Tracking down network flood

My server was attacked last night, at roughly 1:02AM - 1:40AM, with the attack slowing down after that (so Apache started logging again). Here's what I was able to get from the logs:

213.60.65.43 - - [18/Mar/2003:01:30:38 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:30:41 -0500] "-" 408 - "-" "-"
211.61.66.54 - - [18/Mar/2003:01:30:42 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:30:42 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:30:43 -0500] "-" 408 - "-" "-"
211.61.66.54 - - [18/Mar/2003:01:30:56 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:00 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:01 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:13 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:15 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:15 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:16 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:17 -0500] "-" 408 - "-" "-"
200.221.59.202 - - [18/Mar/2003:01:31:17 -0500] "-" 408 - "-" "-"
200.221.59.202 - - [18/Mar/2003:01:31:17 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:26 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:28 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:34 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:40 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:41 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:47 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:47 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:48 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:48 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:48 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:49 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:49 -0500] "-" 408 - "-" "-"
200.221.59.202 - - [18/Mar/2003:01:31:49 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:52 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:52 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:54 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:55 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:58 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:31:59 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:00 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:05 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:05 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:05 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:14 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:15 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:15 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:15 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:16 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:16 -0500] "-" 408 - "-" "-"
24.98.94.75 - - [18/Mar/2003:01:32:16 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:22 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:24 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:24 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:25 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:25 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:26 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:26 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:28 -0500] "-" 408 - "-" "-"
213.60.65.43 - - [18/Mar/2003:01:32:29 -0500] "-" 408 - "-" "-"
218.164.6.128 - - [18/Mar/2003:01:41:17 -0500] "-" 408 - "-" "-"
218.164.6.128 - - [18/Mar/2003:01:41:18 -0500] "-" 408 - "-" "-"
218.164.6.128 - - [18/Mar/2003:01:41:18 -0500] "-" 408 - "-" "-"
218.164.6.128 - - [18/Mar/2003:01:41:21 -0500] "-" 408 - "-" "-"
218.160.11.229 - - [18/Mar/2003:01:41:26 -0500] "-" 408 - "-" "-"
218.160.11.229 - - [18/Mar/2003:01:41:27 -0500] "-" 408 - "-" "-"
218.2.8.31 - - [18/Mar/2003:01:41:58 -0500] "-" 408 - "-" "-"
80.14.21.115 - - [18/Mar/2003:01:52:51 -0500] "-" 408 - "-" "-"
218.5.13.225 - - [18/Mar/2003:01:52:57 -0500] "-" 408 - "-" "-"
218.104.232.116 - - [18/Mar/2003:01:53:04 -0500] "-" 408 - "-" "-"
80.14.21.115 - - [18/Mar/2003:01:53:28 -0500] "-" 408 - "-" "-"
80.14.21.115 - - [18/Mar/2003:01:53:34 -0500] "-" 408 - "-" "-"
218.235.16.226 - - [18/Mar/2003:01:53:35 -0500] "-" 408 - "-" "-"
218.235.16.226 - - [18/Mar/2003:01:53:35 -0500] "-" 408 - "-" "-"
218.235.16.226 - - [18/Mar/2003:01:53:35 -0500] "-" 408 - "-" "-"
80.14.21.115 - - [18/Mar/2003:01:53:40 -0500] "-" 408 - "-" "-"
80.26.61.224 - - [18/Mar/2003:01:54:29 -0500] "-" 408 - "-" "-"
218.235.16.226 - - [18/Mar/2003:01:54:56 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
211.213.249.18 - - [18/Mar/2003:02:35:15 -0500] "-" 408 - "-" "-"
Looks like the 408's are Request Timed Out... What are these trying to access? These look like cable modems from the traces - as you'll notice, there are some legit requests thrown in with the bad ones.

Note: I had to delete parts of the log posted here due to length, they can be found at http://www.mainarea.com/log.txt
- Matt

 

 

 

 

Top