Re: [CentOS] semi OT: logwatch results

2008-07-18 Thread John Thomas
Robert - elists wrote: GET http://scifi.pages.at/myproxies/azenv.php HTTP/1.1 with response code(s) 404 1 responses I installed fail2ban from rpmforge and created a filter that bans these type of things. Here is my novice attempt at the failregex = - - \[.*\] \"GET .*(azenv\.php|adxmlrpc\.p

Re: [CentOS] semi OT: logwatch results

2008-07-18 Thread Marcelo Roccasalva
On Fri, Jul 18, 2008 at 1:13 PM, Robert - elists <[EMAIL PROTECTED]> wrote: > Semi Off Topic > > My searching hasn't found what I consider superior info, and we are > wondering from others experience on this list... > > In the logwatch results we all see the info below on almost a daily basis > > I

Re: [CentOS] semi OT: logwatch results

2008-07-18 Thread Brent L. Bates
We've been seeing the same type of entries in our Web server logs for at least a couple months now and not just a few entires. It isn't just `azenv.php', but references to other PHP files that do not exist on our systems. They've hit some of our servers so hard I figured it must be some kind

[CentOS] semi OT: logwatch results

2008-07-18 Thread Robert - elists
Semi Off Topic My searching hasn't found what I consider superior info, and we are wondering from others experience on this list... In the logwatch results we all see the info below on almost a daily basis I have taken the liberty of combining logwatch results from centos 4 and 5 machines for ex