]
    "\xe3I" 501 -
    [CLIENT_IP_ADDR] - - [13/Nov/2002:12:39:32 +0100]
    "\xe34" 501 -

    error_log:
    [Wed Nov 13 12:39:50 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?I
    [Wed Nov 13 12:39:50 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?E
    [Wed Nov 13 12:39:51 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?I
    [Wed Nov 13 12:39:52 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?E
    [Wed Nov 13 12:39:52 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?J
    [Wed Nov 13 12:39:52 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?=
    [Wed Nov 13 12:39:52 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?7
    [Wed Nov 13 12:39:54 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?4
    [Wed Nov 13 12:39:55 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?I
    [Wed Nov 13 12:39:55 2002] [error] [client
    [CLIENT_IP_ADDR]] Invalid
    method in request ?@

    So, what the heck is trying to access my server? I
    looked around at google for spyware or worm signatures,
    but none of them fits. Has anybody else seen this? It
    started on Monday, 21.Oct. 2002. We already had 630.000
    (in words: more than sixhundredthousands!) requests of
    this type. That are more than 200.000 requests a week.
    I really don't know what this is, but i think it's
    spyware. Can i prevent apache from responding to this
    requests? Maybe with the
    <FilesMatch> directive?

    Please Help me, tia! Christian

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management
    and tracking system please see: http://aris.securityfocus.com



    Relevant Pages

    • Re: invalid url and proxy
      ... generate invalid names. ... I'm really missing mls.ca. ... Invalid Request ... Illegal character in hostname; underscores are not allowed ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: 400 Bad Request for all files on IIS 6.0
      ... If IE reports "Bad Request (Invalid Hostname)", ... web site is using a specific IP other than "All unassigned". ...
      (microsoft.public.inetserver.iis)
    • Re: $20,999,999.00 eBay Auction Won!!!
      ... I couldn't resist sharing this though. ... Item 180170420342: Established Inernet Business 06 ... sean.brender (Invalid Request 53209, ...
      (alt.marketing.online.ebay)
    • "The request is invalid in the current state"
      ... Sometime, we don't know why, calling the startfunction we get the ... "The request is invalid in the current state" ...
      (microsoft.public.windowsmedia.sdk)
    • "The request is invalid in the current state"
      ... Sometime, we don't know why, calling the startfunction we get the ... "The request is invalid in the current state" ...
      (microsoft.public.windowsmedia.server)