Strange Apache Server Logs
We are having a Cloud Based ERP application which is written in python and running on apache webserver. Its working fine, and we are using DigitalOcean Droplets for hosting our application.
We are having more than 250 droplets, and everything works fine. Unfortuantely, now we noticed some strange entries in apache access logs as follows (SSL Already enabled on server)
94.24.83.13 - - [01/Jan/2019:11:11:02 +0000] "/x17\xbcx8exc9{vxdcxb7xeexc8xb0[xc7(x12Wx88x135xcbx1axfb59xbdxb0exeax023m~xaarxefsx06x7fxb1x80Fx91bx97pxbfxd5.xdbx1ax15U" 400 301 "-" "-"
37.32.127.218 - - [01/Jan/2019:11:11:02 +0000] "xc3xf4xe2x14xab_xe2x05SUx95}Zxa5txbdx1dxc0Jxc4xa7xe6x1exdexcf<xa5xd4xc0x84rx1fx8ax8fPxe2xedxd7xf4xdbxafx06Exxf3Wx1axfexccx01J@xe1xd0x9f3x0fxbcxf5 Rxb3xc0Bxafx18x83;xbay.x84K3x99x9dx19xc9xa4,x1bUbxb2pxcfix1dxe8nx82x02xf9xfbxadF^xc4xe6x1bxf5)wx93xc8,xa1xd0xfc;x0ex89HAx1ex10{$:xc3xf5ozx98Rxb8xd5Qxa0x87xe6xc0x9bxb8x8eIxa8oxebxc5xkxfexc0xf27x8eF*t5xb8x06xd1)lxdfx0exc8xe3xb6xadxb5xc7#xcdEx83xc1x0e#xfc`xa7;xe7K/2x98IlhYix1cxc4xa9xe8x86TxcbS>>xc5tx10=*x11GLxb0xa55xd77r4xd4|Dxe2" 400 447 "-" "-"
95.162.183.101 - - [01/Jan/2019:11:11:02 +0000] ")xc1(U/xa2xe5rx9aFBxefx0fxcb*xdfxf33%xdbx83x84xa7ax88xaaxb0xxe0xe5xf3b92Lx9dEGxc5x1cx15x16xfbHkxdebxcex86uNxd1xedxa7x0cx10xd8xbb\*x18" 400 301 "-" "-"
There are many requests like this from different IPs. All are Iran based IPs
Can anyone please tell me, what is meant by these logs ? And why they don't have any method like GET/POST/HEAD. Also how can we block these type of requests?
apache ddos
add a comment |
We are having a Cloud Based ERP application which is written in python and running on apache webserver. Its working fine, and we are using DigitalOcean Droplets for hosting our application.
We are having more than 250 droplets, and everything works fine. Unfortuantely, now we noticed some strange entries in apache access logs as follows (SSL Already enabled on server)
94.24.83.13 - - [01/Jan/2019:11:11:02 +0000] "/x17\xbcx8exc9{vxdcxb7xeexc8xb0[xc7(x12Wx88x135xcbx1axfb59xbdxb0exeax023m~xaarxefsx06x7fxb1x80Fx91bx97pxbfxd5.xdbx1ax15U" 400 301 "-" "-"
37.32.127.218 - - [01/Jan/2019:11:11:02 +0000] "xc3xf4xe2x14xab_xe2x05SUx95}Zxa5txbdx1dxc0Jxc4xa7xe6x1exdexcf<xa5xd4xc0x84rx1fx8ax8fPxe2xedxd7xf4xdbxafx06Exxf3Wx1axfexccx01J@xe1xd0x9f3x0fxbcxf5 Rxb3xc0Bxafx18x83;xbay.x84K3x99x9dx19xc9xa4,x1bUbxb2pxcfix1dxe8nx82x02xf9xfbxadF^xc4xe6x1bxf5)wx93xc8,xa1xd0xfc;x0ex89HAx1ex10{$:xc3xf5ozx98Rxb8xd5Qxa0x87xe6xc0x9bxb8x8eIxa8oxebxc5xkxfexc0xf27x8eF*t5xb8x06xd1)lxdfx0exc8xe3xb6xadxb5xc7#xcdEx83xc1x0e#xfc`xa7;xe7K/2x98IlhYix1cxc4xa9xe8x86TxcbS>>xc5tx10=*x11GLxb0xa55xd77r4xd4|Dxe2" 400 447 "-" "-"
95.162.183.101 - - [01/Jan/2019:11:11:02 +0000] ")xc1(U/xa2xe5rx9aFBxefx0fxcb*xdfxf33%xdbx83x84xa7ax88xaaxb0xxe0xe5xf3b92Lx9dEGxc5x1cx15x16xfbHkxdebxcex86uNxd1xedxa7x0cx10xd8xbb\*x18" 400 301 "-" "-"
There are many requests like this from different IPs. All are Iran based IPs
Can anyone please tell me, what is meant by these logs ? And why they don't have any method like GET/POST/HEAD. Also how can we block these type of requests?
apache ddos
add a comment |
We are having a Cloud Based ERP application which is written in python and running on apache webserver. Its working fine, and we are using DigitalOcean Droplets for hosting our application.
We are having more than 250 droplets, and everything works fine. Unfortuantely, now we noticed some strange entries in apache access logs as follows (SSL Already enabled on server)
94.24.83.13 - - [01/Jan/2019:11:11:02 +0000] "/x17\xbcx8exc9{vxdcxb7xeexc8xb0[xc7(x12Wx88x135xcbx1axfb59xbdxb0exeax023m~xaarxefsx06x7fxb1x80Fx91bx97pxbfxd5.xdbx1ax15U" 400 301 "-" "-"
37.32.127.218 - - [01/Jan/2019:11:11:02 +0000] "xc3xf4xe2x14xab_xe2x05SUx95}Zxa5txbdx1dxc0Jxc4xa7xe6x1exdexcf<xa5xd4xc0x84rx1fx8ax8fPxe2xedxd7xf4xdbxafx06Exxf3Wx1axfexccx01J@xe1xd0x9f3x0fxbcxf5 Rxb3xc0Bxafx18x83;xbay.x84K3x99x9dx19xc9xa4,x1bUbxb2pxcfix1dxe8nx82x02xf9xfbxadF^xc4xe6x1bxf5)wx93xc8,xa1xd0xfc;x0ex89HAx1ex10{$:xc3xf5ozx98Rxb8xd5Qxa0x87xe6xc0x9bxb8x8eIxa8oxebxc5xkxfexc0xf27x8eF*t5xb8x06xd1)lxdfx0exc8xe3xb6xadxb5xc7#xcdEx83xc1x0e#xfc`xa7;xe7K/2x98IlhYix1cxc4xa9xe8x86TxcbS>>xc5tx10=*x11GLxb0xa55xd77r4xd4|Dxe2" 400 447 "-" "-"
95.162.183.101 - - [01/Jan/2019:11:11:02 +0000] ")xc1(U/xa2xe5rx9aFBxefx0fxcb*xdfxf33%xdbx83x84xa7ax88xaaxb0xxe0xe5xf3b92Lx9dEGxc5x1cx15x16xfbHkxdebxcex86uNxd1xedxa7x0cx10xd8xbb\*x18" 400 301 "-" "-"
There are many requests like this from different IPs. All are Iran based IPs
Can anyone please tell me, what is meant by these logs ? And why they don't have any method like GET/POST/HEAD. Also how can we block these type of requests?
apache ddos
We are having a Cloud Based ERP application which is written in python and running on apache webserver. Its working fine, and we are using DigitalOcean Droplets for hosting our application.
We are having more than 250 droplets, and everything works fine. Unfortuantely, now we noticed some strange entries in apache access logs as follows (SSL Already enabled on server)
94.24.83.13 - - [01/Jan/2019:11:11:02 +0000] "/x17\xbcx8exc9{vxdcxb7xeexc8xb0[xc7(x12Wx88x135xcbx1axfb59xbdxb0exeax023m~xaarxefsx06x7fxb1x80Fx91bx97pxbfxd5.xdbx1ax15U" 400 301 "-" "-"
37.32.127.218 - - [01/Jan/2019:11:11:02 +0000] "xc3xf4xe2x14xab_xe2x05SUx95}Zxa5txbdx1dxc0Jxc4xa7xe6x1exdexcf<xa5xd4xc0x84rx1fx8ax8fPxe2xedxd7xf4xdbxafx06Exxf3Wx1axfexccx01J@xe1xd0x9f3x0fxbcxf5 Rxb3xc0Bxafx18x83;xbay.x84K3x99x9dx19xc9xa4,x1bUbxb2pxcfix1dxe8nx82x02xf9xfbxadF^xc4xe6x1bxf5)wx93xc8,xa1xd0xfc;x0ex89HAx1ex10{$:xc3xf5ozx98Rxb8xd5Qxa0x87xe6xc0x9bxb8x8eIxa8oxebxc5xkxfexc0xf27x8eF*t5xb8x06xd1)lxdfx0exc8xe3xb6xadxb5xc7#xcdEx83xc1x0e#xfc`xa7;xe7K/2x98IlhYix1cxc4xa9xe8x86TxcbS>>xc5tx10=*x11GLxb0xa55xd77r4xd4|Dxe2" 400 447 "-" "-"
95.162.183.101 - - [01/Jan/2019:11:11:02 +0000] ")xc1(U/xa2xe5rx9aFBxefx0fxcb*xdfxf33%xdbx83x84xa7ax88xaaxb0xxe0xe5xf3b92Lx9dEGxc5x1cx15x16xfbHkxdebxcex86uNxd1xedxa7x0cx10xd8xbb\*x18" 400 301 "-" "-"
There are many requests like this from different IPs. All are Iran based IPs
Can anyone please tell me, what is meant by these logs ? And why they don't have any method like GET/POST/HEAD. Also how can we block these type of requests?
apache ddos
apache ddos
edited Jan 2 at 8:49
Mike
2,0871825
2,0871825
asked Jan 2 at 6:07
itzforuitzforu
50212
50212
add a comment |
add a comment |
0
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f54001944%2fstrange-apache-server-logs%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
0
active
oldest
votes
0
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f54001944%2fstrange-apache-server-logs%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown