[Techtalk] Apache, abuse and nonexistent domains.

Therese Gustafsson th_gustafsson at yahoo.com
Tue Dec 17 02:41:45 EST 2002


Hi everyone. 

Lately I have a lot of logentries in my Apache access_log like this:
208.3.113.49 - - [17/Dec/2002:04:34:42 +0100] "CONNECT
203.190.194.95:25 HTTP/1.1" 400 379 "-" "-"
They come from a couple of different ip-numbers and they're trying to
connect to a lot of servers with different ip-numbers, all on on port
25. What is this? Should I get worried? I tried it myself and used
telnet to connect to my webserver on port 80 and wrote what they wrote
but all I got back was the html for the index webpage. Some of the
entries have the code "200" instead of "400" like the one above. 
I wanted to report it to the appropriate domain for the ip-numbers, but
some, like the one above, doesn't resolve to a hostname. I only get
"Non-existent domain" as an answer. What should I do then? How can I
find out where to report it to? And when I report it what should I say?
Should I just attach the appropriate parts of the server logs?

Thanks for any help you can give me.

/Therese

__________________________________________________
Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
http://mailplus.yahoo.com



More information about the Techtalk mailing list