Groups keyboard shortcuts have been updated
Dismiss
See shortcuts

OBA Access Log

34 views
Skip to first unread message

Devin Braun

unread,
Oct 9, 2024, 10:44:18 AM10/9/24
to onebusaway-developers
Hi everyone,

Suddenly our OBA logs got enormous.  When looking at the logs, there are literally hundreds of calls per second to this address:

These are from the tomcat-9 directory:
/onebusaway-transit-data-federation-webapp/remoting/transit-data-service

There seem to be corresponding logs in the tomcat6 directory like this for but different stop IDs:
2024-10-07 17:36:56,328 WARN  [RemoteInvocationTraceInterceptor.java:87] : Processing of HessianServiceExporter remote call resulted in fatal exception: org.onebusaway.transit_data.services.TransitDataService.getStop
org.onebusaway.exceptions.NoSuchStopServiceException: No such stop: SAN_92041

What would explain this behavior?  Is it somebody trying to get stop updates every second for many stops, or a cyber attack issue?

Thanks,

Devin

Wojciech Kulesza

unread,
Oct 9, 2024, 10:50:13 AM10/9/24
to onebusaway...@googlegroups.com
Hi,
since those requests end up with No such Stop:.... message, it seems like this is some kind of attack. Can you see the IP addresses and block such range of IP in the firewall to see if that helps out straight away ?

We saw situations like this, but not to OBA in some cases and those were random automatized ways to see if a server can be brought down or accessed.

Let me know if that helps ?

Wojciech


--
You received this message because you are subscribed to the Google Groups "onebusaway-developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email to onebusaway-devel...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/onebusaway-developers/32124dcc-8f05-4d4d-9d76-7399562844b6n%40googlegroups.com.


--

Wojciech Kulesza

Właściciel / Owner

goEuropa Polska Wojciech Kulesza

+48616248682
wojciech...@goeuropa.eu
www.goeuropa.eu
ul. 28 Czerwca 1956r nr 406

Sheldon A. Brown

unread,
Oct 9, 2024, 1:55:48 PM10/9/24
to onebusaway...@googlegroups.com
I would guess this is a bot trying to index the site based on the example you gave.  If you want to discourage indexing of your OBA you can create a robots.txt which may or may not be respected.

If the issue is still on-going, see if you can get a user-agent string from the requesting client, that should confirm the issue.

Sheldon

Reply all
Reply to author
Forward
0 new messages