Log File

 
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions
View previous topic :: View next topic  
Author Message
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Thu Mar 18, 2004 1:35 pm    Post subject: Log File Reply with quote

Four abnormalities I found in my log file: 1.) A whole 2 pages of a mix of random readable and unreadable characters. 2.) About 2/3 of a page of 'blocks' (letters that can't be displayed). 3.) An entire 4 pages of markup. 4.) Sites that arn't mine, just randoms ones that I go to in IE. Does anybody know how or what is causing this?
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Anonymoose
-


Joined: 09 Sep 2003
Posts: 2192

PostPosted: Thu Mar 18, 2004 2:22 pm    Post subject: Reply with quote

Are you using an ad blocker ? A lot of them work by redirecting adverts to 127.0.0.1 (your machine) under the assumption there is nothing there, so the advert should time out and fail to load. If you're running a server you will see these appear in your log file as they attempt to load from your site instead of failing. The Abyss log should be showing 404's. As for the unreadable characters, I'm not sure - unless someone with a badly configured browser has viewed the site and sent all their requests in a foreign character set / unicode. Could you post a chunk of it ?
Back to top View user's profile Send private message
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Thu Mar 18, 2004 2:23 pm    Post subject: Reply with quote

I believe that in some early versions that
HTML from web pages would appear in
your log file , I haven't noticed any more.

You may have some traces of a worm
trying to hack into your system , post
a sample of the log file here.
Back to top View user's profile Send private message Visit poster's website
iNaNimAtE
-


Joined: 05 Nov 2003
Posts: 2381
Location: Everywhere you're not.

PostPosted: Thu Mar 18, 2004 11:48 pm    Post subject: Reply with quote

I can almost guarantee you that some of the log entries are IIS exploits taking place. You have nothing to worry about though, because you are using Abyss.
_________________
Bienvenidos!
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Fri Mar 19, 2004 1:13 am    Post subject: Reply with quote

Heres some sample lines:

127.0.0.1 - - [28/Mar/2003:03:36:52 +0100] "GET /ad/N763.starcom.yahoo/B1086033.112;sz=1x1;ord=1048819009379391? HTTP/1.0" 404 427 "http://us.f208.mail.yahoo.com/ym/ShowFolder?rb=Inbox&reset=1&YY=87875" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90; YComp 5.0.2.4)"
127.0.0.1 - - [28/Mar/2003:03:37:01 +0100] "GET /ad/N763.starcom.yahoo/B1086033.112;sz=1x1;ord=1048819019247256? HTTP/1.0" 404 427 "http://us.f208.mail.yahoo.com/ym/ShowLetter?MsgId=7128_1983593_874_1184_599_0_4840_1139_2582576731&YY=39625&inc=200&order=down&sort=date&pos=0&view=a&head=f&box=Inbox" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90; YComp 5.0.2.4)"
127.0.0.1 - - [28/Mar/2003:03:41:11 +0100] "GET /ad/N3289.Yahoo/B1116250.5;sz=300x250;ord=1048819267173343? HTTP/1.0" 404 427 "http://us.f208.mail.yahoo.com/ym/ShowFolder?ET=1&.crumb=KDJDOpOd0sJ&reset=1&YY=52297&inc=200&order=down&sort=date&pos=0&view=a&head=f&box=%40B%40Bulk" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90; YComp 5.0.2.4)"
127.0.0.1 - - [28/Mar/2003:03:49:32 +0100] "GET /site=138745/size=425600/bnum=1048819766/bins=1/rich=0 HTTP/1.0" 404 427 "http://us.f208.mail.yahoo.com/ym/ShowFolder?rb=Inbox&reset=1&YY=17298&inc=200&order=down&sort=date&pos=0&view=a&head=f&box=Inbox&YN=1" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90; YComp 5.0.2.4)"


And this:

¼È>ÿKèo`Z,È‚Æ.ŒÃ^¢zšž`1Á|s3œ½zè¾
^‘®X­è[Wž¢pœîX%|‰£EpuëÅ!Tb‘b
2È%\?º­FÛž,f².!ˆX'6ž.¡Ê'+

And this also:
<html>
<head>
<title>Some Title</title>
.........


Well I can't post the 'blocks' in here for some reason.
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
iNaNimAtE
-


Joined: 05 Nov 2003
Posts: 2381
Location: Everywhere you're not.

PostPosted: Fri Mar 19, 2004 1:40 am    Post subject: Reply with quote

In reference to:
"127.0.0.1 - - [28/Mar/2003:03:36:52 +0100] "GET /ad/N763.starcom.yahoo/B1086033.112;sz=1x1;ord=1048819009379391? HTTP/1.0" 404 427 "http://us.f208.mail.yahoo.com/ym/ShowFolder?rb=Inbox&reset=1&YY=87875" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90; YComp 5.0.2.4)" "

First of all, the guy is using Windows 98, so you really have nothing to worry about. Second, I'm just guessing, but it looks like he came from viewing a mail message, to guessing a url on your webserver. Notice the "404" meaning he didn't get very far.
_________________
Bienvenidos!
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Sat Mar 20, 2004 4:36 pm    Post subject: Reply with quote

Well 127.0.0.1 = localhost = me. I'm still wondering how all my normal surfing gets in my Abyss log.
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
TRUSTAbyss
-


Joined: 29 Oct 2003
Posts: 3752
Location: USA, GA

PostPosted: Sat Mar 20, 2004 4:56 pm    Post subject: Reply with quote

What version of Abyss Web Server are you using ?
Back to top View user's profile Send private message Visit poster's website
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Sun Mar 21, 2004 4:01 am    Post subject: Reply with quote

Im using 1.2.2.2.
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
aprelium
-


Joined: 22 Mar 2002
Posts: 6800

PostPosted: Mon Mar 22, 2004 3:11 pm    Post subject: Reply with quote

jmoschetti45,

If you're running Windows 98 with IE 5.5, these log lines seems to be generated by an ad blocker which redirects ad requests to localhost. Usually people won't notice something, but if you have a web server on the computer, it will answer the requests.
_________________
Support Team
Aprelium - http://www.aprelium.com
Back to top View user's profile Send private message Send e-mail
sat
-


Joined: 20 Mar 2004
Posts: 5

PostPosted: Sat Mar 27, 2004 9:16 pm    Post subject: Re: Log File Reply with quote

jmoschetti45 wrote:
Four abnormalities I found in my log file: 1.) A whole 2 pages of a mix of random readable and unreadable characters. 2.) About 2/3 of a page of 'blocks' (letters that can't be displayed). 3.) An entire 4 pages of markup. 4.) Sites that arn't mine, just randoms ones that I go to in IE. Does anybody know how or what is causing this?


I had similar problems with the log file displaying hex instead of text
delete the access.log file and create a new blank one in notepad.
Back to top View user's profile Send private message
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Tue Apr 06, 2004 12:14 am    Post subject: Reply with quote

Yes, deleting it fixes the problem. But it will just happen again.

Well I tried IE 6, Mozilla, Opera, Netscape, Firefox, and Avant. Its clearly not related to the browser. Plus I have the ad requests show up as 127.0.0.1.
_________________
http://jmoschetti45.com
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
iNaNimAtE
-


Joined: 05 Nov 2003
Posts: 2381
Location: Everywhere you're not.

PostPosted: Tue Apr 06, 2004 12:36 am    Post subject: Reply with quote

The internet can be strange. Have you tried turning "Extended Logging Format" to "OFF?"
_________________
Bienvenidos!
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Tue Apr 06, 2004 2:55 am    Post subject: Reply with quote

No, but I will as soon as I get my server back up. Currently the hard drive has filled up because of another unknown problem. Got 0 bytes free and nothing runs (That problem is in another thread).
_________________
http://jmoschetti45.com
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
aprelium
-


Joined: 22 Mar 2002
Posts: 6800

PostPosted: Wed Apr 07, 2004 1:45 pm    Post subject: Reply with quote

jmoschetti45,

Do you have an ad blocker?
_________________
Support Team
Aprelium - http://www.aprelium.com
Back to top View user's profile Send private message Send e-mail
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Wed Apr 07, 2004 3:38 pm    Post subject: Reply with quote

No. The only form of ad 'blocking' I use is adding the ad servers to my hosts file. But that redirects them to 127.0.0.2 and I see the 127.0.0.2 in the log.
_________________
http://jmoschetti45.com
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
iNaNimAtE
-


Joined: 05 Nov 2003
Posts: 2381
Location: Everywhere you're not.

PostPosted: Thu Apr 08, 2004 2:16 am    Post subject: Reply with quote

Is there a way just to turn the log off? Maybe remove the "Log File" directory entry...
_________________
Bienvenidos!
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
jmoschetti45
-


Joined: 29 Oct 2003
Posts: 95
Location: MI USA

PostPosted: Thu Apr 08, 2004 2:23 am    Post subject: Reply with quote

Not really I think. Im sure I could modify Abyss to stop it but I want the log. If something goes wrong (eg: hacker) I need to be able to get IP. Plus its nice to keep track of visitors. It's not a major problem with all of the extra trash in it. Its just annoying.
_________________
http://jmoschetti45.com
Back to top View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    Aprelium Forum Index -> General Questions All times are GMT + 1 Hour
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB phpBB Group