Hi there
The last few days my logs for modsecurity2 has started to grow rapidly. After deleting the excisting log and a reboot today i discovered the following lines inside the log a few minutes after successful reboot:
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2355b20][/mysql/admin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/"$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2355b20][/mysql/admin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_L$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2332a70][/mysql/sqlmanager/][1] Access denied with code 400 (phase 2). Pattern match "^\$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2332a70][/mysql/sqlmanager/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ER$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#234b120][/mysql/mysqlmanager/][1] Access denied with code 400 (phase 2). Pattern match "$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#234b120][/mysql/mysqlmanager/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#245fe20][/phpmyadmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#245fe20][/phpmyadmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpMyadmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpMyadmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2347b10][/phpMyAdmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2347b10][/phpMyAdmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#25fc7f0][/phpmyAdmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#25fc7f0][/phpmyAdmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpmyadmin2/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/"$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpmyadmin2/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_L$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2334a80][/2phpmyadmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/"$
The IP-adress of all these lines (there are plenty more) points towards one of my nameservers, and is not the "server-IP".
Whats going on? There are several hundred lines that refers to the following paths (that doesn't even exist i might ad):
/program/
/dbadmin/
/db/
/database/
/mysqlmanager/
/phpmy-admin/
...and a lot more. Is someone trying to hack my server?
The last few days my logs for modsecurity2 has started to grow rapidly. After deleting the excisting log and a reboot today i discovered the following lines inside the log a few minutes after successful reboot:
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2355b20][/mysql/admin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/"$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2355b20][/mysql/admin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_L$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2332a70][/mysql/sqlmanager/][1] Access denied with code 400 (phase 2). Pattern match "^\$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2332a70][/mysql/sqlmanager/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ER$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#234b120][/mysql/mysqlmanager/][1] Access denied with code 400 (phase 2). Pattern match "$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#234b120][/mysql/mysqlmanager/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#245fe20][/phpmyadmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#245fe20][/phpmyadmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpMyadmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpMyadmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2347b10][/phpMyAdmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2347b10][/phpMyAdmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#25fc7f0][/phpmyAdmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/" $
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#25fc7f0][/phpmyAdmin/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_LO$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpmyadmin2/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/"$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#233aab0][/phpmyadmin2/][2] Warning. Match of "rx ModSecurity" against "WEBSERVER_ERROR_L$
[28/Mar/2011:10:45:49 +0000] [188.138.43.161/sid#1cf7a00][rid#2334a80][/2phpmyadmin/][1] Access denied with code 400 (phase 2). Pattern match "^\w+:/"$
The IP-adress of all these lines (there are plenty more) points towards one of my nameservers, and is not the "server-IP".
Whats going on? There are several hundred lines that refers to the following paths (that doesn't even exist i might ad):
/program/
/dbadmin/
/db/
/database/
/mysqlmanager/
/phpmy-admin/
...and a lot more. Is someone trying to hack my server?