There has been a continuous attack on Apache in cpanel...
The http error logs show attack pattern as follows .....
tail -f /usr/local/apache/logs/error_log
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK jrtfc\\rUSER csmxaohd
\\"\\" \\"\\" :gpab\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK jjjhnl\\rUSER nlawdw
\\"\\" \\"\\" :kcnt\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK kdumxigr\\rUSER gtqxa
\\"\\" \\"\\" :xvbdxmkn\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK qmpxknxi\\rUSER dnxelvf
\\"\\" \\"\\" :mtccg\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK ualo\\rUSER xnrure
\\"\\" \\"\\" :qcqyu\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK yyhvj\\rUSER hrpjunq
\\"\\" \\"\\" :kryorv\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK qwte\\rUSER hcgrwvt
\\"\\" \\"\\" :popmvl\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK mygfhb\\rUSER putfuil
\\"\\" \\"\\" :rmog\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK gkunh\\rUSER bvvi
\\"\\" \\"\\" :bgbfvms\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK fayhqcdx\\rUSER dyoyyx
\\"\\" \\"\\"
We have added the NICK pattern to modsec rules.. but this doesnot resolve the
issue..
Please advise.
The http error logs show attack pattern as follows .....
tail -f /usr/local/apache/logs/error_log
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK jrtfc\\rUSER csmxaohd
\\"\\" \\"\\" :gpab\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK jjjhnl\\rUSER nlawdw
\\"\\" \\"\\" :kcnt\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK kdumxigr\\rUSER gtqxa
\\"\\" \\"\\" :xvbdxmkn\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK qmpxknxi\\rUSER dnxelvf
\\"\\" \\"\\" :mtccg\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK ualo\\rUSER xnrure
\\"\\" \\"\\" :qcqyu\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK yyhvj\\rUSER hrpjunq
\\"\\" \\"\\" :kryorv\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK qwte\\rUSER hcgrwvt
\\"\\" \\"\\" :popmvl\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK mygfhb\\rUSER putfuil
\\"\\" \\"\\" :rmog\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK gkunh\\rUSER bvvi
\\"\\" \\"\\" :bgbfvms\\r
[Sat Oct 21 17:47:52 2006] [error] [client 219.110.29.162] request failed:
erroneous characters after protocol string: NICK fayhqcdx\\rUSER dyoyyx
\\"\\" \\"\\"
We have added the NICK pattern to modsec rules.. but this doesnot resolve the
issue..
Please advise.