Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- nginx.conf
- http {
- log_format scott_custom '$ssl_protocol $ssl_cipher $request';
- }
- scotthelme.co.uk.conf
- server {
- access_log /var/log/nginx/scott_custom.log scott_custom;
- }
- mkdir ~/logs/
- cd /var/log/nginx
- sudo cp scott_custom.log.*.gz ~/logs/
- cd ~/logs/
- gunzip *.gz
- cat * >> big.log
- scott@scotthelme:~/logs$ awk '{print $1}' big.log | sort | uniq -c | sort -rn
- 6140215 TLSv1.2
- 466836 TLSv1
- 24787 TLSv1.1
- 610 -
- scott@scotthelme:~/logs$ awk '{print $2}' big.log | sort | uniq -c | sort -rn
- 4083598 ECDHE-RSA-AES128-GCM-SHA256
- 1567382 ECDHE-RSA-AES256-GCM-SHA384
- 533093 ECDHE-RSA-AES256-SHA
- 205345 DHE-RSA-AES256-GCM-SHA384
- 130156 ECDHE-RSA-AES256-SHA384
- 51609 AES256-SHA
- 35278 DHE-RSA-AES256-SHA
- 10837 ECDHE-RSA-AES128-SHA
- 3059 DHE-RSA-AES128-GCM-SHA256
- 2977 DHE-RSA-AES256-SHA256
- 2512 AES128-GCM-SHA256
- 1838 AES256-SHA256
- 1783 DES-CBC3-SHA
- 1295 DHE-RSA-AES128-SHA
- 610 -
- 525 AES256-GCM-SHA384
- 356 (NONE)
- 115 ECDHE-RSA-AES128-SHA256
- 69 AES128-SHA
- 11 EDH-RSA-DES-CBC3-SHA
- scott@scotthelme:~/logs$ awk '{print $3}' big.log | sort | uniq -c | sort -rn
- 6498247 GET
- 76709 HEAD
- 50750 POST
- 5184 PUT
- 427 OPTIONS
- 425 PROPFIND
- 309 \x15\x03\x01\x00\x02\x01\x00
- 140
- 61 \x15\x03\x02\x00\x02\x01\x00
- 53 \x15\x03\x03\x00\x02\x01\x00
- 23 DELETE
- 18 CONNECT
- 17 Accept-Encoding:
- 14 quit
- 12 -
- 9 \x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01\x01
- 7 x
- 6 q
- 4 \x80\x03\x00\x04\x01\x00\x00\x14\x00\x00\x00\x02\x00\x00\x00\x04\x00\x00\x00d\x00\x00\x00\x07\x00\x01\x00\x00\x80\x03\x00\x01\x00\x00\x01r\x00\x00\x00\x01\x00\x00\x00\x00
- 4 \x80\x03\x00\x04\x01\x00\x00\x14\x00\x00\x00\x02\x00\x00\x00\x04\x00\x00\x00d\x00\x00\x00\x07\x00\x01\x00\x00\x80\x03\x00\x01\x00\x00\x01\x5C\x00\x00\x00\x01\x00\x00\x00\x00
- 4 \x15\x03\x03\x00\x02\x02(
- 3 \x15\x03\x01\x00\x02\x02*
- 2 atvv\x0Cvwv\x00tt
- 2 TRACE
- 1 ~\xF1\xFC\xCA\x81\x0E\x035\xE2\xF9\x95\xFDF(;\xEF\xB7.|\x07\x8A\xD4R\xA9\xD8\xFC\xC9r\x0C\xE2On\xD5\xB8fi$T\x12Z\x86-\x88Y\x8E\xA4\x122\xA5$\xD6B\xA3\x9El\x11o_\xFA<0\xAE\x98X
- 1 q\x03\xB3c&68\xA3p\xAC\xC9\x1A\x82\xB6\xAF\x8A!W\xD6\xD2\xF0B\xB6\x1A\xA9\x87B\x0Eg\x98\xF5\xBEX\xB1\xCC\x9B-\xF1\xBDw\xC4\xA8T\xFF\x10\xCA\x9C\xC3\xAD\x82|@\x93X\x1D\xF5\xC0\xB1Y\xDC\xA1{1\x15|0\x9A\xBB\x04<\xB1]S\xF9i\xEB
- 1 j
- 1 atww\xEEvww\xE2twJ\xF1N\xE5\xA0\xFDUanY\xDB\xF88\xE6\xC3\xEF1;\xAA\x1F\xF2T\xA6v:\xF1\xAE\x1A\xCA\x178\xF0ww\x19\xB7c\xB7}wNwOw@wAw\xFFw\xF0w\xF1w\xF2\xB7x\xB7rwBw\xF3\xB7d\xB7~wDwEwFwGw\xEDw\xEEw\xEFw\xE0w2w3w4w5\xB7y\xB7swXw\xE1w6wp\xB7f\xB7p\xB7{\xB7uwrws\xB7e\xB7\x7Fwawdwgwz\xB7z\xB7tw}wbwewxw{w~w\x88vw
- 1 atww\xEEvww\xE2tw7\xE20\xF3\xB5\x15?]\xF9\x0BOa\xDF@\xD2\xE0\x01\xCA\xA9\x95X\xCC\xAE\xE2A\xE6\xE1\xE5\xE7b\x11Uww\x19\xB7c\xB7}wNwOw@wAw\xFFw\xF0w\xF1w\xF2\xB7x\xB7rwBw\xF3\xB7d\xB7~wDwEwFwGw\xEDw\xEEw\xEFw\xE0w2w3w4w5\xB7y\xB7swXw\xE1w6wp\xB7f\xB7p\xB7{\xB7uwrws\xB7e\xB7\x7Fwawdwgwz\xB7z\xB7tw}wbwewxw{w~w\x88vw
- 1 atvw\x92vww\x96tv\xDB(\x92\x8FD(=\xDCC\xE2K\xE1\x84\x83\xA4\xC4X\xD9\xD6\xD3\xF1\xC6\x88\xB5\x9C\x96\x12\xD2s\x84\xFF\xC5ww\x19\xB7c\xB7}wNwOw@wAw\xFFw\xF0w\xF1w\xF2\xB7x\xB7rwBw\xF3\xB7d\xB7~wDwEwFwGw\xEDw\xEEw\xEFw\xE0w2w3w4w5\xB7y\xB7swXw\xE1w6wp\xB7f\xB7p\xB7{\xB7uwrws\xB7e\xB7\x7Fwawdwgwz\xB7z\xB7tw}wbwewxw{w~w\x88vww=wwwbwdwwg\x04\x14\x18\x03\x03\x1F\x12\x1B\x1A\x12Y\x14\x18Y\x02\x1Cw|wstwvuw}wkwmw`wnwkwlwowmwawywzw|w{w~w}wTwwwxwvv
- 1 atvw\x92vww\x96tvT\xD5s\xFA\x11r\xDDY\x8D\xBA
- 1 atvv&vwv:tt\xB1\xD2<\x5C\xDA0\x85\x83'\xBB)\xFA\xDC\xC2\x83\xE2\x9A'\x94\x1Fg8\x91\x1F\xAF\xCC\x9AZ\x1B\x9C\x87#ww\xC1\xB7G\xB7[\xB7_\xB7S\xB7c\xB7}w\xD2w\xD4w\xD6w\xE8w\x1Cw\x1Dw\x1Ew\x1FwNwOw@wAw\xFFw\xF0w\xF1w\xF2\xB7E\xB7Y\xB7]\xB7Q\xB7x\xB7rw\xEAwJwBw\xF3\xB7X\xB7\x5C\xB7P\xB7T\xB7d\xB7~w\xD3w\xD5w\xD7w\xE9w\x10w7wHwIwDwEwFwGw\xEDw\xEEw\xEFw\xE0w2w3w4w5\xB7F\xB7Z\xB7^\xB7R\xB7y\xB7sw\xEBwKwXw\xE1w6wp\xB7f\xB7p\xB7{\xB7uwrws\xB7e\xB7\x7Fwawdwgwz\xB7z\xB7tw}wbwewxw{w~w\x88vww\x19wwwbwdwwg\x04\x14\x18\x03\x03\x1F\x12\x1B\x1A\x12Y\x14\x18Y\x02\x1Cw|wstwvuw}wkwmw`wnwkwlwowmwawywzw|w{w~w}wTwwwzwWwiqvquqtrvrurtsvsusttvtuttuvuuutwxwvv
- 1 atvv&vwv:tt\x03\xAA\x1C4/\xEE\xD4\x9B\xEDI\x07\x09\xB8/\x83)%\xBD=p\xDB\xE8\xD7\xC9\xBA~iM**v\xEAww\xC1\xB7G\xB7[\xB7_\xB7S\xB7c\xB7}w\xD2w\xD4w\xD6w\xE8w\x1Cw\x1Dw\x1Ew\x1FwNwOw@wAw\xFFw\xF0w\xF1w\xF2\xB7E\xB7Y\xB7]\xB7Q\xB7x\xB7rw\xEAwJwBw\xF3\xB7X\xB7\x5C\xB7P\xB7T\xB7d\xB7~w\xD3w\xD5w\xD7w\xE9w\x10w7wHwIwDwEwFwGw\xEDw\xEEw\xEFw\xE0w2w3w4w5\xB7F\xB7Z\xB7^\xB7R\xB7y\xB7sw\xEBwKwXw\xE1w6wp\xB7f\xB7p\xB7{\xB7uwrws\xB7e\xB7\x7Fwawdwgwz\xB7z\xB7tw}wbwewxw{w~w\x88vww\x19wwwbwdwwg\x04\x14\x18\x03\x03\x1F\x12\x1B\x1A\x12Y\x14\x18Y\x02\x1Cw|wstwvuw}wkwmw`wnwkwlwowmwawywzw|w{w~w}wTwwwzwWwiqvquqtrvrurtsvsusttvtuttuvuuutwxwvv
- 1 atvv&vwv:tt4c\x0C\x16\x22\xF6CjUL\x99r\xE0w\x83\xE3\xDC\xCA-\xF6\xB5\xE72,W\xBF\xA7\xBD\xA9\x0B\xF7\xC3ww\xC1\xB7G\xB7[\xB7_\xB7S\xB7c\xB7}w\xD2w\xD4w\xD6w\xE8w\x1Cw\x1Dw\x1Ew\x1FwNwOw@wAw\xFFw\xF0w\xF1w\xF2\xB7E\xB7Y\xB7]\xB7Q\xB7x\xB7rw\xEAwJwBw\xF3\xB7X\xB7\x5C\xB7P\xB7T\xB7d\xB7~w\xD3w\xD5w\xD7w\xE9w\x10w7wHwIwDwEwFwGw\xEDw\xEEw\xEFw\xE0w2w3w4w5\xB7F\xB7Z\xB7^\xB7R\xB7y\xB7sw\xEBwKwXw\xE1w6wp\xB7f\xB7p\xB7{\xB7uwrws\xB7e\xB7\x7Fwawdwgwz\xB7z\xB7tw}wbwewxw{w~w\x88vww\x19wwwbwdwwg\x04\x14\x18\x03\x03\x1F\x12\x1B\x1A\x12Y\x14\x18Y\x02\x1Cw|wstwvuw}wkwmw`wnwkwlwowmwawywzw|w{w~w}wTwwwzwWwiqvquqtrvrurtsvsusttvtuttuvuuutwxwvv
- 1 \x15\x03\x03\x00\x1A\x00\x00\x00\x00\x00\x00\x00\x02\x8B|#Y\xFC\x95y=Z\x22\x22\x1AI#Av\xC6\xA9
- 1 \x05\x02\x00\x02
- 1 \x04\x01\x1F\x00\x00\x00\x00\x00\x00
- 1 \x00\x9C\x00\x01\x1A+<M\x00\x01\x00\x00\x01\x00\x00\x00\x00\x00\x00\x01\x00\x00\x00\x01\x00\x00
- 1 TRACK
- 1 SSH-2.0-LYGhost_1.2.7-20100630
- 1 Hello
- 1 FLURP
- scott@scotthelme:~/logs$ awk '{print $4}' big.log | sort | uniq -c | sort -rn
- 662145 /rss/
- 209532 /assets/css/Aio.min.css
- 205015 /assets/css/rrssb.min.css
- 202162 /assets/js/ga.min.js
- 195522 /assets/js/rrssb.min.js
- 194582 /assets/images/favicon.ico
- 160176 /assets/fonts/fontawesome-webfont.woff?v=4.0.3
- 137152 /
- 133411 /feed/
- 105270 /assets/js/disqus-post.min.js
- 103310 /rss
- 101015 /assets/js/Aio-lib.min.js
- 91287 /assets/js/nr.min.js
- 79905 /setting-up-le/
- 77278 /setting-up-hsts-in-nginx/
- 42766 /hardening-your-http-response-headers/
- 42697 /assets/js/ads.min.js
- 29939 /robots.txt
- 27012 /content/images/2015/02/iis-url-rewrite-view-server-variables-back-to-rules.png
- 26837 /content/images/2015/02/iis-response-headers.png
- 26523 /content/images/2015/02/iis-url-rewrite-view-server-variables.png
- 26510 /content/images/2015/02/iis-url-rewrite-add-rule-content-x-powered-by.png
- 26509 /content/images/2015/02/iis-url-rewrite-add-rule-content-value.png
- 26470 /content/images/2015/02/iis-remove-x-powered-by.png
- 26466 /content/images/2015/02/iis-url-rewrite-add-rule-content.png
- 26463 /content/images/2015/02/iis-url-rewrite.png
- 26459 /content/images/2015/02/iis-url-rewrite-view-server-variables-add.png
- 26452 /content/images/2015/02/iis-url-rewrite-add-rules.png
- 26451 /content/images/2015/02/iis-response-headers-1.png
- 26424 /content/images/2015/02/iis-url-rewrite-add-variable-x-powered-by.png
- 26389 /content/images/2015/02/iis-xfo-header.png
- 26375 /content/images/2015/02/nginx-server-header-source-modified.png
- 26365 /content/images/2015/02/iis-url-rewrite-server-header-with-value.png
- 26364 /content/images/2015/02/nginx-server-header-source.png
- 26362 /content/images/2015/02/iis-xxss-header.png
- 26356 /content/images/2015/02/iis-url-rewrite-blank-server-header.png
- 26350 /content/images/2015/02/iis-url-rewrite-add-rules-blank.png
- 26336 /content/images/2015/02/iis-server-header.png
- 26330 /content/images/2015/02/iis-url-rewrite-view-server-variables-add-value.png
- 26323 /content/images/2015/02/nginx-server-header-1.png
- 26320 /content/images/2015/02/iis-hsts-header.png
- 26313 /content/images/2015/02/iis-csp-header.png
- 26305 /content/images/2015/02/iis-xcto-header.png
- 26303 /content/images/2015/03/iis-hpkp-header.png
- 23119 /content-security-policy-an-introduction/
- 22358 /wp-content/uploads/2013/08/pineapple.png
- 20161 /still-think-you-dont-need-https/
- 19880 /assets/js/disqus.min.js
- 19716 /ee-brightbox-router-hacked/
- 19441 /hpkp-http-public-key-pinning/
- *snip - way too big*
- scott@scotthelme:~/logs$ awk '{print $5}' big.log | sort | uniq -c | sort -rn
- 4167611 HTTP/2.0
- 2418259 HTTP/1.1
- 45907 HTTP/1.0
- 668
- 1 RTSP/1.0
- 1 :-D
- 1 2{A\x11\xC56\xA3\x16v\x8F\x8F\xBB\xE6\x8B\x05k\xF0|\xC3T|dWww\xBD\xB7G\xB7[\xB7_\xB7S\xB7c\xB7}\xB7U\xB7Vw\xD4w\xE8w\x1Cw\x1DwNwOw\xFFw\xF0\xB7n\xB7Ww\xD0w\x1AwMw\xFE\xB7E\xB7Y\xB7]\xB7Q\xB7x\xB7rw\xEAwJwBw\xF3\xB7e\xB7\x7F\xB7k\xB7lwawd\xB7`\xB7mwl\xB7z\xB7tw}\xB7X\xB7\x5C\xB7P\xB7T\xB7d\xB7~\xB7h\xB7iw\xD5w\xE9w\x10w7wDwEw\xEDw\xEEw2w3\xB7o\xB7jw\xD1w\x1BwCw\xECw1\xB7F\xB7Z\xB7^\xB7R\xB7y\xB7sw\xEBwKwXw\xE1w6wp\xB7f\xB7p\xB7awo\xB7{\xB7uwrwswbwewmw~wcwfwnw\x7Fwqw`wtw\x88vww\xF3wwwbwdwwg\x04\x14\x18\x03\x03\x1F\x12\x1B\x1A\x12Y\x14\x18Y\x02\x1Cw|wstwvuw}wCwEwywzwnw|w{wow~w}waw`w\x7FwqwpwcwbwswrwewdwvwuwtwxwgwfwzwUwWqvquqtrvrurtsvsusttvtuttuvuuutvvwxwvv
Add Comment
Please, Sign In to add comment