Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
apache-web-log-analysis-lab — Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity. | Kitploit
Tools/GitHubGitHub/pedrofbrm/apache-web-log-analysis-lab
Web SecurityLearning & EducationLog AnalysisLabs & Practice
GitHubpedrofbrm/apache-web-log-analysis-lab

apache-web-log-analysis-lab

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

View Repository
234 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Apache Web Log Analysis Lab

Blue Team lab focused on analyzing Apache HTTP server logs to detect web scanning activity, directory enumeration, and path traversal attempts.


Objective

Install and expose an Apache web server in an isolated lab environment, simulate automated web scanning using industry-standard tools, and analyze the generated logs from a Blue Team perspective — identifying attack patterns, tool signatures, and indicators of malicious reconnaissance activity.


Environment

ComponentDetails
Attacker VMKali Linux
Target VMDebian 13
NetworkNAT Network (VirtualBox)
Attacker IP10.0.2.5
Target IP10.0.2.15
Web serverApache 2.4.67
Log sources/var/log/apache2/access.log, /var/log/apache2/error.log
HTTP port80

Steps Performed

1. Apache Service Validation

Confirmed that the Apache HTTP server was active and running on the target machine.

sudo systemctl status apache2 --no-pager

Result: active (running) since Wed 2026-05-06 21:09:17. Apache 2.4.67 (Debian), Main PID 3164, 55 tasks active.


2. Target IP Identification

Identified the IP address of the Debian target machine.

ip a

Target IP: 10.0.2.15/24 — interface enp0s3


3. Connectivity Test

Verified network connectivity between the Kali attacker machine and the Debian target.

ping -c 4 10.0.2.15

Result: 4 packets transmitted, 4 received, 0% packet loss. RTT min/avg/max: 0.495/1.288/2.139ms.


4. Apache Browser Test

Accessed the Apache server from the Kali browser to confirm HTTP service availability.

http://10.0.2.15

Result: Apache2 Debian Default Page loaded successfully — confirming the web server was reachable and responding to HTTP requests.


5. Web Content Setup

Created test directories and pages on the target server to simulate a realistic web application structure.

sudo mkdir -p /var/www/html/admin
sudo mkdir -p /var/www/html/backup
sudo mkdir -p /var/www/html/login
echo "<h1>Admin Panel</h1>" | sudo tee /var/www/html/admin/index.html
echo "<h1>Login Page</h1>" | sudo tee /var/www/html/login/index.html

Directories created: /admin, /backup, /login


6. Nikto Scan

Ran Nikto against the target web server to simulate automated vulnerability scanning.

nikto -h http://10.0.2.15

Nikto v2.5.0 — Start Time: 2026-05-06 20:16:56 — End Time: 20:17:13 (17 seconds)

Findings reported by Nikto:

  • Server: Apache/2.4.67 (Debian)
  • Missing header: X-Frame-Options — clickjacking protection absent
  • Missing header: X-Content-Type-Options — MIME sniffing protection absent
  • ETag leak: Server may leak inode numbers via ETags (CVE-2003-1418)
  • Allowed methods: GET, POST, OPTIONS, HEAD
  • Interesting directories found: /admin/, /backup/, /login/
  • Confirmed: /admin/index.html — Admin login page accessible
  • Total requests: 8102 in 17 seconds

7. Dirb Scan

Ran Dirb to perform directory brute forcing against the target web server.

dirb http://10.0.2.15

DIRB v2.22 — Start: Wed May 6 20:19:50 2026 — End: 20:19:59 2026 (9 seconds)

Wordlist used: /usr/share/dirb/wordlists/common.txt — 4612 words tested

Directories and files found:

URLCodeSize
http://10.0.2.15/index.html20010703
http://10.0.2.15/server-status403314
http://10.0.2.15/admin/200—
http://10.0.2.15/admin/index.html20021
http://10.0.2.15/backup/200—
http://10.0.2.15/login/200—
http://10.0.2.15/login/index.html20020

Warning: /backup/ directory listing is enabled — no index file present, directory contents directly browsable.

Total downloaded: 13836 bytes — Found: 4 resources


8. Access Log Analysis

Inspected raw access log entries to identify the attack pattern.

sudo cat /var/log/apache2/access.log

Sample entries from the Nikto scan phase (21:18:32):

10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10.0.2.15.tar.bz2 HTTP/1.1" 404 527
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10_0_2_15.gz HTTP/1.1" 404 527
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10.0.2.15.sql HTTP/1.1" 404 527
10.0.2.5 - - [06/May/2026:21:18:32 -0300] "GET /10.0.2.15.zip HTTP/1.1" 404 527

Sample entries from the Dirb scan phase (21:21:34):

10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/xsql HTTP/1.1" 404 472
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/xxx HTTP/1.1" 404 472
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/zimbra HTTP/1.1" 404 472
10.0.2.5 - - [06/May/2026:21:21:34 -0300] "GET /login/zoom HTTP/1.1" 404 472

Pattern observed: Hundreds of sequential requests within the same second, all targeting non-existent paths — consistent with automated scanning behavior.


9. Scan Pattern by Source IP

Filtered all access log entries originating from the attacker IP.

sudo grep "10.0.2.5" /var/log/apache2/access.log | head -30

Additional patterns observed:

  • Nikto attempted to access backup files using the server IP as filename (e.g., 10.0.2.15.tar.bz2, 10.0.2.15.sql, 10.0.2.15.zip)
  • Dirb iterated through alphabetically ordered wordlists targeting each discovered directory
  • Both tools generated requests at machine speed — multiple entries per second from the same source port range

10. HTTP Status Code Distribution

Counted requests by HTTP response code to quantify the attack surface.

sudo grep " 200 " /var/log/apache2/access.log | wc -l
sudo grep " 403 " /var/log/apache2/access.log | wc -l
sudo grep " 404 " /var/log/apache2/access.log | wc -l
HTTP CodeMeaningCount
200OK — resource found and served177
403Forbidden — resource exists but access denied26
404Not Found — resource does not exist21740

Total 404 errors: 21,740 — the overwhelming majority of requests targeted paths that do not exist, which is the defining characteristic of automated directory brute forcing.


11. Total Requests by Attacker IP

Counted all access log entries originating from the attacker.

sudo grep "10.0.2.5" /var/log/apache2/access.log | wc -l

Total requests from 10.0.2.5: 21,962


12. Tool Signature Identification

Searched for scanner-specific signatures in the access log.

Nikto signature

sudo grep "nikto" /var/log/apache2/access.log | head -5

Result:

10.0.2.5 - - [06/May/2026:21:18:32 -0300] "PUT /nikto-test-pk9VPSjF.html HTTP/1.1" 405 590 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"

Nikto created a test file (nikto-test-pk9VPSjF.html) via PUT request to verify write permissions on the server.

Dirb signature

sudo grep "DirBuster\|dirb" /var/log/apache2/access.log | head -5

Result:

Download Tool