Hack?
Postat: 12 juni 2025, 13:31:37
Vad är detta?
Det två första rader är ganska normala från mig. Inget av de andra IP-nr är några jag känner till. Jag har en Flaskserver. Jag har en kanal genom routern till Flaskservern. Jag tog ner servern när jag såg detta.
Kod: Markera allt
....
127.0.0.1 - - [12/Jun/2025 12:13:49] "GET /items/?start=11&query=event_2025May26 HTTP/1.1" 200 -
127.0.0.1 - - [12/Jun/2025 12:13:50] "GET /items/?start=11&query=event_2025May26 HTTP/1.1" 200 -
198.235.24.211 - - [12/Jun/2025 12:36:20] code 400, message Bad request version ('À\x13À')
198.235.24.211 - - [12/Jun/2025 12:36:20] "\x16\x03\x01\x00î\x01\x00\x00ê\x03\x03\x12K\x96(\x80\x81é\x9aw\x03ð\x19_\x0eëF]ò\x8f\x05w*8ö¦\x00M\x9f¤ñ¶\x12 R븶½\x04ÊÈ/Q\x12$ªZ\x03\x8enº\x92\x0bÙÔz#Ã?\x1b&+)\x93D\x00&À+À/À,À0̨̩À\x09À\x13À" HTTPStatus.BAD_REQUEST -
198.235.24.211 - - [12/Jun/2025 12:36:20] code 400, message Bad request version ('À(À$À\x14À')
198.235.24.211 - - [12/Jun/2025 12:36:20] "\x16\x03\x01\x00Ê\x01\x00\x00Æ\x03\x03\x14¿7ÿ\x189ÓúaüsàÈ\x95øK¬k×÷ÕY\x81O.Î\x14´à\x0c\x96V\x00\x00hÌ\x14Ì\x13À/À+À0À,À\x11À\x07À'À#À\x13À\x09À(À$À\x14À" HTTPStatus.BAD_REQUEST -
90.151.171.106 - - [12/Jun/2025 12:52:17] "CONNECT 90.151.171.106:443 HTTP/1.1" 404 -
90.151.171.106 - - [12/Jun/2025 12:52:27] code 400, message Bad request syntax ('\x04\x01\x00PZ\x97«j0\x00')
90.151.171.106 - - [12/Jun/2025 12:52:27] "\x04\x01\x00PZ\x97«j0\x00" HTTPStatus.BAD_REQUEST -
90.151.171.106 - - [12/Jun/2025 12:52:27] "GET http://90.151.171.106/ip.php?Z73659115251Q1 HTTP/1.1" 404 -
90.151.171.106 - - [12/Jun/2025 12:52:32] code 400, message Bad request syntax ('\x05\x01\x00')
90.151.171.106 - - [12/Jun/2025 12:52:32] "\x05\x01\x00" HTTPStatus.BAD_REQUEST -
147.185.132.141 - - [12/Jun/2025 12:59:16] "GET / HTTP/1.1" 200 -
194.0.234.107 - - [12/Jun/2025 13:12:43] "GET /admin HTTP/1.1" 404 -
205.210.31.226 - - [12/Jun/2025 13:14:04] "GET / HTTP/1.0" 200 -
Kod: Markera allt
$ python3 run.py
* Serving Flask app 'run'
* Debug mode: off
WARNING: This is a development server. Do not use it in a production deployment. Use a production WSGI server instead.
* Running on all addresses (0.0.0.0)
* Running on http://127.0.0.1:5000
* Running on http://192.168.1.105:5000
Press CTRL+C to quit