I wonder if anyone is familiar with tclhttpd log entries and can shed
some light on this:
Typically each log entry contains a bunch of attributes including the ip address, a timestamp, the requested url, user agent, http code, etc.
But I am seeing an increasing number of weird entries where most of that
info is empty. The lines only include the ip address and the timestamp,
and the rest is just "- - - - -".
What does this mean?
Yeah, it doesn't look kosher. I saw like 10 of them like that one after another. Then I get normal entries from the same source but the
requests all appear to be hacking attempts containing shell commands
with rm, cd, wget, or some .php stuff.
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 463 |
Nodes: | 16 (2 / 14) |
Uptime: | 157:16:03 |
Calls: | 9,384 |
Calls today: | 4 |
Files: | 13,561 |
Messages: | 6,096,000 |