Lesson 1 of 1 in The One Request That Worked
A Million That Failed
An internet-facing box is scanned constantly. Almost all of it is noise, and the skill is knowing which shape is not.
2 min read
Not yet reviewed
Every server on the public internet is probed continuously by automated scanners looking for known-vulnerable software. This is background radiation. It has nothing to do with you, it never stops, and a beginner reading an access log for the first time usually concludes they are under sustained attack.
They are not. They are looking at weather. The job is to find the one line that is not weather.
What noise looks like
203.0.113.7 - - [14/Aug/2026:02:11:04 +0000] "GET /wp-login.php" 404 162
198.51.100.44 - - [14/Aug/2026:02:11:19 +0000] "GET /.env" 404 162
203.0.113.7 - - [14/Aug/2026:02:11:31 +0000] "GET /phpmyadmin/" 404 162
192.0.2.88 - - [14/Aug/2026:02:12:02 +0000] "GET /.git/config" 404 162
198.51.100.44 - - [14/Aug/2026:02:12:44 +0000] "POST /xmlrpc.php" 404 162
Five different attacks, none of which can succeed, because none of that software is installed. Every one is a 404. A thousand of these tells you nothing except that your server has an IP address.
Note
The status code is the filter. A scanner firing at software you do not run produces 404 after 404. The request that mattered got a 200, or a 302, or a 500 — because it reached something real.
The shape that is not weather
Three shapes are worth your attention, and all three are about a change in pattern rather than about any single line.
Worth looking at
A path you recognise, answered 200, from an address that never appears again
A long burst of 404s from one address, then one 200, then silence
A 500 — you made the application crash, which means you reached itWeather
Thousands of 404s for software you do not run
The same three paths from a hundred different addresses
Anything at all against /wp-login.php on a site that is not WordPressThe middle-left one is the classic: the scanner found something, and the silence afterwards is somebody switching from a tool to their hands.
That is enough theory. The rest of this lesson is a real log — four hundred lines from a real-looking morning — and one request in it worked.
This is the access log from the morning of the defacement. One request was answered with a 200 by something that should not have answered at all. Find it.
Notice what you did not do: you did not read four hundred lines. You filtered on the property that separates *reached something* from *bounced off nothing*, and there was one line left.
Tip
grep " 200 " access.log is the highest-value command in this course. When it returns too much — because your site legitimately serves traffic — narrow by adding the hour, or by excluding the paths you know are yours.
You grep for 200s and get eight thousand lines, because the site is busy. What narrows it fastest?