Logwatch reports a possible successful probe on my server. Has my server been exploited?
Dave at Collaboration Café <dave-ZGY8ohtN/[email protected]> Sun, 15 Nov 2020 01:00:16 +0200
| Newsgroups | gmane.comp.log.logwatch.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi, I am running an Ubuntu 18.04 Nginx-powered server with multiple
vhosts, with Logwatch giving me a report (highest level of detail) in my
mailbox every morning.
In the httpd section of the report, I'm frequently getting the snippet
below.
A total of 1 possible successful probes were detected (the following
URLs
contain strings that match one or more of a listing of strings that
indicate a possible exploit):
null HTTP Response 200
Then in the requests listing of the httpd section, I'm seeing output
such as below (this is just a small snippet of a day's report):
Requests with error response codes
400 Bad Request
/: 14 Time(s)
null: 8 Time(s)
/0bef: 6 Time(s)
Question 1: has anyone seen this before, and do I have a serious
problem? I'm not noticing anything amiss in my server's operation...
Question 2: I have been trying to locate the exact log lines in
/var/log/nginx/access.log and /var/log/nginx/error.log by manually
tailing my logs and by using grep to search. But so far I have failed.
Can anyone advise me of a way to locate these lines effectively?
Any other useful advice would be much appreciated.
--
With all best wishes,
Dave
--
With all best wishes,
Dave