
Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.
Blue Team lab focused on analyzing Apache HTTP server logs to detect web scanning activity, directory enumeration, and path traversal attempts.
Install and expose an Apache web server in an isolated lab environment, simulate automated web scanning using industry-standard tools, and analyze the generated logs from a Blue Team perspective — identifying attack patterns, tool signatures, and indicators of malicious reconnaissance activity.
| Component | Details |
|---|---|
| Attacker VM | Kali Linux |
| Target VM | Debian 13 |
| Network | NAT Network (VirtualBox) |
| Attacker IP | 10.0.2.5 |
| Target IP | 10.0.2.15 |
| Web server | Apache 2.4.67 |
| Log sources | /var/log/apache2/access.log, /var/log/apache2/error.log |
| HTTP port | 80 |
Confirmed that the Apache HTTP server was active and running on the target machine.
sudo systemctl status apache2 --no-pager
Result: active (running) since Wed 2026-05-06 21:09:17. Apache 2.4.67 (Debian), Main PID 3164, 55 tasks active.
Identified the IP address of the Debian target machine.
ip a
Target IP: 10.0.2.15/24 — interface enp0s3
Verified network connectivity between the Kali attacker machine and the Debian target.
ping -c 4 10.0.2.15
Result: 4 packets transmitted, 4 received, 0% packet loss. RTT min/avg/max: 0.495/1.288/2.139ms.
Accessed the Apache server from the Kali browser to confirm HTTP service availability.
http://10.0.2.15
Result: Apache2 Debian Default Page loaded successfully — confirming the web server was reachable and responding to HTTP requests.
Created test directories and pages on the target server to simulate a realistic web application structure.
sudo mkdir -p /var/www/html/admin
sudo mkdir -p /var/www/html/backup
sudo mkdir -p /var/www/html/login
echo "<h1>Admin Panel</h1>" | sudo tee /var/www/html/admin/index.html
echo "<h1>Login Page</h1>" | sudo tee /var/www/html/login/index.html
Directories created: /admin, /backup, /login
Ran Nikto against the target web server to simulate automated vulnerability scanning.
nikto -h http://10.0.2.15
Nikto v2.5.0 — Start Time: 2026-05-06 20:16:56 — End Time: 20:17:13 (17 seconds)
Findings reported by Nikto:
X-Frame-Options — clickjacking protection absentX-Content-Type-Options — MIME sniffing protection absent/admin/, /backup/, /login//admin/index.html — Admin login page accessibleRan Dirb to perform directory brute forcing against the target web server.
dirb http://10.0.2.15
DIRB v2.22 — Start: Wed May 6 20:19:50 2026 — End: 20:19:59 2026 (9 seconds)
Wordlist used: /usr/share/dirb/wordlists/common.txt — 4612 words tested
Directories and files found:
Warning: /backup/ directory listing is enabled — no index file present, directory contents directly browsable.
Total downloaded: 13836 bytes — Found: 4 resources
Inspected raw access log entries to identify the attack pattern.
sudo cat /var/log/apache2/access.log
Sample entries from the Nikto scan phase (21:18:32):
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10.0.2.15.tar.bz2 HTTP/1.1" 404 527
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10_0_2_15.gz HTTP/1.1" 404 527
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10.0.2.15.sql HTTP/1.1" 404 527
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10.0.2.15.zip HTTP/1.1" 404 527
Sample entries from the Dirb scan phase (21:21:34):
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/xsql HTTP/1.1" 404 472
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/xxx HTTP/1.1" 404 472
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/zimbra HTTP/1.1" 404 472
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/zoom HTTP/1.1" 404 472
Pattern observed: Hundreds of sequential requests within the same second, all targeting non-existent paths — consistent with automated scanning behavior.
Filtered all access log entries originating from the attacker IP.
sudo grep "10.0.2.5" /var/log/apache2/access.log | head -30
Additional patterns observed:
10.0.2.15.tar.bz2, 10.0.2.15.sql, 10.0.2.15.zip)Counted requests by HTTP response code to quantify the attack surface.
sudo grep " 200 " /var/log/apache2/access.log | wc -l
sudo grep " 403 " /var/log/apache2/access.log | wc -l
sudo grep " 404 " /var/log/apache2/access.log | wc -l
| HTTP Code | Meaning | Count |
|---|---|---|
| 200 | OK — resource found and served | 177 |
| 403 | Forbidden — resource exists but access denied | 26 |
| 404 | Not Found — resource does not exist | 21740 |
Total 404 errors: 21,740 — the overwhelming majority of requests targeted paths that do not exist, which is the defining characteristic of automated directory brute forcing.
Counted all access log entries originating from the attacker.
sudo grep "10.0.2.5" /var/log/apache2/access.log | wc -l
Total requests from 10.0.2.5: 21,962
Searched for scanner-specific signatures in the access log.
sudo grep "nikto" /var/log/apache2/access.log | head -5
Result:
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "PUT /nikto-test-pk9VPSjF.html HTTP/1.1" 405 590 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
Nikto created a test file (nikto-test-pk9VPSjF.html) via PUT request to verify write permissions on the server.
sudo grep "DirBuster\|dirb" /var/log/apache2/access.log | head -5
Result: