Logwatch for linode01.ovirt.org (Linux)

logwatch at lists.ovirt.org logwatch at lists.ovirt.org
Sun Mar 31 07:21:13 UTC 2013


 ################### Logwatch 7.3.6 (05/19/07) #################### 
        Processing Initiated: Sun Mar 31 03:21:13 2013
        Date Range Processed: yesterday
                              ( 2013-Mar-30 )
                              Period is day.
      Detail Level of Output: 0
              Type of Output: unformatted
           Logfiles for Host: linode01.ovirt.org
  ################################################################## 
 
 --------------------- httpd Begin ------------------------ 

 A total of 1 sites probed the server 
    216.224.179.80
 
 A total of 2 possible successful probes were detected (the following URLs
 contain strings that match one or more of a listing of strings that
 indicate a possible exploit):
 
    /pipermail/users/2012-October/?option=com_google&controller=../../../../../../../../../../..//proc/self/environ%0000 HTTP Response 200 
    /?option=com_google&controller=../../../../../../../../../../..//proc/self/environ%0000 HTTP Response 200 
 
 Requests with error response codes
    404 Not Found
       /**mailman/listinfo/users<http://lists.ovi ... /listinfo/users: 1 Time(s)
       //admin/categories.php/login.php?cPath=&ac ... product_preview: 1 Time(s)
       //dompdf/dompdf.php?input_file=http://miro ... mages/id.flv???: 3 Time(s)
       //dompdf/dompdf.php?input_file=http://www. ... /.log/b0t.php??: 3 Time(s)
       /__: 1 Time(s)
       /admin/banner_manager.php/login.php: 1 Time(s)
       /admin/categories.php/login.php: 1 Time(s)
       /admin/categories.php/login.php?cPath=&act ... product_preview: 4 Time(s)
       /admin/file_manager.php/login.php: 1 Time(s)
       /apple-touch-icon-precomposed.png: 33 Time(s)
       /apple-touch-icon.png: 29 Time(s)
       /category/news/feed: 11 Time(s)
       /category/news/feed/: 102 Time(s)
       /community: 1 Time(s)
       /extras/curltest.php: 1 Time(s)
       /favicon.ico: 192 Time(s)
       /infra: 1 Time(s)
       /licensing: 2 Time(s)
       /pipermail/engine-devel/2013-March/mobiquo/mobiquo.php: 1 Time(s)
       /pipermail/index.php?act=Reg&CODE=00: 1 Time(s)
       /pipermail/index.php?app=core&module=global&section=register: 1 Time(s)
       /pipermail/infra/2012-August/000813.html/a ... product_preview: 1 Time(s)
       /pipermail/infra/2012-August/000878.html/a ... product_preview: 1 Time(s)
       /pipermail/infra/2012-August/admin/banner_ ... r.php/login.php: 1 Time(s)
       /pipermail/infra/2012-August/admin/categor ... product_preview: 2 Time(s)
       /pipermail/infra/2012-August/admin/categories.php/login.php: 1 Time(s)
       /pipermail/infra/2012-August/admin/file_ma ... r.php/login.php: 1 Time(s)
       /pipermail/infra/2012-November//dompdf/dom ... /.log/b0t.php??: 3 Time(s)
       /pipermail/infra/2012-November//dompdf/dom ... mages/id.flv???: 3 Time(s)
       /pipermail/infra/2012-November/001283.html ... product_preview: 1 Time(s)
       /pipermail/infra/2012-November/001285.html ... c.com%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-November/001303.html ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-November/001313.html ... s.co.za/bat.php: 1 Time(s)
       /pipermail/infra/2012-November/001330.html ... com%2Findex.php: 1 Time(s)
       /pipermail/infra/2012-November/001330.html ... g.com%2Fbad.php: 2 Time(s)
       /pipermail/infra/2012-November/001330.html ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-November/001330.html ... s.com%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-November/001342.html ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-November/001362.html ... c.com%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-November/001410.html ... .ch%2Fbyroe.php: 1 Time(s)
       /pipermail/infra/2012-November/001410.html ... /.log/b0t.php??: 44 Time(s)
       /pipermail/infra/2012-November/001410.html ... mages/id.flv???: 44 Time(s)
       /pipermail/infra/2012-November/001410.html ... s.co.za/bat.php: 1 Time(s)
       /pipermail/infra/2012-November/001432.html ... al.org/crax.php: 1 Time(s)
       /pipermail/infra/2012-November/001445.html ... gos.ba%2Fsh.php: 2 Time(s)
       /pipermail/infra/2012-November/001445.html ... s.co.za/bat.php: 1 Time(s)
       /pipermail/infra/2012-November/001445.html ... zza.org/bad.php: 1 Time(s)
       /pipermail/infra/2012-November/001471.html ... g.com%2Fbad.php: 3 Time(s)
       /pipermail/infra/2012-November/001471.html ... s.co.za/bat.php: 1 Time(s)
       /pipermail/infra/2012-November/001483.html ... g.com%2Fbad.php: 3 Time(s)
       /pipermail/infra/2012-November/001506.html ... al.com%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-November/001506.html ... z.com%2Fbad.php: 10 Time(s)
       /pipermail/infra/2012-November/001525.html ... oczi.hu/jos.php: 1 Time(s)
       /pipermail/infra/2012-November/001572.html ... s.com%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-November/admin/categ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... .ch%2Fbyroe.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... a.org%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... al.com%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... al.org/crax.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... c.com%2Fbad.php: 2 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... com%2Fbogel.php: 2 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... com%2Findex.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... com%2Fxgood.php: 10 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... g.com%2Fbad.php: 2 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... gos.ba%2Fsh.php: 5 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... oczi.hu/jos.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... om.br%2Fbad.php: 3 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... s.co.za/bat.php: 4 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... s.com%2Fbad.php: 2 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... z.com%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-November/wp-content/ ... zza.org/bad.php: 1 Time(s)
       /pipermail/infra/2012-October//admin/categ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001166.html& ... product_preview: 2 Time(s)
       /pipermail/infra/2012-October/001166.html& ... s.co.za/bat.php: 1 Time(s)
       /pipermail/infra/2012-October/001166.html& ... zi.hu/jahat.php: 1 Time(s)
       /pipermail/infra/2012-October/001166.html/ ... zi.hu/jahat.php: 1 Time(s)
       /pipermail/infra/2012-October/001181.html& ... s.com%2Fcok.php: 1 Time(s)
       /pipermail/infra/2012-October/001183.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001184.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001212.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001215.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001216.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001232.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001235.html& ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001235.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001237.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001244.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/001266.html& ... .info/cilik.php: 1 Time(s)
       /pipermail/infra/2012-October/001266.html& ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-October/001266.html/ ... product_preview: 1 Time(s)
       /pipermail/infra/2012-October/admin/banner ... r.php/login.php: 1 Time(s)
       /pipermail/infra/2012-October/admin/catego ... product_preview: 4 Time(s)
       /pipermail/infra/2012-October/admin/categories.php/login.php: 1 Time(s)
       /pipermail/infra/2012-October/admin/file_m ... r.php/login.php: 1 Time(s)
       /pipermail/infra/2012-October/wp-content/t ... .info/cilik.php: 1 Time(s)
       /pipermail/infra/2012-October/wp-content/t ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-October/wp-content/t ... s.co.za/bat.php: 1 Time(s)
       /pipermail/infra/2012-October/wp-content/t ... s.com%2Fcok.php: 1 Time(s)
       /pipermail/infra/2012-October/wp-content/t ... zi.hu/jahat.php: 2 Time(s)
       /pipermail/infra/2012-September/001015.htm ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-September/001071.htm ... as/curltest.php: 1 Time(s)
       /pipermail/infra/2012-September/001072.htm ... as/curltest.php: 1 Time(s)
       /pipermail/infra/2012-September/001139.htm ... .ch%2Fbyroe.php: 1 Time(s)
       /pipermail/infra/2012-September/001139.htm ... al.com%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-September/001143.htm ... g.com%2Fbad.php: 3 Time(s)
       /pipermail/infra/2012-September/extras/curltest.php: 1 Time(s)
       /pipermail/infra/2012-September/wp-content ... .ch%2Fbyroe.php: 1 Time(s)
       /pipermail/infra/2012-September/wp-content ... al.com%2Fsh.php: 1 Time(s)
       /pipermail/infra/2012-September/wp-content ... g.com%2Fbad.php: 1 Time(s)
       /pipermail/infra/2012-September/wp-content ... gos.ba%2Fsh.php: 1 Time(s)
       /pipermail/infra/admin/banner_manager.php/login.php: 1 Time(s)
       /pipermail/infra/admin/categories.php/login.php: 1 Time(s)
       /pipermail/infra/admin/file_manager.php/login.php: 1 Time(s)
       /pipermail/user/register: 1 Time(s)
       /pipermail/users/2012-August/009192.html/xmlrpc.php: 1 Time(s)
       /pipermail/users/2012-August/009198.html/xmlrpc.php: 1 Time(s)
       /pipermail/users/2012-August/xmlrpc.php: 1 Time(s)
       /pipermail/users/2012-December/mobiquo/mobiquo.php: 1 Time(s)
       /pipermail/users/2012-October/010209.html& ... lf/environ%0000: 1 Time(s)
       /releases/3.1/rpm/fedora/17/noarch/ovirt-n ... fc17.noarch.rpm: 1 Time(s)
       /releases/3.1/rpm/fedora/19/noarch/vdsm-ho ... fc17.noarch.rpm: 1 Time(s)
       /releases/3.2/rpm/EL/6/)oncentos-6.4: 1 Time(s)
       /releases/3.2/rpm/EL/6/x86_64/repodata/repomd.xml: 1 Time(s)
       /releases/3.2_bak/rpm/Fedora/18/repodata/primary.xml.gz: 1 Time(s)
       /releases/3.2_bak/rpm/Fedora/19/: 1 Time(s)
       /releases/beta.old.20120808/rpm/Fedora/17/: 1 Time(s)
       /releases/beta/binary/: 1 Time(s)
       /releases/beta/fedora/: 1 Time(s)
       /releases/beta/fedora/17: 1 Time(s)
       /releases/beta/fedora/17/repodata/filelists.xml.gz: 6 Time(s)
       /releases/beta/fedora/17/repodata/repomd.xml: 21 Time(s)
       /releases/beta/ovirt-engine.repo: 2 Time(s)
       /releases/nightly/RHEL/6/repodata/other.xml.gz: 1 Time(s)
       /releases/nightly/fedora/16/repodata/: 1 Time(s)
       /releases/nightly/fedora/16/repodata/filelists.xml.gz: 24 Time(s)
       /releases/nightly/fedora/16/repodata/repomd.xml: 35 Time(s)
       /releases/ovirt-release-fedora-4-2.noarch.rpm: 1 Time(s)
       /releases/ovirt-release-fedora-5-3-1.noarch.rpm: 1 Time(s)
       /releases/ovit-releas-fedora.noarch.rpm: 1 Time(s)
       /releases/stable/binary/: 1 Time(s)
       /releases/stable/f16: 1 Time(s)
       /releases/stable/fedora: 1 Time(s)
       /releases/stable/fedora/16/: 3 Time(s)
       /releases/stable/fedora/16/ovirt-engine.repo: 4 Time(s)
       /releases/stable/fedora/16/repodata/repomd.xml: 163 Time(s)
       /releases/stable/fedora/18/repodata/repomd.xml: 1 Time(s)
       /releases/stable/ovirt-engine.repo: 2 Time(s)
       /releases/stable/rpm/EL/6/repodata/repomd.xml: 41 Time(s)
       /releases/stable/rpm/EL6/6/repodata/repomd.xml: 45 Time(s)
       /releases/stable/rpm/EL6/6Server/repodata/repomd.xml: 46 Time(s)
       /releases/stable/rpm/EL6/6Workstation/repodata/repomd.xml: 4 Time(s)
       /releases/stable/rpm/Fedora/15/repodata/repomd.xml: 2 Time(s)
       /releases/stable/rpm/Fedora/16/repodata/repomd.xml: 30 Time(s)
       /releases/stable/rpm/Fedora/18/i386/: 2 Time(s)
       /releases/stable/rpm/Fedora/19/: 1 Time(s)
       /releases/stable/rpm/Fedora/19/noarch/old/: 2 Time(s)
       /releases/stable/rpm/Fedora/19/repodata/repomd.xml: 7 Time(s)
       /robots.txt: 30 Time(s)
       /root/passwords: 1 Time(s)
       /trafficbasedsspsitemap.xml: 2 Time(s)
       /wp-content/themes/Aggregate/timthumb.php? ... s.co.za/bat.php: 1 Time(s)
       /wp-content/themes/Avenue/timthumb.php?src ... .ch%2Fbyroe.php: 1 Time(s)
       /wp-content/themes/Avenue/timthumb.php?src ... com%2Fbogel.php: 2 Time(s)
       /wp-content/themes/Avenue/timthumb.php?src ... s.co.za/bat.php: 1 Time(s)
       /wp-content/themes/Envisioned/timthumb.php ... g.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/Minimal/scripts/timthum ... gos.ba%2Fsh.php: 1 Time(s)
       /wp-content/themes/Minimal/timthumb.php?sr ... s.co.za/bat.php: 1 Time(s)
       /wp-content/themes/Minimal/timthumb.php?sr ... zi.hu/jahat.php: 2 Time(s)
       /wp-content/themes/Nova/timthumb.php?src=h ... .info/cilik.php: 1 Time(s)
       /wp-content/themes/Nova/timthumb.php?src=h ... gos.ba%2Fsh.php: 1 Time(s)
       /wp-content/themes/OptimizePress/timthumb. ... com%2Findex.php: 1 Time(s)
       /wp-content/themes/OptimizePress/timthumb. ... g.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/OptimizePress/timthumb. ... gos.ba%2Fsh.php: 1 Time(s)
       /wp-content/themes/OptimizePress/timthumb. ... s.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/TheTravelTheme/includes ... g.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/TheTravelTheme/timthumb ... s.co.za/bat.php: 1 Time(s)
       /wp-content/themes/aperture/thumb.php?src= ... s.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/arras/library/timthumb. ... .ch%2Fbyroe.php: 1 Time(s)
       /wp-content/themes/busybee/thumb.php?src=h ... a.org%2Fbad.php: 1 Time(s)
       /wp-content/themes/busybee/thumb.php?src=h ... oczi.hu/jos.php: 1 Time(s)
       /wp-content/themes/canvas/timthumb.php?src ... gos.ba%2Fsh.php: 1 Time(s)
       /wp-content/themes/crisp/thumb.php?src=htt ... z.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/crisp/timthumb.php?src= ... al.com%2Fsh.php: 1 Time(s)
       /wp-content/themes/delicate/thumb.php?src= ... c.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/delicate/thumb.php?src= ... om.br%2Fbad.php: 3 Time(s)
       /wp-content/themes/ecobiz/timthumb.php?src ... com%2Fxgood.php: 1 Time(s)
       /wp-content/themes/flashnews/timthumb.php? ... gos.ba%2Fsh.php: 2 Time(s)
       /wp-content/themes/flashnews/timthumb.php? ... s.co.za/bat.php: 1 Time(s)
       /wp-content/themes/headlines/timthumb.php? ... gos.ba%2Fsh.php: 1 Time(s)
       /wp-content/themes/mainstream/thumb.php?sr ... c.com%2Fbad.php: 1 Time(s)
       /wp-content/themes/multidesign/scripts/tim ... al.org/crax.php: 1 Time(s)
       /wp-content/themes/multidesign/scripts/tim ... com%2Fxgood.php: 6 Time(s)
       /wp-content/themes/r755/thumb.php?src=http ... al.com%2Fsh.php: 1 Time(s)
       /wp-content/themes/u-design/scripts/timthu ... s.com%2Fcok.php: 1 Time(s)
       /wp-content/themes/welcome_inn/thumb.php?s ... com%2Fxgood.php: 3 Time(s)
       /wp-content/themes/welcome_inn/thumb.php?s ... zza.org/bad.php: 1 Time(s)
       /wp-login.php: 77 Time(s)
       /xmlrpc.php: 1 Time(s)
    416 Request Range Not Satisfiable
       /releases/3.2/iso/ovirt-node-iso-2.6.1-20120228.fc18.iso: 1 Time(s)
       /releases/3.2/rpm/Fedora/18/x86_64/vdsm-py ... fc18.x86_64.rpm: 1 Time(s)
       /releases/3.2/tools/ovirt-live-1.0.iso: 1 Time(s)
       /releases/nightly/rpm/Fedora/18/noarch/ovi ... fc18.noarch.rpm: 3 Time(s)
       /releases/stable/rpm/Fedora/18/i686/libgud ... fc18.2.i686.rpm: 1 Time(s)
       /releases/stable/rpm/Fedora/18/i686/vdsm-4 ... 6.fc18.i686.rpm: 1 Time(s)
       /releases/stable/rpm/Fedora/18/i686/vdsm-4 ... 8.fc18.i686.rpm: 1 Time(s)
       /releases/stable/rpm/Fedora/18/noarch/ovir ... fc18.noarch.rpm: 5 Time(s)
       /releases/stable/rpm/Fedora/18/noarch/vdsm ... fc18.noarch.rpm: 18 Time(s)
       /releases/stable/rpm/Fedora/18/x86_64/libg ... 18.2.x86_64.rpm: 12 Time(s)
       /releases/stable/rpm/Fedora/18/x86_64/syst ... 18.2.x86_64.rpm: 3 Time(s)
       /releases/stable/rpm/Fedora/18/x86_64/vdsm ... fc18.x86_64.rpm: 3 Time(s)
 
 ---------------------- httpd End ------------------------- 

 
 --------------------- Postfix Begin ------------------------ 

        2   *Warning: Pre-queue content-filter connection overload 
 
    1.881M  Bytes accepted                         1,972,175
   10.980M  Bytes delivered                       11,513,407
 ========   ================================================
 
      192   Accepted                                  96.97%
        6   Rejected                                   3.03%
 --------   ------------------------------------------------
      198   Total                                    100.00%
 ========   ================================================
 
        3   Reject relay denied                       50.00%
        3   Reject unknown user                       50.00%
 --------   ------------------------------------------------
        6   Total Rejects                            100.00%
 ========   ================================================
 
      148   Connections made      
        4   Connections lost      
      148   Disconnections        
      177   Removed from queue    
       85   Delivered             
     1810   Sent via SMTP         
        1   Forwarded             
       23   Deferred              
      371   Deferrals             
        2   Bounce (local)        
       11   Bounce (remote)       
        3   Expired and returned to sender 
       16   DSNs undeliverable    
 
      239   Connection failure (outbound) 
        2   Timeout (inbound)     
        7   Hostname verification errors 
       10   Enabled PIX workaround 
 
 
 
 ---------------------- Postfix End ------------------------- 

 
 --------------------- SSHD Begin ------------------------ 

 
 Users logging in through sshd:
    gerrit-backup:
       107.22.212.69 (gerrit.ovirt.org): 3 times
    jenkins:
       93.186.181.42 (jenkins.ekohl.nl): 1 time
 
 
 Received disconnect:
    11: Bye Bye : 1204 Time(s)
    11: disconnected by user : 3 Time(s)
 
 SFTP subsystem requests: 1 Time(s)
 
 **Unmatched Entries**
 reverse mapping checking getaddrinfo for static.customer-201-116-17-163.uninet-ide.com.mx [201.116.17.163] failed - POSSIBLE BREAK-IN ATTEMPT! : 1086 time(s)
 
 ---------------------- SSHD End ------------------------- 

 
 --------------------- Disk Space Begin ------------------------ 

 Filesystem            Size  Used Avail Use% Mounted on
 /dev/xvda              48G   43G  4.4G  91% /
 
 /dev/xvda => 91% Used. Warning. Disk Filling up.
 
 ---------------------- Disk Space End ------------------------- 

 
 ###################### Logwatch End ######################### 

 



More information about the Infra mailing list