I’ve recently set up a tiny Debian VPS for hosting a couple of personal sites.
In the Apache access logs, I’ve noticed quite a few requests for URLs like /phpMyAdmin-2.6.4/scripts/setup.php
coming from one particular IP address. The IP address in question is listed on Project Honeypot. They haven’t noticed any dodgy activity from it recently, but I got these requests this morning.
I don’t run any of the services the IP address seems to be looking for, but I wondered whether I should block all requests from this IP address using the firewall on my server. I’m thinking it would at least clear up my access logs, and if it’s one IP address, in the worst case scenario, I wouldn’t have blocked many users from the site if it was used for legitimate purposes in future.