have BIG trouble with dissapeared database content.
in some way all db entries have been deleted.
the database is just part of a bigger project and only accessible for administration (and protected via .htaccess)
on the main-site all the antries are (were) listed in short-form, below each a link for 'edit' 'details' and 'delete'
the delete link opens a page 'fs.content.delete.php?id=XX'
now take a look at the logfile at the bottom:
-every page request cmes from the sam ip and allways calls the same lins (edit, details, delete)
-the whole thing goes quite fast (+/- 5 requests/second)
-it's HTTP/1.0 (sould it not be 1.1 for most browsers)
-from the site-layout it is impossible to regenerate this order of requests
-googeling gave me the result that it could be the msnSpider
the ip 212.23.xxx.xxx belongs to the company i'm working for (runs the webserver AND theyr proxy)
so my possible explination:
it was a searchengine spider running on the named server that caused the requests. the question remains why this stupid spider knows username and password!
could it be that's a combination of webserver/searchengine/proxy and the searchengine gets new urls through the proxy?
and then? does the proxy also give out passwords?
or does our webserver give access to the searchengine because there was already an established connection from that ip?
or am i completely wrong?
would really appreciate any answers that could track down this problem (and prevent me from lawer-battles...)
thanks in advance!
and ask if u need mor infos (logs etc)
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:37 +0100] "GET /img/eoeoeo.gif HTTP/1.0" 404 208 "http://xxxxxxxxxxxxxxxx.xx/fs.content.l-ext.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:38 +0100] "GET /fs.top.php HTTP/1.0" 200 1437 "http://xxxxxxxxxxxxxxxx.xx/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:38 +0100] "GET /fs.menu.php HTTP/1.0" 200 1322 "http://xxxxxxxxxxxxxxxx.xx/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:38 +0100] "GET /fs.bottom.php HTTP/1.0" 200 969 "http://xxxxxxxxxxxxxxxx.xx/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:38 +0100] "GET /fs.content.l-short.php HTTP/1.0" 200 101105 "http://xxxxxxxxxxxxxxxx.xx/index.php" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:43 +0100] "GET /fs.content.delete.php?id=21 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:43 +0100] "GET /fs.content.d-ext.php?id=22 HTTP/1.0" 200 20080 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:43 +0100] "GET /fs.content.d-ext.php?id=21 HTTP/1.0" 200 18678 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:43 +0100] "GET /fs.content.d-edit.php?id=21 HTTP/1.0" 200 24256 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:28:43 +0100] "GET /fs.content.l-short.php?id=21 HTTP/1.0" 200 98588 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:10 +0100] "GET /fs.content.delete.php?id=23 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:10 +0100] "GET /fs.content.d-edit.php?id=22 HTTP/1.0" 200 24762 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:10 +0100] "GET /fs.content.d-ext.php?id=23 HTTP/1.0" 200 18678 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:10 +0100] "GET /fs.content.d-edit.php?id=23 HTTP/1.0" 200 23597 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:10 +0100] "GET /fs.content.d-edit.php?id=47 HTTP/1.0" 200 25833 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:11 +0100] "GET /fs.content.l-short.php?id=23 HTTP/1.0" 200 96079 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:11 +0100] "GET /fs.content.delete.php?id=47 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:11 +0100] "GET /fs.content.delete.php?id=25 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:11 +0100] "GET /fs.content.d-ext.php?id=25 HTTP/1.0" 200 20416 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:12 +0100] "GET /fs.content.d-ext.php?id=46 HTTP/1.0" 200 19690 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:12 +0100] "GET /fs.content.l-short.php?id=47 HTTP/1.0" 200 91011 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:12 +0100] "GET /fs.content.l-short.php?id=25 HTTP/1.0" 200 91011 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:12 +0100] "GET /fs.content.d-edit.php?id=46 HTTP/1.0" 200 24464 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:13 +0100] "GET /fs.content.delete.php?id=46 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:14 +0100] "GET /fs.content.d-edit.php?id=49 HTTP/1.0" 200 25878 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:14 +0100] "GET /fs.content.d-ext.php?id=49 HTTP/1.0" 200 21265 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:14 +0100] "GET /fs.content.d-ext.php?id=20 HTTP/1.0" 200 19892 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:14 +0100] "GET /fs.content.l-short.php?id=46 HTTP/1.0" 200 88486 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:15 +0100] "GET /fs.content.delete.php?id=20 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:15 +0100] "GET /fs.content.d-edit.php?id=20 HTTP/1.0" 200 23597 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:15 +0100] "GET /fs.content.d-edit.php?id=26 HTTP/1.0" 200 26951 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:15 +0100] "GET /fs.content.l-short.php?id=20 HTTP/1.0" 200 85971 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:18 +0100] "GET /fs.content.delete.php?id=26 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:18 +0100] "GET /fs.content.delete.php?id=48 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:19 +0100] "GET /fs.content.d-ext.php?id=48 HTTP/1.0" 200 20493 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:19 +0100] "GET /fs.content.d-ext.php?id=19 HTTP/1.0" 200 21295 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:19 +0100] "GET /fs.content.d-edit.php?id=48 HTTP/1.0" 200 23597 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:19 +0100] "GET /fs.content.l-short.php?id=48 HTTP/1.0" 200 80954 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:19 +0100] "GET /fs.content.delete.php?id=19 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:19 +0100] "GET /fs.content.d-ext.php?id=27 HTTP/1.0" 200 20223 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:20 +0100] "GET /fs.content.delete.php?id=27 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:20 +0100] "GET /fs.content.delete.php?id=28 HTTP/1.0" 302 0 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:20 +0100] "GET /fs.content.l-short.php?id=19 HTTP/1.0" 200 78437 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:20 +0100] "GET /fs.content.d-edit.php?id=28 HTTP/1.0" 200 23597 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:20 +0100] "GET /fs.content.l-short.php?id=27 HTTP/1.0" 200 75917 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
212.23.xxx.xxx - swiss-subcon [14/Feb/2005:16:29:21 +0100] "GET /fs.content.l-short.php?id=28 HTTP/1.0" 200 73400 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"