Odd log requests

37 views
Skip to first unread message

Phillip Vector

unread,
Feb 17, 2016, 10:06:54 AM2/17/16
to lu...@googlegroups.com
So about 6 months ago, I made a page on my local server that pulls up a list of movies I had in a directory and displayed them as links (I was working on a way to make the WiiU in my living room play movies).. 

Fast forward.. About a month ago, I started noticing a remote IP trying to access (and succeeding) the local server and pulling it up. Thing is, my WiiU is packed away since I moved and I can confirm that isn't it.

It's happening every minute and there is no port forwarding through port 80 to my machine.

When I pull up the logs, I get this.

User Agent:Microsoft-WebDAV-MiniRedir/6.1.7601
Lucee (Neo) Os FINAL 4.5.1.000 (CFML Version 10,0,0,0)
Time StampFeb 17, 2016 6:58 AM
Time ZoneAmerica/Los_Angeles
LocaleEnglish (us)
Remote IP[Redacted]

This is my local computer, but I'm not running anything that checks it every minute. Does anyone have any suggestions on how I can figure out what is accessing this link? There are no scheduled tasks that are running (or even entered) that would do this.


Denard Springle

unread,
Feb 18, 2016, 2:10:15 PM2/18/16
to Lucee, vec...@mostdeadlygame.com
The user agent is a good place to start...

http://security.stackexchange.com/questions/44600/is-this-a-security-issue-at-the-remote-host-or-the-local-host


Is that folder shared over your network, by any chance?

-- Denny

Denard Springle

unread,
Feb 18, 2016, 2:18:08 PM2/18/16
to Lucee, vec...@mostdeadlygame.com

Phillip Vector

unread,
Feb 18, 2016, 2:45:28 PM2/18/16
to lu...@googlegroups.com
It was shared. Now it isn't and the connections continue.

I'm not using IIS, so I don't think it's WebDAV is doing it. I tried ending Chrome, but that didn't help.

--
Love Lucee? Become a supporter and be part of the Lucee project today! - http://lucee.org/supporters/become-a-supporter.html
---
You received this message because you are subscribed to the Google Groups "Lucee" group.
To unsubscribe from this group and stop receiving emails from it, send an email to lucee+un...@googlegroups.com.
To post to this group, send email to lu...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/lucee/6653b69f-7413-4b24-8f4d-042861cc1bf9%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Phillip Vector

unread,
Feb 18, 2016, 2:55:55 PM2/18/16
to lu...@googlegroups.com
Well... Damm..

After a lot of outputting to a text file, I got this.

User Agent:Microsoft-WebDAV-MiniRedir/6.1.7601

I guess that IS my problem. Thanks for the heads up. I have no idea what turned this on.

Phillip Vector

unread,
Feb 18, 2016, 2:59:01 PM2/18/16
to lu...@googlegroups.com
Weird though.. I don't have IIS installed on my Windows 7 machine.

Phillip Vector

unread,
Feb 18, 2016, 3:17:01 PM2/18/16
to lu...@googlegroups.com
Oddly as well, it stopped at 11:58AM (it was doing it every 2 mins twice). Almost like a scheduled task, but there are none of those either.

Phillip Vector

unread,
Feb 18, 2016, 3:19:43 PM2/18/16
to lu...@googlegroups.com
and now it's back at 12:15pm.. *cries*

Phillip Vector

unread,
Feb 18, 2016, 3:24:08 PM2/18/16
to lu...@googlegroups.com
So... If another computer inside the network is accessing the tomcat host on the main computer, that won't show up at localhost.. Right?



User Agent:Microsoft-WebDAV-MiniRedir/6.1.7601
Lucee (Neo) Os FINAL 4.5.1.000 (CFML Version 10,0,0,0)
Time StampFeb 18, 2016 12:21 PM
Time ZoneAmerica/Los_Angeles
LocaleEnglish (us)
Remote IP[Redacted] 853:8299:f5a4:da64%10
Host Namefloyd
Architecture64bit

The remote IP has that %10 at the end, but that's my IPv6 IP for the local host ("floyd"). Is it possible another computer is accessing it? If so, wouldn't the remote IP show that computers IP? Is there something about the %10 at the end that I'm not understanding?



Reply all
Reply to author
Forward
0 new messages