Greetings,
There a strange occurrences where our proxy server is hitting a particular website 2 week ago starting every morning from 6 am till midnight, thus hogging up both our and their website traffic. These are sample of the logs
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 125 301 151 - - 195 135 204 135 1 DIRECT INTR FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 125 301 151 - - 195 135 204 135 0 DIRECT INTR FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 302 124 302 145 - - 189 136 198 136 1 DIRECT INTR FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 151 301 151 - - 195 135 204 135 0 DIRECT FIN FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 151 301 151 - - 195 135 204 135 0 DIRECT FIN FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:46 +0800] "GET HTTP/1.0" 302 145 302 145 - - 189 136 198 136 1 DIRECT FIN FIN NON-CACHEABLE
This is a sample of a normal log web access where the ip address and the userid "amrk" is shown
10.77.23.1 - amrk [09/Sep/2003:12:57:19 +0800] "GET HTTP/1.0" 304 - 304 - - - 348 140 352 140 0 DIRECT FIN FIN UP-TO-DATE
Appreciated if anyone could shed some lights on what could be happening ? Viruses on the sun solaris machine ?
There a strange occurrences where our proxy server is hitting a particular website 2 week ago starting every morning from 6 am till midnight, thus hogging up both our and their website traffic. These are sample of the logs
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 125 301 151 - - 195 135 204 135 1 DIRECT INTR FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 125 301 151 - - 195 135 204 135 0 DIRECT INTR FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 302 124 302 145 - - 189 136 198 136 1 DIRECT INTR FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 151 301 151 - - 195 135 204 135 0 DIRECT FIN FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:45 +0800] "GET HTTP/1.0" 301 151 301 151 - - 195 135 204 135 0 DIRECT FIN FIN NON-CACHEABLE
localhost - - [09/Sep/2003:10:18:46 +0800] "GET HTTP/1.0" 302 145 302 145 - - 189 136 198 136 1 DIRECT FIN FIN NON-CACHEABLE
This is a sample of a normal log web access where the ip address and the userid "amrk" is shown
10.77.23.1 - amrk [09/Sep/2003:12:57:19 +0800] "GET HTTP/1.0" 304 - 304 - - - 348 140 352 140 0 DIRECT FIN FIN UP-TO-DATE
Appreciated if anyone could shed some lights on what could be happening ? Viruses on the sun solaris machine ?