Portál AbcLinuxu, 5. května 2025 15:52
tcp 0 0 xxx.xxx.xxx.xxx:37014 222.122.39.161:80 TIME_WAIT tcp 0 0 xxx.xxx.xxx.xxx:44260 209.85.148.103:80 TIME_WAIT tcp 0 1 xxx.xxx.xxx.xxx:48150 121.14.152.46:80 SYN_SENTA také IPv6, jestli to dobře chápu:
tcp6 0 0 xxx.xxx.xxx.xxx:80 88.71.83.126:53294 TIME_WAIT tcp6 0 0 xxx.xxx.xxx.xxx:80 89.74.188.233:1620 TIME_WAIT tcp6 0 0 xxx.xxx.xxx.xxx:80 219.131.173.94:1139 FIN_WAIT2Tohle je výstup z apache statusu:
1-0 13473 2/5/5 K 0.01 13 30 0.0 0.01 0.01 118.123.215.166 xxx.xxx.xxx POST http://r.admob.com/ad_source.php HTTP/1.1 2-0 13474 1/8/8 C 0.02 1 1667 20.0 0.12 0.12 212.117.168.22 xxx.xxx.xxx GET http://tib.dodlive.mil/2010/12/20/my-hero/comment-page-1/?r 3-0 13475 0/2/2 W 0.02 10 0 0.0 0.00 0.00 76.73.4.18 xxx.xxx.xxx GET http://www.ku70.com/ HTTP/1.1 4-0 13476 4/4/4 K 0.00 1 110 14.5 0.01 0.01 193.110.115.58 xxx.xxx.xxx GET http://dreamscity.combats.com/main.pl?rnd=0.448367925421856 5-0 13477 0/0/0 W 0.00 13 0 0.0 0.00 0.00 109.104.179.219 xxx.xxx.xxx GET http://www.moterostrailmadrid.es/modules.php?name=Reviews&r 6-0 13478 3/4/4 K 0.01 0 4987 9.4 0.01 0.01 219.134.238.38 xxx.xxx.xxx GET http://c.baidu.com/c.gif?t=0&q=%B6%AB%DD%B8%D1%B9%BB%FAB%EA 7-0 13479 1/8/8 C 0.02 0 375 20.9 0.12 0.12 89.74.188.233 xxx.xxx.xxx GET http://purepleasure.pl/posting.php?mode=post&f=122 HTTP/1.0 9-0 13481 0/2/2 W 0.00 1 0 0.0 0.00 0.00 204.45.109.18 xxx.xxx.xxx GET http://www.ku70.com/Taocao/ HTTP/1.1Návštěvnost mých stránek je mizivá. Když povypínám všechny vhosty a nechám jen defaultní vhost bez obsahu, pak je situace stejná. Pokud vypnu Apache, tak postupně vše odezní (zmizí z nestatu). Pokud pustím lighttpd, pak je situace stejna (jeden vhost do prázdného adresáře). V obou případech bez podpory PHP. V čem to může být? Podle tcpdumpu jsou také spojení z mého serveru. Díky.
Řešení dotazu:
76.73.108.42 - - [25/Feb/2011:18:16:59 +0100] "GET http://chek.zennolab.com/proxy.php HTTP/1.1" 200 271 "RefererString" "Mozilla / 4.0" 212.95.32.234 - - [25/Feb/2011:18:16:57 +0100] "GET http://www.pornbling.com/ HTTP/1.0" 200 66865 "-" "Opera/9.63 (Windows NT 6.1; U; ru) Presto/2.1.1" 112.81.56.247 - - [25/Feb/2011:18:16:54 +0100] "GET http://blog.china.alibaba.com/blog/a344481/click.html?iframe_delete=true HTTP/1.1" 200 750 "http://a344481.blog.china.alibaba.com/" "Mozilla/5.0 (Windows; U; Windows NT 5.1; zh-CN; rv:1.7.6)" 218.204.58.60 - - [25/Feb/2011:18:16:59 +0100] "GET http://ads.adonion.com/serving/zone.php?ob=1&zone_id=36623&user_id=16883&site_id=14741&random=8998 HTTP/1.0" 200 531 "http://www.naturalnews.com/Report_Breast_Cancer_Deception_13.html" "Windows-RSS-Platform/2.0 (MSIE 8.0; Windows NT 6.0)" 92.62.114.45 - - [25/Feb/2011:18:16:58 +0100] "GET http://www.google.com/search?client=navclient-auto&ch=6-351446600&features=Rank&q=info:bloodandhonor.cs-mapping.com.ua HTTP/1.0" 403 5148 "http://www.google.com/search?client=navclient-auto&ch=6-351446600&features=Rank&q=info:bloodandhonor.cs-mapping.com.ua" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)" 212.117.168.183 - - [25/Feb/2011:18:16:57 +0100] "POST http://westly2006.com/wp-comments-post.php HTTP/1.1" 302 852 "http://westly2006.com/?p=1" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)" 212.95.32.92 - - [25/Feb/2011:18:16:58 +0100] "POST http://www.chabadgz.org/ch/MessageSave.asp?MemberID=0 HTTP/1.1" 200 340 "http://www.chabadgz.org/ch/MessageWrite.asp" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)" 79.41.196.98 - - [25/Feb/2011:18:16:59 +0100] "GET http://119.161.12.193/config/login?.patner=sbc&login=_frank__rizzo_&passwd=football&.save=1 HTTP/1.0" 999 6304 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.5) Gecko/20091102 Firefox/3.5.5" 175.42.64.199 - - [25/Feb/2011:18:16:59 +0100] "GET http://ptlogin2.qq.com/login?u=1049663385&p=1753E57A6FD8847A31B0695AC811C35B&verifycode=ttne&webqq_type=1&remember_uin=1&aid=8000203&u1=http%3A%2F%2Fweb2.qq.com%2Floginproxy.html%3Frun%3Deqq%26strong%3Dtrue&h=1&ptredirect=0&ptlang=2052&from_ui=1&pttype=1&dumy=&fp=loginerroralert HTTP/1.1" 200 365 "-" "Mozilla/5.0 (Windows; U; Windows NT 6.1; zh-CN; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8"
/etc/apache2# apache2ctl -f /etc/apache2/apache2.conf -e debug [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module alias_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module auth_basic_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module authn_file_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module authz_default_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module authz_groupfile_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module authz_host_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module authz_user_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module autoindex_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module cgi_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module deflate_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module dir_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module env_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module mime_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module negotiation_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module php5_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module reqtimeout_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module rewrite_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module setenvif_module [Fri Feb 25 21:16:59 2011] [debug] mod_so.c(246): loaded module status_moduleNebo:
/etc/apache2# apache2ctl -t -D DUMP_MODULES Loaded Modules: core_module (static) log_config_module (static) logio_module (static) mpm_prefork_module (static) http_module (static) so_module (static) alias_module (shared) auth_basic_module (shared) authn_file_module (shared) authz_default_module (shared) authz_groupfile_module (shared) authz_host_module (shared) authz_user_module (shared) autoindex_module (shared) cgi_module (shared) deflate_module (shared) dir_module (shared) env_module (shared) mime_module (shared) negotiation_module (shared) php5_module (shared) reqtimeout_module (shared) rewrite_module (shared) setenvif_module (shared) status_module (shared) Syntax OK
# debsums -s debsums: no md5sums for binutils debsums: no md5sums for dhcp3-client debsums: no md5sums for doc-debian debsums: no md5sums for libdb4.5 debsums: no md5sums for mawk debsums: no md5sums for netbaseZkusil jsem i vypnout mod_rewrite, odinstaloval jsem mod_proxy (libapache2-mod-proxy-html).
telnet <server> 80 # a napsat: GET http://www.google.com/ HTTP/1.0 # a 2x enterMělo by to buď zařvat chybu a nebo vrátit lokální stránku - pokud vrátí google.com, tak je problém...
[Fri Feb 25 21:33:06 2011] [error] [client 89.74.188.233] script '/var/www/index.php' not found or unable to stat, referer: http://www.arpin.com/index.php [Fri Feb 25 21:33:06 2011] [error] [client 72.130.126.126] File does not exist: /var/www/FAQ, referer: http://www.anontalk.se/shitlisted [Fri Feb 25 21:33:06 2011] [error] [client 76.73.4.34] File does not exist: /var/www/index.html, referer: www.google.com [Fri Feb 25 21:33:07 2011] [error] [client 79.86.16.83] Attempt to serve directory: /var/www/ [Fri Feb 25 21:33:07 2011] [error] [client 83.169.12.178] File does not exist: /var/www/search, referer: http://search.yahoo.com/search?p=id.com+inurl:article.htm&sm=Yahoo%21+Search&fr=FP-tab-web-t&toggle=1&cop=&ei=UTF-8 [Fri Feb 25 21:33:07 2011] [error] [client 204.45.109.18] File does not exist: /var/www/index.html, referer: www.google.com [Fri Feb 25 21:33:07 2011] [error] [client 72.130.126.126] File does not exist: /var/www/spell_checking, referer: http://www.anontalk.se/shitlisted [Fri Feb 25 21:33:07 2011] [error] [client 209.190.31.67] File does not exist: /var/www/client [Fri Feb 25 21:33:07 2011] [error] [client 83.169.12.178] File does not exist: /var/www/search, referer: http://search.yahoo.com/search?p=id.com+inurl:catalog.&sm=Yahoo%21+Search&fr=FP-tab-web-t&toggle=1&cop=&ei=UTF-8 [Fri Feb 25 21:33:07 2011] [error] [client 89.223.24.135] script '/var/www/dorf1.php' not found or unable to stat, referer: http://speed.travian.ru/dorf1.php [Fri Feb 25 21:33:07 2011] [error] [client 193.110.115.58] File does not exist: /var/www/inf.pl
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.