hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Hosting Security and Technology Tutorials : 501 error in apache
Reply

Hosting Security and Technology Tutorials Tutorials related to server security or the like.
Forum Jump

501 error in apache

Reply Post New Thread In Hosting Security and Technology Tutorials Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-31-2005, 12:20 AM
thejas thejas is offline
Newbie
 
Join Date: Apr 2005
Location: Bangalore
Posts: 13
Question

501 error in apache


501errors killing apache. Httpd connection increase so high that apache goes down as soon as it is restarted. Do any one have any clue about this weird problem.
==========
#tail -f /usr/local/apache/logs/error_log
[Sat Jul 30 23:42:40 2005] [error] [client xxxxxxx] Invalid method in request OfQSnUBjyyyN2JxjJSWuLx2six8MP9u4Zr3JVSXHJ6MgASFOliMOq7RBybGjWBtyHPYgg8UdbFbXjkLVikcsiIOoaXmjjC3p71P3oERHyRNGhUTsIB0HQ4ZuIiNNQOSN
[Sat Jul 30 23:42:40 2005] [error] [client xxxxxxx] Invalid method in request Vp8YPNvIN7giIBGolK3dZvEzFDmDOi5KP5EoCilYSKLhP
[Sat Jul 30 23:42:45 2005] [error] [client xxxxxxx] Invalid method in request vV1uIP4TztKBWD5EwdxIyBg2CZijw5GFKmZoJc

#tail -f /usr/local/apache/logs/access_log
xxxxxx- - [30/Jul/2005:23:44:35 -0400] "r0Lfl0eoJtoibvNTxPsLmRBX" 501 -
xxxxxx - - [30/Jul/2005:23:44:35 -0400] "dr6DmXXypNS2bRf3l11cwMrNS2jP1Sq0wEWrTnERqmdDN5xgbM2ngD0IhNboqslx" 501 -
xxxxxx - - [30/Jul/2005:23:44:35 -0400] "-" 408 -
xxxxxx - - [30/Jul/2005:23:44:35 -0400] "GaLk1AAeG9bnx6ZsbcllqGUqwMt2h9KltrISnD6SX0ooxyW86AjLCaZmlKwYWq1RPxULUH6SmhFZHgaTA" 501 -
xxxxxx- - [30/Jul/2005:23:44:36 -0400] "i8hRuSwYAfWOA0vYuHEPXs52SexVLqML2NLEs23gKtEQRF23j2j78LwbgMJZLFks46qiJV7pUKf8i8EILQ6yU0g4gcEFwWfNnQCW3nUSAl6WHPkCRa" 501 -

# ps -aux |grep http|wc -l
212
=============

I have replaced IPs with xxxxx in the logs.

Reply With Quote


Sponsored Links
  #2  
Old 07-31-2005, 02:28 AM
gilbert gilbert is offline
Web Hosting Master
 
Join Date: Jun 2003
Location: United States of America
Posts: 1,831
what programs running off of apache there? prolly php or cgi my guess? it could be running to many times if you got people accessing a site

please insite us on your website(s) and ram and processor

Reply With Quote
  #3  
Old 07-31-2005, 07:23 AM
jamesyeeoc jamesyeeoc is offline
Junior Guru
 
Join Date: Dec 2003
Location: Sunny So. Calif.
Posts: 204
Wouldn't this be more of a flood of requests coming in to his server? PHP or cgi running internally on his server would not show in the access_log. To me it looks like someone is trying to possibly do a buffer overflow.

@thejas - if the IP addresses are the same or just a few, you may want to consider blocking them in APF/Iptables, then restart Apache. If they are all within the same netblock of addresses, then you may have to (at least temporarily) block a range.

Reply With Quote
Sponsored Links
  #4  
Old 08-02-2005, 04:34 PM
thejas thejas is offline
Newbie
 
Join Date: Apr 2005
Location: Bangalore
Posts: 13
Yeh, it was an attempt to do buffer overflow, a kind of DoS attack.

Thank you

Reply With Quote
  #5  
Old 08-02-2005, 06:38 PM
pfak pfak is offline
Junior Guru Wannabe
 
Join Date: Nov 2002
Location: British Columbia, Canada
Posts: 44
That's a SYN Flood, not trying to compromise your server.

Reply With Quote
  #6  
Old 08-03-2005, 05:58 PM
thejas thejas is offline
Newbie
 
Join Date: Apr 2005
Location: Bangalore
Posts: 13
Can this be stopped, other than by blocking IP`s.

Reply With Quote
  #7  
Old 08-03-2005, 07:44 PM
jamesyeeoc jamesyeeoc is offline
Junior Guru
 
Join Date: Dec 2003
Location: Sunny So. Calif.
Posts: 204
There was another post recently in the Technical & Security forum with APF/Iptables rules.

http://www.webhostingtalk.com/showth...hreadid=363499

http://www.webhostingtalk.com/showth...23#post2169023

http://www.webhostingtalk.com/showth...85#post2786185

There are more, use Search, terms: apf iptables syn

Reply With Quote
  #8  
Old 08-03-2005, 08:10 PM
thejas thejas is offline
Newbie
 
Join Date: Apr 2005
Location: Bangalore
Posts: 13
I have noticed that most of the hostile IPs were from China and Taiwan.
Is it Chinese Language that is seen as garbage in logs.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Researchers Urge System Admins to Check for New Apache Web Server Backdoor Malware Web Hosting News 2013-05-01 11:35:53
Apache Web Server Adds Cloud Capabilities with First Major Update in 5 Years Web Hosting News 2012-02-21 16:05:02
The Apache Software Foundation Launches Hadoop v1.0 Web Hosting News 2012-01-05 18:29:16
Oracle is the Latest Vendor to Apply Patch for Apache Killer Flaw Web Hosting News 2011-09-19 14:43:58
Patch Released for Apache Software DDoS Vulnerability Web Hosting News 2011-08-26 15:03:10


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?