.................Citaat:
Oorspronkelijk geplaatst door Arto
Mod Evasive had ik al
Afdrukvoorbeeld
.................Citaat:
Oorspronkelijk geplaatst door Arto
Mod Evasive had ik al
Wilt iemand aub mij helpen met dit klote probleem.
IK wordt hier schijt ziek van.
Zie foto :
http://img381.imageshack.us/img381/9935/naamloosse0.jpg
Bijna elke 5 minuten loopt ie zo vast en moet ik telkens httpd en mysqld restarten
Heb je al proberen uit te vissen van welke van alle sites die je host de aanval vandaan komt? Dan kun je daar kijken wat er verkeerd zit in hun scripting.
Als het met mod_evasive nog steeds zo een problemen geeft...
Ik weet niet eens of het echt door een aanval komt, ik zie wel veel atacks in /temp
Maar via het log bestanden kan ik niks uithalen.
Of
- aanval
of
- een site die je host werkt niet goed met zijn /temp bestanden...
Moeten die niet opgekuist worden na gebruik?
Als ik zo het /var/log/httpd bekijk zie ik heel veel ssl_mutex bestanden
Zij ook bijlage voor error log
Ik denk dat er iets mis met openssl en mod_ssl
[Fri Aug 4 16:23:40 2006] [error] mod_ssl: SSL handshake failed (server shared.domain:443, client 219.133.128.185) (OpenSSL library error follows)
[Fri Aug 4 16:23:40 2006] [error] OpenSSL: error:1407609B:SSL routines:SSL23_GET_CLIENT_HELLO:https proxy request [Hint: speaking HTTP to HTTPS port!?]
[Fri Aug 4 16:23:40 2006] [error] mod_ssl: SSL handshake failed (server shared.domain:443, client 219.133.128.185) (OpenSSL library error follows)
[Fri Aug 4 16:23:40 2006] [error] OpenSSL: error:1407609B:SSL routines:SSL23_GET_CLIENT_HELLO:https proxy request [Hint: speaking HTTP to HTTPS port!?]
Kan iemand mij helpen aub?
Quote: http://www.tenon.com/lists/html/iToo.../msg00104.html
And I get a new ssl_mutex.* file in my log directory.
=> You can delete those files
Verder google:
if you have configured
SSLMutex to something other than default setting of "default" in the
Fedora /etc/httpd/conf.d/ssl.conf. Can you double-check that?
Kijk ff die ssl.conf na
Draai ook ff httpd configtest commando.
If aanval:
One thing you might try kind of tedious but is to go to WHM and suspend all the accounts on the server then try and restart apache. If it starts and will stay running then start unsuspending sites one at a time until it crashes that way you will know what site they are attacking.
Verder:
I sound a wake up call to all out there who feel their servers are secure. Both chkrootkit and rkhunter both say the server is clean but I have discovered its been hacked. How do I know - because titles in WHM have been altered - there is a service in the Service Manager called "EvilApache" - its pretty clear whats happened. So we are in the process of migrating clients away from the server to another server. But I just am amazed by this attack, it was completely undetectable and nothing protected us from it - it seems to be exploting an Apache weakness of somekind. This is a serious issue that needs to be addressed fast. Now I am worried about all our servers. Anyone who's had this similar issue with Apache - its a Hack of somekind thats pretty damn stealthy.
Bron:
http://www.webhostingtalk.com/archiv...29742-p-1.html
Ik vermoed dat het inderdaad een slechte instelling van ssl is...
Of van 1 van uw extensies zoals mod security...
Probeer allles te disablen en dan 1 per 1 te heractiveren tot de server crasht, dan weet je ongeveer waar het probleem zit...
Ik hoop dat ik je een beetje heb kunnen helpen, ik ken er zelf niet zo heeeel veel van... Maar aangezien verder niemand reageerde...