Salut il me semble que je subi une attack sur notre site ! j’ai des log étranges qui concorde avec le lancement de plein d’instance Apache et qui termine en saturation de la ram et du CPu :
Dec 2 11:39:14 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:11:38:55 +0100] "GET /certsrv/ HTTP/1.0" 404 14436 "-" "-"
Dec 2 11:47:46 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:11:47:24 +0100] "GET /phprojekt/rts/ HTTP/1.0" 404 14442 "-" "-"
Dec 2 11:56:07 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:11:55:47 +0100] "GET /phprojekt-3.1/rts/ HTTP/1.0" 404 14446 "-" "-"
Dec 2 12:04:42 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:12:04:23 +0100] "GET /phprojekt-3.1a/rts/ HTTP/1.0" 404 14447 "-" "-"
Dec 2 12:18:54 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:12:18:43 +0100] "GET /certsrv/certrqxt.asp HTTP/1.0" 404 14448 "-" ";<<<script>QualysTest</script><script>alert('QualysTest')</script>>>"
Dec 2 12:45:24 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:12:45:09 +0100] "GET /reports/rwservlet/showmap HTTP/1.0" 404 14453 "-" "-"
Dec 2 13:14:40 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:13:14:23 +0100] "GET /news/certsrv/ HTTP/1.0" 404 14449 "-" "-"
Dec 2 14:25:15 test httpd: www.monsite.com 192.168.254.60 - - [02/Dec/2014:14:24:56 +0100] "GET /wordpress/certsrv/ HTTP/1.0" 404 14446 "-" "-"
je suis parano et je dois chercher ailleurs ? je cherche pourquoi mon Apache crash. Il essaye de faire tourner un CMS ezpublish.
Merci.
