Ver Mensaje Individual
  #1 (permalink)  
Antiguo 18/06/2015, 16:01
quebien
 
Fecha de Ingreso: febrero-2007
Mensajes: 309
Antigüedad: 17 años, 9 meses
Puntos: 16
Pregunta Extraño log de apache

Hola!

Estoy teniendo un comportamiento extraño en mi sitio web, aparentemente el FCKEditor (que no uso en mi sitio) esta llamando a mi web con infinidad de request solicitando archivos que no existen y que nunca existieron.

Esto me trae el problema de que me agota el ancho de banda. Normalmente por dia mi ancho de banda es de 400 mb y ahora es de 2 Gigas por día. Colapsando mi servidor.

Es un ataque de algun tipo?

142.54.174.178 - - [18/Jun/2015:12:10:03 -0500] "GET /dekra/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:03 -0500] "GET / /html/images_sys/fckeditor.o/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:03 -0500] "GET /adminicpsb/script/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:03 -0500] "GET /gbe/modules/content/admin/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:03 -0500] "GET /blog/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /webmanager/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /controls/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /crm/include/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /sites/efeefe.no-ip.org/modules_bak/fckeditor/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /kmustkjc/plugins/editors/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /newsite/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /sites/all/modules/fckeditor/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /system/lib/ext/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /portfolio/aui/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /site/lib/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /joshiken/html/mambots/editors/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /~documents/CMGA6/registration/public/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /javascript/editors/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /html/editor/wp-content/plugins/fckeditor_for_wordpress/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /cf/scripts/ajax/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /UI/Tools/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /adm_gerencia/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /stara/include/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /~pi/opiti/pppblog/FCKeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /user_data/packages/miyabunnew/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /common/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /libs/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /webmail/plugins/html_mail/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /jeunes/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /wysiwyg/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /drupal/sites/all/modules/fckeditor/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
142.54.174.178 - - [18/Jun/2015:12:10:04 -0500] "GET /admin/libexterne/fckeditor/editor/fckeditor.html HTTP/1.1" 500 7378 "-" "-"
y hay mas....

Visor visual de logs de apache:



Otro log extraño que veo es el Googlebot pidiendo mi robots.txt cada 10 segundos o menos!, tengo miles de esos request:

66.249.67.7 - - [18/Jun/2015:15:12:03 -0500] "GET /robots.txt HTTP/1.1" 500 7374 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.124 - - [18/Jun/2015:15:12:06 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.14 - - [18/Jun/2015:15:12:14 -0500] "GET /robots.txt HTTP/1.1" 500 7374 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.118 - - [18/Jun/2015:15:12:16 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.124 - - [18/Jun/2015:15:12:26 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.14 - - [18/Jun/2015:15:12:35 -0500] "GET /robots.txt HTTP/1.1" 500 7374 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.112 - - [18/Jun/2015:15:12:36 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.118 - - [18/Jun/2015:15:12:46 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.14 - - [18/Jun/2015:15:12:52 -0500] "GET /robots.txt HTTP/1.1" 500 7374 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.112 - - [18/Jun/2015:15:12:56 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.118 - - [18/Jun/2015:15:13:06 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.124 - - [18/Jun/2015:15:13:16 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.7 - - [18/Jun/2015:15:13:18 -0500] "GET /robots.txt HTTP/1.1" 500 7374 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.118 - - [18/Jun/2015:15:13:26 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.124 - - [18/Jun/2015:15:13:36 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.124 - - [18/Jun/2015:15:13:46 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.118 - - [18/Jun/2015:15:13:56 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.124 - - [18/Jun/2015:15:14:06 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.14 - - [18/Jun/2015:15:14:13 -0500] "GET /robots.txt HTTP/1.1" 500 7374 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.112 - - [18/Jun/2015:15:14:16 -0500] "GET /robots.txt HTTP/1.1" 500 7378 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
66.249.67.118 - - [18/Jun/2015:15:14:26 -0500] "GET /robots.txt HTTP/1.1" 500



Me podrá alguien guiar un poco? Gracias!
__________________
Responder encuestas