withhelds
Aug 26th, 2010, 07:23 AM
Hi,
Recently, my web server running on Red Hat generates a lot of high CPU usage and I have check both the apache access and error log and found out there is some unknown IP requesting access to certain phpmyadmin directories.
I have researched and found out it might be related to ZMEU Attack @ http://linux.m2osw.com/zmeu-attack .
However, what ponder me was how is it possible for a public user to find my web server when my web server is set to restricted outbound traffic i.e. public are not able to access to the intranet site as this server is only accessible within the private network.
Although my web server is able to access the internet as it require SMTP to send out email and other stuff, so I am not sure what causes this to be happened.
Is there a way to check the system log for outbound traffic or what scripts (I am using PHP) that trigger to allow outside user to find this web server?
Please advise on the troubleshooting steps.
Thank you for reading
Recently, my web server running on Red Hat generates a lot of high CPU usage and I have check both the apache access and error log and found out there is some unknown IP requesting access to certain phpmyadmin directories.
I have researched and found out it might be related to ZMEU Attack @ http://linux.m2osw.com/zmeu-attack .
However, what ponder me was how is it possible for a public user to find my web server when my web server is set to restricted outbound traffic i.e. public are not able to access to the intranet site as this server is only accessible within the private network.
Although my web server is able to access the internet as it require SMTP to send out email and other stuff, so I am not sure what causes this to be happened.
Is there a way to check the system log for outbound traffic or what scripts (I am using PHP) that trigger to allow outside user to find this web server?
Please advise on the troubleshooting steps.
Thank you for reading