merhaba arkadaşlar,
uzun süredir sistemimde apache 2,php,mysql kurulu durmakta ve bilgisayar açık oldugu sürece apache web server da açık ve ip adresim port 80'den dışarı yönlenmiş durumda.
geçenlerde apache log dosyasını incelerken,normal olmayan(bana göre) bir durumla karşılaştım.
normalde , kendi bilgisayarımda host ettigim dosyalara erişimi gösteren apache log dosyası, bilgisayarım üzerinden pek çok farklı domaine geçiş yapıldıgını hatta zaman zaman bazı sitelere login yapmak için,brute force için kullanıldıgını gördüm.
genelde yahoo için kullanılmış ama oldukça huylandım bu durumdan? proxy olarak mı kullanılıyorum ?
ya da bunu engellemenin bir yolu var mıdır ?
örnekler şöyle:
81.9.57.52 - - [23/May/2006:17:43:25 +0300] "GET http://www.ebay.com/ HTTP/1.1" 200 5116
81.9.57.52 - - [23/May/2006:17:53:48 +0300] "CONNECT login.icq.com:443 HTTP/1.0" 200 277
81.9.57.52 - - [23/May/2006:17:57:31 +0300] "CONNECT login.icq.com:443 HTTP/1.0" 200 277
81.52.161.77 - - [23/May/2006:17:57:47 +0300] "GET http://a938.f.akamai.net/login.korea.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 324
81.52.161.77 - - [23/May/2006:17:58:57 +0300] "GET http://a391.v.akamai.net/login.europe.yahoo.com/config/login?login=kiki-10&passwd=password HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:17:59:30 +0300] "GET http://a320.h.akamai.net/login.bjs.yahoo.com/config/login?login=kiki-karen&passwd=password HTTP/1.0" 404 322
81.52.161.77 - - [23/May/2006:18:00:03 +0300] "GET http://a534.e.akamai.net/login.tpe.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 322
81.52.161.77 - - [23/May/2006:18:01:03 +0300] "GET http://a224.t.akamai.net/n1.login.scd.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:18:01:54 +0300] "GET http://a208.z.akamai.net/n10.login.dcn.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:02:07 +0300] "GET http://a240.p.akamai.net/n10.login.scd.yahoo.com/config/login?login=kiki-666&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:02:35 +0300] "GET http://a140.p.akamai.net/n11.login.dcn.yahoo.com/config/login?login=kiki-monkey&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:03:05 +0300] "GET http://a457.c.akamai.net/n12.login.dcn.yahoo.com/config/login?login=super-stretch&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:03:38 +0300] "GET http://a513.f.akamai.net/n12.login.scd.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:04:09 +0300] "GET http://a363.p.akamai.net/n13.login.dcn.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:04:57 +0300] "GET http://a812.e.akamai.net/n13.login.scd.yahoo.com/config/login?login=kiki-666&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:05:16 +0300] "GET http://a436.b.akamai.net/n18.login.dcn.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:05:47 +0300] "GET http://a561.l.akamai.net/n20.login.dcn.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:06:11 +0300] "GET http://a215.h.akamai.net/n26.login.dcn.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:18:06:39 +0300] "GET http://a240.l.akamai.net/n27.login.dcn.yahoo.com/config/login?login=kiki-1&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:20:53 +0300] "GET http://a67.k.akamai.net/n39.login.dcn.yahoo.com/config/login?login=box-key&passwd=red HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:21:05 +0300] "GET http://a160.z.akamai.net/n39.login.scd.yahoo.com/config/login?login=super-fucker&passwd=red HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:22:00 +0300] "GET http://a858.e.akamai.net/n4.login.dcn.yahoo.com/config/login?login=kiki-10&passwd=orange HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:22:12 +0300] "GET http://a743.z.akamai.net/n44.login.scd.yahoo.com/config/login?login=super-stretch&passwd=red HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:22:44 +0300] "GET http://a464.v.akamai.net/n46.login.dcn.yahoo.com/config/login?login=kiki-7&passwd=red HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:24:25 +0300] "GET http://a831.l.akamai.net/n50.login.dcn.yahoo.com/config/login?login=kiki-3&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:25:14 +0300] "GET http://a250.p.akamai.net/n6.login.dcn.yahoo.com/config/login?login=super-angela&passwd=love HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:25:36 +0300] "GET http://a983.t.akamai.net/n6.login.scd.yahoo.com/config/login?login=super-dancer&passwd=love HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:26:35 +0300] "GET http://a317.x.akamai.net/login.korea.yahoo.com/config/login?login=kiki-3&passwd=orange HTTP/1.0" 404 324
81.52.161.77 - - [23/May/2006:21:27:04 +0300] "GET http://a802.d.akamai.net/login.yahoo.com/config/login?login=kiki-7&passwd=red HTTP/1.0" 404 318
81.52.161.77 - - [23/May/2006:21:27:35 +0300] "GET http://a337.t.akamai.net/login.europe.yahoo.com/config/login?login=super-dana&passwd=red HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:28:08 +0300] "GET http://a733.f.akamai.net/login.bjs.yahoo.com/config/login?login=super-33&passwd=orange HTTP/1.0" 404 322
81.52.161.77 - - [23/May/2006:21:29:01 +0300] "GET http://a540.k.akamai.net/login.tpe.yahoo.com/config/login?login=super-fucker&passwd=red HTTP/1.0" 404 322
81.52.161.77 - - [23/May/2006:21:29:46 +0300] "GET http://a459.t.akamai.net/n1.login.scd.yahoo.com/config/login?login=super-jean&passwd=love HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:30:20 +0300] "GET http://a405.l.akamai.net/n10.login.dcn.yahoo.com/config/login?login=super-33&passwd=sexy HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:31:15 +0300] "GET http://a535.g.akamai.net/n10.login.scd.yahoo.com/config/login?login=kiki-15&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:31:35 +0300] "GET http://a5.k.akamai.net/n11.login.dcn.yahoo.com/config/login?login=kiki-2000&passwd=psycho HTTP/1.0" 404 324
81.52.161.77 - - [23/May/2006:21:32:19 +0300] "GET http://a165.k.akamai.net/n12.login.dcn.yahoo.com/config/login?login=super-games&passwd=red HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:32:42 +0300] "GET http://a687.d.akamai.net/n12.login.scd.yahoo.com/config/login?login=super-games&passwd=red HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:33:15 +0300] "GET http://a131.l.akamai.net/n13.login.dcn.yahoo.com/config/login?login=super-33&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:35:03 +0300] "GET http://a872.h.akamai.net/n20.login.dcn.yahoo.com/config/login?login=super-3&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:35:15 +0300] "GET http://a630.v.akamai.net/n26.login.dcn.yahoo.com/config/login?login=kiki-man&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:35:47 +0300] "GET http://a359.f.akamai.net/n27.login.dcn.yahoo.com/config/login?login=box-10&passwd=password HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:36:40 +0300] "GET http://a141.f.akamai.net/n31.login.scd.yahoo.com/config/login?login=kiki-3&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:37:13 +0300] "GET http://a794.c.akamai.net/n33.login.dcn.yahoo.com/config/login?login=super-69&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:37:26 +0300] "GET http://a849.d.akamai.net/n33.login.scd.yahoo.com/config/login?login=kiki-mail&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:38:33 +0300] "GET http://a248.c.akamai.net/n34.login.scd.yahoo.com/config/login?login=super-3&passwd=love HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:39:09 +0300] "GET http://a848.d.akamai.net/n35.login.dcn.yahoo.com/config/login?login=kiki-snoopy&passwd=red HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:39:59 +0300] "GET http://a244.t.akamai.net/n35.login.scd.yahoo.com/config/login?login=super-dana&passwd=love HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:40:13 +0300] "GET http://a97.p.akamai.net/n36.login.dcn.yahoo.com/config/login?login=super-dana&passwd=orange HTTP/1.0" 404 325
81.52.161.77 - - [23/May/2006:21:41:25 +0300] "GET http://a285.z.akamai.net/n37.login.dcn.yahoo.com/config/login?login=kiki-2000&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:42:59 +0300] "GET http://a120.z.akamai.net/n38.login.scd.yahoo.com/config/login?login=super-alexander&passwd=orange HTTP/1.0" 404 326
81.52.161.77 - - [23/May/2006:21:43:29 +0300] "GET http://a439.e.akamai.net/n39.login.dcn.yahoo.com/config/login?login=box-10&passwd=password HTTP/1.0" 404 326
194.164.213.65 - - [24/May/2006:02:39:12 +0300] "GET /sumthin HTTP/1.0" 404 294
218.171.152.213 - - [24/May/2006:04:35:27 +0300] "CONNECT smtp.pchome.com.tw:25 HTTP/1.0" 200 277
67.187.59.107 - - [24/May/2006:14:42:59 +0300] "GET https://217.12.4.59/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=b _______________ HTTP/1.0" 404 299
84.195.196.172 - - [24/May/2006:14:46:40 +0300] "GET http://216.109.127.38/config/login?login=texas+2&passwd=kalkalelibelgium22/5&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:14:50:41 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=1 23456__ HTTP/1.0" 404 299
84.195.196.172 - - [24/May/2006:14:51:59 +0300] "GET http://217.12.4.116/config/login?login=texas+2&passwd=kalkalelinbelg22/5&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 297
84.195.196.172 - - [24/May/2006:14:57:28 +0300] "GET http://202.43.219.18/config/login?login=texas+2&passwd=kalkalelinbelg17/5&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 298
67.187.59.107 - - [24/May/2006:14:58:26 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=b right_ HTTP/1.0" 404 299
84.195.196.172 - - [24/May/2006:15:02:55 +0300] "GET http://216.109.127.6/config/login?login=eliana&passwd=kalkalelinabel19/5&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 298
67.187.59.107 - - [24/May/2006:15:06:27 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=cat_____ _______ HTTP/1.0" 404 299
84.195.196.172 - - [24/May/2006:15:08:03 +0300] "GET http://216.109.127.6/config/login?login=texas+2&passwd=kalkalelinabel21/5&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 298
84.195.196.172 - - [24/May/2006:15:13:21 +0300] "GET http://217.12.4.78/config/login?login=eliana&passwd=kalkalelinabelgium16/5&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 296
67.187.59.107 - - [24/May/2006:15:14:30 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=bubble s_________________________ HTTP/1.0" 404 299
84.195.196.172 - - [24/May/2006:15:18:32 +0300] "GET http://202.43.211.248/config/login?login=elinas_&passwd=kalkalelinbelg400&.done=http%3a//subscribe.yahoo.com/showaccount&.intl=us HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:15:22:58 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=amber__ ___ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:15:31:34 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=dido_ HTTP/1.0" 404 299
85.96.196.234 - - [24/May/2006:15:34:28 +0300] "GET /org.rar HTTP/1.1" 206 8396
85.96.196.234 - - [24/May/2006:15:34:31 +0300] "GET /org.rar HTTP/1.1" 206 8396
67.187.59.107 - - [24/May/2006:15:40:25 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=dave____ ____ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:15:59:34 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=c larissa__ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:16:09:18 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=edge_ _________ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:16:18:57 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=e_____ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:16:28:56 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=edge______ HTTP/1.0" 404 299
66.171.238.93 - - [24/May/2006:16:36:55 +0300] "GET http://login.yahoo.com HTTP/1.0" 200 277
67.187.59.107 - - [24/May/2006:16:39:03 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=amber__ ___ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:16:49:17 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=b right_ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:16:59:27 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=e_______________ _____ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:17:09:58 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=amber__ ___ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:17:20:34 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=c himera___ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:17:31:12 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=flash_ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:17:42:27 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=dr eams____ HTTP/1.0" 404 299
81.9.57.52 - - [24/May/2006:17:43:08 +0300] "GET http://www.ebay.com/ HTTP/1.1" 200 277
67.187.59.107 - - [24/May/2006:17:53:25 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=b right_ HTTP/1.0" 404 299
81.9.57.52 - - [24/May/2006:17:57:09 +0300] "CONNECT login.icq.com:443 HTTP/1.0" 200 277
67.187.59.107 - - [24/May/2006:18:05:19 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=flower___ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:18:17:37 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=francine______ HTTP/1.0" 404 299
67.187.59.107 - - [24/May/2006:18:30:02 +0300] "GET https://211.115.101.253/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=freak_____ _ HTTP/1.0" 404 299
67.187.59.107 - - [25/May/2006:00:48:48 +0300] "GET https://216.155.202.124/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=h__ HTTP/1.0" 404 299
67.187.59.107 - - [25/May/2006:01:10:51 +0300] "GET https://216.155.202.124/config/login?.hash=564635436656&.last=g9v3n5&.tries=1&.hasMsgr=1&.chkP=n&.done=https://login.my.login.yahoo.com/&passwd=Asshole&login=b right_ HTTP/1.0" 404 299
61.129.113.230 - - [25/May/2006:10:40:19 +0300] "GET http://lookfreebies.com/prx1.php HTTP/1.0" 404 297
218.169.63.244 - - [25/May/2006:10:55:50 +0300] "CONNECT 168.95.5.240:25 HTTP/1.0" 200 277
218.169.63.244 - - [25/May/2006:10:55:53 +0300] "CONNECT 168.95.5.248:25 HTTP/1.0" 200 277
218.169.63.244 - - [25/May/2006:10:55:55 +0300] "CONNECT 168.95.5.210:25 HTTP/1.0" 200 277
61.129.113.230 - - [25/May/2006:11:43:58 +0300] "GET http://lookfreebies.com/prx1.php HTTP/1.0" 404 297
61.129.113.230 - - [25/May/2006:13:03:20 +0300] "GET http://lookfreebies.com/prx1.php HTTP/1.0" 404 297
59.105.7.35 - - [25/May/2006:15:20:24 +0300] "CONNECT 210.200.181.194:25 HTTP/1.0" 200 277
59.105.7.35 - - [25/May/2006:15:20:26 +0300] "CONNECT 210.200.181.194:25 HTTP/1.0" 200 277
59.105.7.35 - - [25/May/2006:15:20:28 +0300] "CONNECT 210.200.181.193:25 HTTP/1.0" 200 277