NETWORK SECURITY WEB APPLICATION CODE EXPLANATION

Asked by sandeep

1.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/z_user_show.php
Explanation:

2.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/[SecCheck]/..%2f..%2f../ext.ini
Explanation:

3.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/[SecCheck]/..%5c..%5c../ext.ini
Explanation:

4.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/_pages
Explanation:

5.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/_vti_bin/fpcount.exe/
Explanation:

6.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/~/<script>alert('Vulnerable')</script>.asp
Explanation:

7.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/~/<script>alert('Vulnerable')</script>.aspx
Explanation:

8.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/~/<script>alert('Vulnerable')</script>.aspx
Explanation:

9.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/admin/config.php
Explanation:

10.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/adm/config.php
Explanation:

11.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] client denied by server configuration: /var/www/cgi-bin/.htaccess
Explanation:

12.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] client denied by server configuration: /var/www/cgi-bin/.htaccess.old
Explanation:

13.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] client denied by server configuration: /var/www/cgi-bin/.htaccess.save
Explanation:

14.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] client denied by server configuration: /var/www/cgi-bin/.htaccess~
Explanation:

15.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] client denied by server configuration: /var/www/cgi-bin/.htpasswd
Explanation:

16.[Wed Jan 26 05:31:12 2005] [error] [client 10.10.147.32] Invalid URI in request GET cgi-bin/htsearch?exclude=%60/etc/passwd%60 HTTP/1.0
Explanation:

17.[Wed Jan 26 05:31:12 2005] [error] [client 10.10.147.32] Invalid URI in request GET cgi-bin/htsearch?exclude=%60/etc/passwd%60 HTTP/1.0
Explanation:

Question information

Language:
English Edit question
Status:
Answered
For:
Ubuntu Edit question
Assignee:
No assignee Edit question
Last query:
Last reply:
Revision history for this message
Robinson Tryon (colonelqubit) said :
#1

Hi,

  1.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] File does not exist: /var/www/html/z_user_show.php

Assuming your web root is set up to be /var/www, that means that someone requested a file html/z_user_show.php but it doesn't exist on your server under /var/www.

  14.[Wed Jan 26 05:31:10 2005] [error] [client 10.10.147.32] client denied by server configuration: /var/www/cgi-bin/.htaccess~

Often Apache is set up by default to prevent access to emacs save files (so you could access index.php, but not index.php~). I believe it's also set up to prevent access to .htpasswd files. These are for security reasons as you don't want anyone reading the contents of these files.

Can you help with this problem?

Provide an answer of your own, or ask sandeep for more information if necessary.

To post a message you must log in.