Skip to content

Tales from the HomeLab

A Nuts and Bolts Exploration of the Cyber Landscape for System Administrators and Security Analysts

Menu
  • About Us
  • Security Onion
  • Apache
  • WordPress
  • pfSense
Menu

Category: Apache

D-Link Router Compromise Attempt

Posted on August 15, 2024

by Fred Theilig – @[email protected] Security Onion threw up three alerts this week:WGET Command Specifying Output in HTTP HeadersPossible D-Link Router HNAP Protocol Security Bypass AttemptD-Link Devices Home Network Administration Protocol Command…

A (slightly) Deeper Dive into Weird Apache Logs

Posted on May 5, 2023

By Fred Theilig – @fmtheilig My IDS alerted me to strange behavior (obfuscated Log4j) on my web server, but rather than investigate through Security Onion, I went straight to the logs. Greping…

Banner Capture for Fun and Profit

Posted on February 12, 2023

On January 30th I saw the single suricata alert “ET SCAN Zmap User-Agent (Inbound)”. This is a low severity alert and the target was my web server. Let’s see what that’s all…

A Whole Lot of Nothings

Posted on January 27, 2023

On August 18th IP address 23.227.202.82 (Tampa, Florida) triggered the suricata alert “ET SCAN MS Terminal Server Traffic on Non-standard Port” on my web server. This is apparently an attempted information leak,…

An Analysis of a Log4Shell Attack

Posted on November 19, 2022

An interesting thing appeared on my Apache log doorstep in late September. What follows is the actual code received from what I am calling a probable Log4Shell exploit. I was hesitant to…

©2025 Tales from the HomeLab | Design: Newspaperly WordPress Theme