Example: /awstats Default: /cgi-bin (means is in /yourwwwroot/cgi.

Note that these statistics are public unless you secure them.Īdd the following code to /etc/crontab for each domain:Ġ */3 * * * /usr/lib/cgi-bin/ -config=yourdomain. with -output option (to generate links in HTML reported page). Statistics for yourdomain.ext should now be available at:įor if you have multiple config files. Reload apache2: /etc/init.d/apache2 reload.Options +ExecCGI -MultiViews +SymLinksIfOwnerMatch Otherwise, add this code inside the VirtualHost tag for each domain you want to monitor: Alias /awstatsclasses "/usr/share/awstats/lib/"Īlias /awstats-icon "/usr/share/awstats/icon/"Īlias /awstatscss "/usr/share/doc/awstats/examples/css" If you have no VirtualHosts set up, place the following code in '/etc/apache2/sites-available/default'. Navigate to /etc/apache2/sites-available/ cd /etc/apache2/sites-available/ Now i get the following errors: code:1 The AWstats command /usr/share/awstats/Check the module.In order to access Awstats, we have to tell Apache2 where it is. generate the initial stats for AWStats based on existing var/log/apache2/access.log: /usr/lib/cgi-bin/ -config=yourdomain.ext -updateįirst tell your apache to use mod_cgi if you haven't enabled it yet a2enmod cgi.make the following changes: LogFile="/var/log/apache2/access.log" SiteDomain="yourdomain.ext" HostAliases="localhost yourdomain.ext".Open file with vi or nano: vi /etc/awstats/ or nano /etc/awstats/.This is the case for SQL Injection, CMD execution, RFI, LFI, etc.

Module Ranking and Traits Module Ranking: excellent: The exploit will never crash the service. iDEFENSE has confirmed that AWStats versions 6.1 and 6.2 are vulnerable. Create a copy of nf for each domain: cp /etc/awstats/nf /etc/awstats/ This module exploits an arbitrary command execution vulnerability in the AWStats CGI script.

Install AWStats with Synaptic or sudo apt-get install awstatsĪwstats configuration files in Ubuntu are located in /etc/awstats. For more help, get XChat and subscribe to channel "#awstats" on the Ubuntu Server. It assumes you already have an Apache2 web server up and running. The following documentation contains specific information on installing and configuring Awstats with Ubuntu and Apache2.

It can analyze log files from all major server tools like Apache log files (NCSA combined/XLF/ELF log format or common/CLF log format), WebStar, IIS (W3C log format) and a lot of other web, proxy, wap, streaming servers, mail servers and some ftp servers. AWStats is Perl script licensed under the GNU General Public License that can work in standalone (command line) and CGI modes and generates web site usage. Note that path '/usr/local/awstats/' must reflect your AWStats Installation path. It uses a partial information file to be able to process large log files, often and quickly. Directives to add to your Apache conf file to allow use of AWStats as a CGI.

This log analyzer works as a CGI or from command line and shows you all possible information your log contains, in few graphical web pages. AWStats is a free powerful and featureful tool that generates advanced web, streaming, ftp or mail server statistics, graphically.

