{"id":350,"date":"2009-06-06T12:10:59","date_gmt":"2009-06-06T19:10:59","guid":{"rendered":"http:\/\/www.evardsson.com\/blog\/?p=350"},"modified":"2009-06-06T12:10:59","modified_gmt":"2009-06-06T19:10:59","slug":"interesting-log-activity","status":"publish","type":"post","link":"https:\/\/www.evardsson.com\/blog\/2009\/06\/06\/interesting-log-activity\/","title":{"rendered":"Interesting log activity"},"content":{"rendered":"<p>While trying to debug the <a href=\"http:\/\/www.samuelaguilera.com\/archivo\/shorten2ping-notifies-pingfm-bitly.xhtml\">Shorten2Ping<\/a> plugin (a really nifty thing, if I could get it working) I went digging through my Apache error logs looking for any PHP errors. (Well, okay, I didn&#8217;t actually <em>dig<\/em>, I just did a last on the file.) What I saw was interesting, even though it did not help the debugging at all. In fact it kind of derailed the whole process. What I saw was an obvious attempt to find <a class=\"zem_slink\" title=\"Horde (software)\" rel=\"homepage\" href=\"http:\/\/www.horde.org\/\">Horde<\/a> on my server (which I did run temporarily a few years ago). My first guess was that there was a new exploit out for Horde. I did some digging around and found that, yes, indeedy, there is. I found the <a href=\"http:\/\/securityvulns.com\/Tdocument354.html\">details of the exploit<\/a> at <a href=\"http:\/\/securityvulns.com\/\">securityvulns.com<\/a> (which is a mirror of or mirrored by <a href=\"http:\/\/www.security.nnov.ru\/\">www.security.nnov.ru<\/a> which is where the first relevant Google link took me.) Oddly enough I have not seen this show up on any other security sites yet, even though I see that the report on securityvulns.com is from March.<\/p>\n<p>Anyhow, in case you are curious, here are the relevant lines from the log. (IPs have <em>not<\/em> been changed to protect the guilty.)<\/p>\n<pre>[Sat Jun 06 01:46:53 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/README\r\n[Sat Jun 06 01:46:53 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde\r\n[Sat Jun 06 01:46:54 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde2\r\n[Sat Jun 06 01:46:55 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde3\r\n[Sat Jun 06 01:46:56 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde-3.0.5\r\n[Sat Jun 06 01:46:57 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde-3.0.6\r\n[Sat Jun 06 01:46:58 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde-3.0.7\r\n[Sat Jun 06 01:46:58 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde-3.0.8\r\n[Sat Jun 06 01:46:59 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/horde-3.0.9\r\n[Sat Jun 06 01:47:00 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/mail\r\n[Sat Jun 06 01:47:01 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/email\r\n[Sat Jun 06 01:47:02 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/webmail\r\n[Sat Jun 06 01:47:03 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/newmail\r\n[Sat Jun 06 01:47:03 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/mails\r\n[Sat Jun 06 01:47:04 2009] [error] [client 81.210.76.194] File does not exist: \/var\/www\/localhost\/htdocs\/evardsson.com\/mailz<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>While trying to debug the Shorten2Ping plugin (a really nifty thing, if I could get it working) I went digging through my Apache error logs looking for any PHP errors. (Well, okay, I didn&#8217;t actually &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[10],"tags":[97,98,147],"class_list":["post-350","post","type-post","status-publish","format-standard","hentry","category-security","tag-exploit","tag-horde","tag-security"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pxT7i-5E","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts\/350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/comments?post=350"}],"version-history":[{"count":1,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts\/350\/revisions"}],"predecessor-version":[{"id":351,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/posts\/350\/revisions\/351"}],"wp:attachment":[{"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/media?parent=350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/categories?post=350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.evardsson.com\/blog\/wp-json\/wp\/v2\/tags?post=350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}