Entenda o log de erros do Nginx

2

Eu tinha arquivos de log de erros do Nginx como:

2016/12/16 14:24:45 [error] 2758#0: *506 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 109.61.223.87, server: www.mydomain.fr, request: "GET /download/50/MSMxOz0jM3owLS4rZnJxLAcYExcdCQkdBRMHRQIMGhoCEB4fDQUaEhkKDwkZUwwKr+Xj9+Xa4eL81vrq/uzj/K/3+/x5qulrqiorq+prquWB2bz5A/kbz_ii_v41.exe?sign=global-rus_treid_2?static?cr=60c1ec2384?signtool=osslsigncode-2?rnd=trnt HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php7.0-fpm.sock:", host: "dlc.certainlesson.ru"

Qual é o significado de host: "dlc.certainlesson.ru" ?

Ou log de erros como:

2016/12/16 15:50:45 [error] 2743#0: *85931 FastCGI sent in stderr: "PHP message: PHP Warning: require(/home/ubuntu/myapp/releases/20161216145901/vendor/composer/../guzzle/guzzle/src/Guzzle/Common/Exception/InvalidArgumentException.php): failed to open stream: No such file or directory in /home/ubuntu/myapp/releases/20161216145901/app/bootstrap.php.cache on line 2850
PHP message: PHP Fatal error: require(): Failed opening required '/home/ubuntu/myapp/releases/20161216145901/vendor/composer/../guzzle/guzzle/src/Guzzle/Common/Exception/InvalidArgumentException.php' (include_path='.:/usr/share/php') in /home/ubuntu/myapp/releases/20161216145901/app/bootstrap.php.cache on line 2850" while reading response header from upstream, client: 163.172.129.17, server: www.myapp.fr, request: "GET /download/ad/zNzM2NjE1pndwsPIg5WUz97Yz6eoramnvavpvaejv6mpqaqkoKe6saG6rvarr/S4vKq+v4aHl7uVh5WJhJnUioSCioPMwMXFx8PHzMrLzQdmkBM/all-in-one_checker_crack_v3_8.exe?sign=global-rus_treid_2?static?cr=4af9a4e12c?signtool=osslsigncode-2?rnd= HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php7.0-fpm.sock:", host: "dlc.magic-terrify.ru", referrer: "https://dlc.magic-terrify.ru/download/ad/zNzM2NjE1pndwsPIg5WUz97Yz6eoramnvavpvaejv6mpqaqkoKe6saG6rvarr/S4vKq+v4aHl7uVh5WJhJnUioSCioPMwMXFx8PHzMrLzQdmkBM/all-in-one_checker_crack_v3_8.exe?sign=global-rus_treid_2?static?cr=4af9a4e12c?signtool=osslsigncode-2?rnd="

Alguém conseguiu executar código no meu servidor sem o meu conhecimento?

Agradeço antecipadamente por explicações.

    
por me987654323 02.01.2017 / 11:44

1 resposta

1

O HTTP GET é uma solicitação de dados de um recurso especificado. No seu caso, esse recurso é dlc.certainlesson.ru .

No registro 15:50:45, parece que o arquivo all-in-one_checker_crack_v3_8.exe foi solicitado com HTTP GET usando

https://dlc.magic-terrify.ru/download/ad/zNzM2NjE1pndwsPIg5WUz97Yz6eoramnvavpvaejv6mpqaqkoKe6saG6rvarr/S4vKq+v4aHl7uVh5WJhJnUioSCioPMwMXFx8PHzMrLzQdmkBM/all-in-one_checker_crack_v3_8.exe

return Nenhum arquivo ou diretório desse tipo

Espero que isso ajude.

    
por 02.01.2017 / 17:36

Tags