- IMSCP: 1.4.3
- Distribution: Debian 8.6
- Proftpd
- PHP FCGID
- MariaDB 10.0
- Courier
- Roundcube
- Pydio
- Plugins:
PanelRedirect 1.1.5, PMA Captcha 1.1.1, RoundCubePlugins 2.0.1, SpamAssassin 1.1.1 , LetsEncrypt 3.2.0
I see many of these requests in my panel access.log
Code
- 188.165.203.182 - - [27/May/2017:15:45:18 +0200] "GET /wp-admin/setup-config.php?step=1 HTTP/1.1" 404 724 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
- 178.18.90.86 - - [27/May/2017:15:43:05 +0200] "GET /blog/wp-admin/setup-config.php?step=1 HTTP/1.1" 302 250 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
- 82.217.114.19 - - [27/May/2017:15:41:13 +0200] "GET /manager/assets/modext/core/modx.js HTTP/1.1" 302 247 "-" "Mozilla/5.0 (Windows NT 6.2; rv:46.0) Gecko/20100101 Firefox/46.0"
- 94.23.35.86 - - [27/May/2017:15:40:27 +0200] "GET /new/wp-admin/setup-config.php?step=1 HTTP/1.1" 404 724 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
- 80.91.50.132 - - [27/May/2017:16:02:31 +0200] "GET /wp-admin/setup-config.php?step=1 HTTP/1.1" 302 245 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
It seems to be a slowloris attack which could also explain my apache timeouts ...