Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Registered User
    Join Date
    Sep 2006
    Posts
    4

    Default weird apache requests

    hi, ive started noticing a lot of the following requests when i goto apache-status in whm

    127.0.0.1 - - [02/Mar/2008:21:49:42 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:43 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:44 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:45 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:46 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:47 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:48 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:49 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:50 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:51 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:52 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:53 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:54 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:55 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:56 +1100] "OPTIONS * HTTP/1.0" 200 -
    127.0.0.1 - - [02/Mar/2008:21:49:57 +1100] "OPTIONS * HTTP/1.0" 200 -

    what are these requests for? how to i find out whats causing it and how do i get rid of it?

    thanks

  2. #2
    Member viraj's Avatar
    Join Date
    Sep 2006
    Location
    India
    Posts
    209
    cPanel/Enkompass Access Level

    DataCenter Provider

    Lightbulb

    Hi,

    I am 90% sure that this is an outbreak of an attack, which is more rather DDoS. Check netstat outputs. I'll reply more when I find something 100% sure

  3. #3
    Member cpanelinfoseeker's Avatar
    Join Date
    Oct 2002
    Location
    NE Illinois
    Posts
    320

    Default

    I'm having a TON of these in /usr/local/apache/logs/access_log, but instead of 127.0.0.1 is is actually using an unused IP address:

    unused ip - - [07/Mar/2008:12:49:10 -0500] "OPTIONS * HTTP/1.0" 200 -
    unused ip - - [07/Mar/2008:12:49:11 -0500] "OPTIONS * HTTP/1.0" 200 -
    unused ip - - [07/Mar/2008:12:49:12 -0500] "OPTIONS * HTTP/1.0" 200 -
    unused ip - - [07/Mar/2008:12:49:24 -0500] "OPTIONS * HTTP/1.0" 200 -

    (actual address removed) There could be as many as 20 with a 1 second spacing and a period of a few secoonds to a few minutes of nothing and it starts again.

    In WHM Apache Status there are many similar lines using the same unused IP. These also used to show 127.0.0.1 but now show an actual IP:

    17-0 - 0/0/2145 . 0.00 169 0 0.0 0.00 35.95 unused ip host.server.com OPTIONS * HTTP/1.0

    I had blocked the server IP in question, but this made no difference. Since it originally had the 127.0.0.1 ip showing, I guess something changed on the server to make it use one of the real IP addrersses.

    I haven't figured it out yet, but hope this helps someone with a better understanding to make some progress. My data center is also looking into this and does not think it is anthing dangerous, but can not determine what is causing these logs.

    Ron

  4. #4
    Registered User
    Join Date
    Sep 2006
    Posts
    4

    Default

    hmm btw, if this makes any difference, im on a vps using virtuoso.

  5. #5
    Member
    Join Date
    Mar 2007
    Location
    UK
    Posts
    18

    Default

    I am seeing the same thing on my VPS.

    Does anyone have any idea what is generating these requests?

    Code:
    ::1 - - [30/Apr/2008:04:43:26 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -
    ::1 - - [30/Apr/2008:04:43:28 +0100] "OPTIONS * HTTP/1.0" 200 -

  6. #6
    cPanel Partner NOC cPanel Partner NOC Badge anton_latvia's Avatar
    Join Date
    May 2004
    Posts
    277

    Default

    That is you, yourself and WHM, viewing "Apache status". I suppose you run Apache 2.x? Unfortunately I don't know how to fix it.. We simply use good-old Apache 1.3.
    * http://www.aleksandrov.eu/ - just a simple personal homepage.

Similar Threads & Tags
Similar threads

  1. apache and lots of read requests ???
    By zye in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 02-24-2007, 04:30 PM
  2. [syslogd] in apache processes and requests
    By shiv in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 10-05-2006, 01:36 PM
  3. apache requests on a different ip
    By Paxuist in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 06-06-2006, 10:06 AM
  4. Blocking Apache requests?
    By n1zyy in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-09-2004, 05:17 AM
  5. Tomcat requests and Apache
    By ialex03 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-14-2004, 10:20 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube