" E! n$ f+ K' M4 |" f& R|--- 500 Code / M) L' D( m1 r; E! m$ _
192.168.4.4 - - [18/Dec/2001:05:11:04 +0000] "GET /cgi-bin/port80.cgi HTTP/1.0" 500 529 "-" / u9 u2 c) O M- B"Mozilla/4.78 [en] (Win98; U)" % f3 ~5 R- F% _
(access_log) $ W# Y4 ]" K9 o, h" x+ M$ f$ Q* Q9 C
[Thu Dec 13 15:30:23 2001] [error] [client 192.168.4.4] Premature end of script headers: 1 Z7 e0 g4 ]/ I3 u0 U5 p |3 Y E
/usr/local/apache/cgi-bin/port80.cgi 7 J$ s: t3 c7 Y
(error_log) 0 d- W7 ~( @& N3 k8 ?) F3 h( [( X. F5 k5 Q
Depending on what exactly the attacker is attempting to do, will determine exactly what : J& l, T; d& y- N; v
the reason will be in your error_log. - J9 U* o0 F! J) ~5 |6 Q( Q t
" B2 l4 ^4 t7 c k4 w; E
Htaccess error codes 7 G8 | O# C4 a, U/ g
) N5 T2 \3 P0 U) t d并不是所有的错误消息都是由于有人正在对你的系统进行攻击所产生的。更多的情况只是例如用户使用了错误的用户名或者密码这种简单的情况所产生的饿。从另一方面来说也有可能是攻击者运行例如“WWWhack”这样的程序来暴力破解密码以获得须授权区域的访问路径。以下是一个例子: ; W( C+ A$ x. _; T c" z2 h
+ b& j- ?0 c4 d7 X c4 _192.168.5.5 - miked [30/Jan/2002:13:37:26 -0500] "GET /secret HTTP/1.0" 401 397 "-" "Mozilla/4.78 [en]C-CCK-MCD sn ( Z0 a, ?$ ~+ E3 ^: `apN45b1 (Win98; U)" 3 h8 }( E% r$ K
(你的access_log中可能出现类似的信息) & F" y4 G& e; T3 @1 s; o1 I X8 ]* X; h$ F8 c- B; T
[Wed Jan 30 13:37:26 2002] [error] [client 192.168.5.5] user miked: authentication failure for "/secret": password mismatch . @- }+ P/ R/ B! ~- c( ]
(你的error_log中可能出现类似的信息) $ K1 B& b" }5 L% k# G