Seitenanfang

Error log analysis

Dieser Post wurde aus meiner alten WordPress-Installation importiert. Sollte es Darstellungsprobleme, falsche Links oder fehlende Bilder geben, bitte einfach hier einen Kommentar hinterlassen. Danke.


I've been forced to check the webserver error logs today - and got some really surprising results. A really big amount of requests tried to get /cgi-bin/cache/[some_hex_string] and I suspected our Javascript guys to do something really strange they shouldn't do - but was wrong.

The requests are spread over many, maybe all, different domains. Here are some (slighty anonymized) samples:

99.999.99.999 - [29/Jan/2013:02:06:42 +0100] "GET /cgi-bin/cache/3081a2c3bc1d9e2fcf64ab875d57f9df HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.999.999 - [29/Jan/2013:07:33:16 +0100] "GET /cgi-bin/cache/235af1ab04978fa0b5dd4fa13c2576f3 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.999 - [29/Jan/2013:05:47:19 +0100] "GET /cgi-bin/cache/55dd94ed9f285b4c78b86bb04fa17c36 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.99 - [29/Jan/2013:02:40:39 +0100] "GET /cgi-bin/cache/046708d10d5fda0ba9b374664d620b70 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.9 - [29/Jan/2013:08:40:28 +0100] "GET /cgi-bin/cache/9cfd009e43704006e16e06f004decbd5 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.999 - [29/Jan/2013:03:10:42 +0100] "GET /cgi-bin/cache/2c6fa1c8400f519e3ec3bafc590d08eb HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.99.99 - [29/Jan/2013:03:53:18 +0100] "GET /cgi-bin/cache/9654500f0a6de653582f8193c8c3e51f HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.99.999 - [29/Jan/2013:05:08:23 +0100] "GET /cgi-bin/cache/b79258bbb42d67c1adc44b4076189cb5 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.9.9.999 - [29/Jan/2013:06:13:46 +0100] "GET /cgi-bin/cache/3b6b74d5a92c729ce36a9d055d3db8e9 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.99.99 - [29/Jan/2013:02:19:52 +0100] "GET /cgi-bin/cache/22551183c958e3152736bea1670507d7 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.999.999 - [29/Jan/2013:02:06:29 +0100] "GET /cgi-bin/cache/524eb54ca2a16215dfa072fe53bbbfc9 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.99.999 - [29/Jan/2013:02:06:59 +0100] "GET /cgi-bin/cache/7c0c08cc2e8f5949f3056f0308b06cbb HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.70 Safari/535.11"99.99.99.999 - [29/Jan/2013:02:59:36 +0100] "GET /cgi-bin/cache/bcaafda50a1aa8122667984ddd1856c6 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.99.999 - [29/Jan/2013:04:58:27 +0100] "GET /cgi-bin/cache/fb348dd30bf6edae1f50a9726091317f HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.999.999 - [29/Jan/2013:02:07:48 +0100] "GET /cgi-bin/cache/35a5b241bd97f3e57ab64e58420b3660 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.52 Safari/537.17"99.999.99.99 - [29/Jan/2013:05:34:55 +0100] "GET /cgi-bin/cache/57bf234caf87fd993ae22ea015a937b7 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.999 - [29/Jan/2013:02:26:25 +0100] "GET /cgi-bin/cache/18bbf73279ba206eaaf48789183ca05b HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.999.999 - [29/Jan/2013:02:19:14 +0100] "GET /cgi-bin/cache/c4e4af69ac132a962d52a431cc2db44b HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.99.999 - [29/Jan/2013:02:06:41 +0100] "GET /cgi-bin/cache/710f1d1b2d92305ddff8c58d7516acea HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.99.999 - [29/Jan/2013:02:56:22 +0100] "GET /cgi-bin/cache/71e71630ac7419946dfdad98aab801cc HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.9.9.999 - [29/Jan/2013:02:17:21 +0100] "GET /cgi-bin/cache/f957c5e85ada9453140c099a07513899 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"9.999.99.999 - [29/Jan/2013:04:30:26 +0100] "GET /cgi-bin/cache/88ab2a9fe257646a09b5ae28e7ed65e9 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.999.999 - [29/Jan/2013:19:32:16 +0100] "GET /cgi-bin/cache/c0d217ae6698aa08b7e22c9e9f1d2bee HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.99 - [29/Jan/2013:02:21:38 +0100] "GET /cgi-bin/cache/d93b511bd72eee697915a09ebaa29a8a HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.99 - [29/Jan/2013:03:37:42 +0100] "GET /cgi-bin/cache/d31fee2103d18244b731b1623650ec2e HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.99.999 - [29/Jan/2013:02:10:54 +0100] "GET /cgi-bin/cache/0e1624eaab90456d96020a2732e8b9eb HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.99.999.99 - [29/Jan/2013:02:35:33 +0100] "GET /cgi-bin/cache/2159b4f105792ca8cb35c9a8d35db990 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"99.999.99.99 - [29/Jan/2013:20:28:16 +0100] "GET /cgi-bin/cache/5b4b81b3ab46a966736a06844b2c41ae HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.0) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.99.99.999 - [29/Jan/2013:02:00:54 +0100] "GET /cgi-bin/cache/b04d1b258a3ac0ae471f537603e6172a HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.19 (KHTML, like Gecko) Chrome/25.0.1323.1 Safari/537.19"99.999.999.99 - [29/Jan/2013:05:10:37 +0100] "GET /cgi-bin/cache/e9c5ecc3f9d7fa1291240700c8da0728 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.999.999 - [29/Jan/2013:02:14:31 +0100] "GET /cgi-bin/cache/09fe503e5898bcba55056542d470a803 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.70 Safari/535.11"999.999.999.999 - [29/Jan/2013:02:11:41 +0100] "GET /cgi-bin/cache/71c2900847ecd4f560699d72e185beff HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.99.999.99 - [29/Jan/2013:02:00:59 +0100] "GET /cgi-bin/cache/121dd294d0865e35c0d529b188ce61b9 HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"999.999.9.99 - [29/Jan/2013:06:00:59 +0100] "GET /cgi-bin/cache/9f6015e7e7ab284b2d697b3713c2f02f HTTP/1.1" 404 564 "" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.17 (KHTML, like Gecko) Chrome/24.0.1312.56 Safari/537.17"

 

Doesn't look like a Javascript problem, because only Chrome browsers seem to be affected. There are many of these requests each day to the webservers I looked at - but much less than overall Chrome requests they get per day.

It took some time but finally I found an existing Chrome bug report describing exactly this issue: Unintended requests to /cache/ - URLs which don't exist.

Feel free to read the bug report and the discussion but the conclusion is: It's not Chrome's fault at all (which complies to my numbers of /cache/ requests vs. overall Chrome visitors), but it's a Chrome plugin called "Ginyas Browser Companion" (whatever this is) which issues these requests.

Some other requests tried to POST to /mobiquo/mobiquo.php - another URL which is completely invalid for servers not running PHP at all - they support Perl only. Theses requests are also unsolicited and issued by clients using a browser plugin. A Stackoverflow question solved this mystery: mobiquo.php is being used by Tapatalk, which is trying to get "Push messages" from the webserver. Maybe they mixed up POST with "push"...

 

2 Kommentare. Schreib was dazu

  1. enter air avis

    Hello would you mind stating which blog platform you're using? I'm planning to start
    my own blog in the near future but I'm having a tough time selecting between BlogEngine/Wordpress/B2evolution and Drupal. The reason I ask is because your layout seems different then most blogs and I'm looking for something completely unique.
    P.S My apologies for getting off-topic but I had to ask!

  2. Sebastian

    It's basically Wordpress, but I think I'ld go for MovableType if I'ld make a new blog.

Keine Kommentare mehr möglich