[NBLUG/talk] CONNECT lines in access_log...

Daniel Smith linux2002 at daniel.org
Thu Mar 20 19:15:01 PST 2003


I just happened to look over my Apache 1.3.27 access_log.
Do these lines look familiar to anyone?  Is it a spammer
trying to somehow use Apache as a relay?
Just wondering about them.

bucky:apache/logs :-) grep CONN access_log
4.43.250.47 - - [13/Mar/2003:20:28:50 -0800] "CONNECT smtp.rol.ru:25 HTTP/1.0"
[snip......]

62.118.251.29 - - [19/Mar/2003:00:32:52 -0800] "CONNECT whois.ripe.net:43 HTTP/
.1" 400 307
172.154.145.68 - - [19/Mar/2003:19:40:01 -0800] "CONNECT smtp.rol.ru:25 HTTP/1.
" 200 215
172.137.130.22 - - [20/Mar/2003:14:47:58 -0800] "CONNECT smtp.rol.ru:25 HTTP/1.
" 200 215
66.237.0.71 - - [20/Mar/2003:18:07:13 -0800] "CONNECT maila.microsoft.com:25 /
TTP/1.0" 400 299
172.137.130.22 - - [20/Mar/2003:18:40:06 -0800] "CONNECT smtp.rol.ru:25 HTTP/1.
" 200 215



-- 
Daniel L. Smith - Sonoma County, CA - AIM: SonomaDaniel




More information about the talk mailing list