false whm root login alert
Posted: 04 Oct 2009, 04:25
Hi,
Minutes ago, i received a false positive.
root@X [~]# cat /usr/local/cpanel/logs/access_log |grep XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX - - [10/04/2009:02:46:19 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - root [10/04/2009:02:46:28 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:20 -0000] "GET /unprotected/cpanel/favicon.ico HTTP/1.0" 200 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:20 -0000] "GET /unprotected/cpanel/style.css HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:20 -0000] "GET /unprotected/cpanel/images/log_02b.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:21 -0000] "GET /unprotected/cpanel/images/log_01_whm.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:21 -0000] "GET /unprotected/cpanel/images/button-bg.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:21 -0000] "GET /unprotected/cpanel/images/log_03.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:50:48 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - root [10/04/2009:02:50:53 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
Can you confirm it's a false positive ?
Minutes ago, i received a false positive.
root@X [~]# cat /usr/local/cpanel/logs/access_log |grep XXX.XXX.XXX.XXX
XXX.XXX.XXX.XXX - - [10/04/2009:02:46:19 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - root [10/04/2009:02:46:28 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:20 -0000] "GET /unprotected/cpanel/favicon.ico HTTP/1.0" 200 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:20 -0000] "GET /unprotected/cpanel/style.css HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:20 -0000] "GET /unprotected/cpanel/images/log_02b.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:21 -0000] "GET /unprotected/cpanel/images/log_01_whm.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:21 -0000] "GET /unprotected/cpanel/images/button-bg.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:47:21 -0000] "GET /unprotected/cpanel/images/log_03.jpg HTTP/1.0" 200 0 "Xttp://YYY.YYY.YYY.YYY:2086/unprotected/cpanel/style.css" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - - [10/04/2009:02:50:48 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
XXX.XXX.XXX.XXX - root [10/04/2009:02:50:53 -0000] "GET / HTTP/1.0" 401 0 "" "Mozilla/5.0 (Windows; U; Windows NT 6.0; ar; rv:1.9.1.3) Gecko/20090824 Firefox/3.5.3 (.NET CLR 3.5.30729) FirePHP/0.3"
Can you confirm it's a false positive ?