9 ms·
On a related note, set up a website a few days ago. Brand new domain, newly opened port. But I've rented this VPS for a while so I guess its IP is already on a
by Frotag 4y ago
On a related note, set up a website a few days ago. Brand new domain, newly opened port. But I've rented this VPS for a while so I guess its IP is already on a few lists.
But anyways, it's interesting watching the logs for what I assume are tests of known exploits.
GET /.gitconfig HTTP/1.0" 422 Unprocessable Entity
GET /.git/config HTTP/1.0" 404 Not Found
GET /owa/auth/x.js HTTP/1.0" 404 Not Found
GET /ecp/Current/exporttool/microsoft.exchange.ediscovery.exporttool.application HTTP/1.0" 404 Not Found
GET /owa/auth/logon.aspx?url=https%3a%2f%2f1%2fecp%2f HTTP/1.0" 404 Not Found
GET /system_api.php HTTP/1.0" 404 Not Found
GET /c/version.js HTTP/1.0" 404 Not Found
GET /streaming/clients_live.php HTTP/1.0" 404 Not Found
GET /stalker_portal/c/version.js HTTP/1.0" 404 Not Found
GET /stream/live.php HTTP/1.0" 404 Not Found
GET /flu/403.html HTTP/1.0" 404 Not Found
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.0" 404 Not Found
GET /?XDEBUG_SESSION_START=phpstorm HTTP/1.0" 404 Not Found
GET /backups-dup-lite/dup-installer/main.installer.php HTTP/1.0" 404 Not Found
GET /%24%7B%28%23a%3D%40org.apache.commons.io.IOUtils%40toString%28%40java.lang.Runtime%40getRuntime%28%29.exec%28%22whoami%22%29.getInputStream%28%29%2C%22utf-8%22%29%29.%28%40com.opensymphony.webwork.ServletActionContext%40getResponse%28%29.setHeader%28%22X-Cmd-Response%22%2C%23a%29%29%7D/
...and the list goes on.
- cesarb 4y agoThat's why I recommend always pointing the default virtual host in the apache or nginx configuration to an empty static site, and making the real site visible only as a named virtual host (requiring the correct Host header), even when the server will be used only for a single site. Most of these automated exploit attempts will never send the correct Host header, and therefore will only see the default virtual host.
- semi-extrinsic 4y agoCould you give a pointer to more info on that? I couldn't find more details on such a setup while googling it.
- cesarb 4y agoWhen configuring apache or nginx, one of the virtual hosts you configure is the "default" virtual host, used when the Host header didn't match any of the virtual hosts. IIRC, on nginx, you explicitly say on the virtual host "this is the default", while on apache, it's either the first or the last (forgot which one). How to configure that virtual host is up to you; the simplest configuration would be to point its document root to an empty directory, and add a couple of access control directives to deny access to it from all IP addresses.
- derefr 4y agoI think this is the (only) place in the Nginx docs that mentions 444: https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#...
- jbverschoor 4y agoFail2van with some good nginx filters to ban scans works really well
- matoro 4y agoWith nginx I also set the return code to 444 on the default virtual host, this is not a real status code but instead tells nginx to kill any connections to this vhost at the TCP level.
- usr1106 4y agoI have used a default host with a self signed certificate and 444 for while. One advice was to make it support only the NULL cipher, but I did not succeed to do that, don't remember the details now. However, many scanners still end with a full 400. Either their implemenations are so bad or they intentionally send corrupted requests to try to exploit some vulnerability. I have not digged any deeper.
- zhfliz 4y agofor https, since 1.19.4 you can reject the tls handshake early https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_reject_handshake https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_...
- sbierwagen 4y agoReally? I see plenty of automated exploit attempts against my vhosts.
- kgeist 4y agoI've had this, too, and it later turned out that it was the VPS provider itself scanning my new instance for vulnerabilities.
- bitwrangler 4y agoWas it actually the provider scanning, or just a compromised VPS host using that same provider? It does seem proactive to scan customers' hosts then notify them if exploits are found.
- deleted 4y ago[deleted]
- banana_giraffe 4y agoYep, I run a barely popular static site, but people do love trying all the attacks on it: https://gist.github.com/Q726kbXuN/85c947a5d37cb01f72f82318d0a34cd4 https://gist.github.com/Q726kbXuN/85c947a5d37cb01f72f82318d0... This is two weeks of 404s
- mro_name 4y agohave you thought about serving them eicar?
- banana_giraffe 4y agoI have served up various memes and annoying graphics on the off chance someone will investigate what they got. Though, I assume if their scanner doesn't see the response it wants, it just automatically moves on.
- cronix 4y agoInstead of 404, possibly redirect them to an ad page and retire early? Half joking...
- NavinF 4y agoNaw, advertisers are pretty good at detecting bots. Your CPM will quickly drop to 0.
- bestes 4y agoAll of these HTTP/1.0 requests look just like a scanner that the security team would run again my internal site. Every day.
- technonerd 4y agoI have found nginx bad bot blocker [1] very handy for this. I have it setup to respond with 444 and it allows me to add my own rules very easily. https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blo...
- technion 4y agoJust shows how regularly Microsoft exchange is attacked that this small list has three different exchange attacks.