|
Home > Archive > Perlbal > June 2007 > Separating requests with persistent backends
You are viewing an archived Text-only version of the thread.
To view this thread in it's original format and/or if you want to reply to
this thread please [click here]
| Author |
Separating requests with persistent backends
|
|
| André Cruz 2007-05-30, 7:11 am |
| Hello all.
Ever since I enabled persistent connections to the backends I get =20
strange requests in my apache error logs. I'll paste one in the end =20
of the mail.
The request seems to be part of another request that was split =20
somehow as it doesn't contain the first part (GET, POST, =20
whatever ...). This wouldn't concern me much, as the request seems =20
like SPAM, if not for the last part of the request: GET /js/pngfix.js =20=
HTTP/1.0. It seems that this bogus request is messing up the next =20
request in line as well...
Just so you know this is a Livejournal installation and the request =20
seems to try to leave a comment. I was expecting Perlbal to discard =20
these invalid requests or at least separate them...
Is my analysis wrong?
Thanks,
Andr=E9
[Wed May 30 11:11:19 2007] [error] [client 10.135.64.111] Invalid =20
method in request =20
replyto=3D&parenttalkid=3D0&itemid=3D36185&journal=3Dasminhasbijuterias&ch=
rp1=3D36=20
185-67653-1178229600-WlQb7jSFB9foAIKwZSrC-ee52bf366bf
415ee4f0914bca253de5d&usertype=3Danonymous&guest_userpost=3D&guest_user_ur=
l=3D=20
http%3A%2F%2Fxwgtkvyq.pochtamt.ru%=20
2F128.html&userpost=3D&password=3Duelpfcvylh&do_login=3D&captcha_chal=3Dc0=
%=20
3A1178229600%3A3049%3A900%3A3ccnHlD8
cVFNEP59a64T%=20
3A05cfd4ae84bf57bbc0819da874594362&answer=3D&checkCommentOrto=3DVerificar=20=
+Ortografia&submitpost=3DPublicar&submitpreview=3DPr%26eacute%3B-=20
visualizar& body=3D%3CA+href%3Dhttp%3A%2F%2Fvizthsbg
342.nightmail.ru%
2F172. html%3E%EA%E0%F1%F1%EE%E2%FB%E9+%E0%EF%E
F%E0%F0%E0%F2+%F7%E5%EB%=20=
FF%E1%E8%ED%F1%EA+%EF%F0%EE%E4%E0%EC+%E1
+%F3%3C%2FA%3E%0Ahttp%3A%2F%=20
2Fvizthsbg342.nightmail.ru%2F172.html%0A%5Burl%3Dhttp%3A%2F%2Fvizthsbg3
42.nightmail.ru%2F172. html%5D%EA%E0%F1%F1%EE%E2%FB%E9+%E0%EF%E
F%E0%F0%=20=
E0%F2+%F7%E5%EB%FF%E1%E8%ED%F1%EA+%EF%F0
%EE%E4%E0%EC+%E1+%F3%5B%2Furl%=20=
5D%0A%3CA+href%3Dhttp%3A%2F%2Flgykbcpb18
15.nightmail.ru%2F259.html%3E
%EC%E8%F2%FF%E5%E2+%EA%F0%E5%EF%E8%F2%E5
%F1%FC+%EB%FE%E4%E8+%F1%EA%EE%=20=
F0%EE+%EB%E5%F2%EE%3C%2FA%3E%0Ahttp%3A%2
F%2Flgykbcpb1815.nightmail.ru%=20=
2F259. html%0A%5Burl%3Dhttp%3A%2F%2Flgykbcpb181
5.nightmail.ru%2F259.ht
ml%5D%EC%E8%F2%FF%E5%E2+%EA%F0%E5%EF%E8%
F2%E5%F1%FC+%EB%FE%E4%E8+%F1%=20
EA%EE%F0%EE+%EB%E5%F2%EE%5B%2Furl%5D%0A%
3CA+href%3Dhttp%3A%2F%=20
2Fotisalrssj.krovatka.su%2F48. html%3E%F1%EA%EB%E0%E4+%EE%EF%F2%3C%2FA%
=20=
3E%0Ahtt
p%3A%2F%2Fotisalrssj.krovatka.su%2F48.html%0A%5Burl%3Dhttp%3A%2F%=20
2Fotisalrssj.krovatka.su%2F48.html%5D%F1%EA%EB%E0%E4+%EE%EF%F2%5B%=20
2Furl%5D%0A%3CA+href%3Dhttp%3A%2F%2Faumq
mvuo.front.ru%2F198.html%3E%EA=20=
%E0%F0%F
2%E0+%FD%EA%EE%EB%EE%E3%E8%F7%E5%F1%EA%E
8+%ED%E5%E1%EB%E0%E3%EE%EF%F0%=20=
E8%FF%F2%ED%FB%F5+%EC%E5%F1%F2+%E2+%F1%E
0%ED%EA%F2-%EF%E5%F2%F0%E1%F3%=20=
F0%E3%E5%3C%2FA%3E%0Ahttp%3A%2F%2Faumqmv
uo.front.ru%2F198.html%0A%5Bu
rl%3Dhttp%3A%2F%2Faumqmvuo.front.ru%2F198.html%5D%EA%E0%F0%F2%E0+%FD%=20
EA%EE%EB%EE%E3%E8%F7%E5%F1%EA%E8+%ED%E5%
E1%EB%E0%E3%EE%EF%F0%E8%FF%F2%=20=
ED%FB%F5+%EC%E5%F1%F2+%E2+%F1%E0%ED%EA%F
2-%EF%E5%F2%F0%E1%F3%F0%E3%E5%
5B%2Furl%5D%0A%3CA+href%3Dhttp%3A%2F%2Fk
mtyqtotn.rbcmail.ru%2F69.html%=20=
3E%F8%E0%E1%EB%EE%ED%FB+%EE%F4%E8%F6%E8%
E0%EB%FC%ED%FB%F5+%EF%E8%F1%=20
E5%EC%3C%2FA%3E%0Ahttp%3A%2F%2Fkmtyqtotn
.rbcmail.ru%2F69.html%0A%5Burl%
3Dhttp%3A%2F%2Fkmtyqtotn.rbcmail.ru%2F69.html%5D%F8%E0%E1%EB%EE%ED%FB+=20=
%EE%F4%E8%F6%E8%E0%EB%FC%ED%FB%F5+%EF%E8
%F1%E5%EC%5B%2Furl%5D%0A%3CA=20
+href%3Dhttp%3A%2F%2Faydxjiwakd705.nm.ru%2F314.html%3E%F2%F0%E8%EB%EE%E
3%E8%FF+%E3%EE%ED%F7%E0%F0%EE%E2%E0+%EE%
E1%F0%FB%E2+%EE+%F0%F3%F1%F1%=20
EA%EE%EC+%E8%E4%E5%E0%EB%E8%F1%F2%E5+%F0
%E5%F4%E5%F0%E0%F2%3C%2FA%3E%=20
0Ahttp%3A%2F%2Faydxjiwakd705.nm.ru%2F314.html%0A%5Burl%3Dhttp%3A%2F%2Fa
ydxjiwakd705.nm.ru%2F314. html%5D%F2%F0%E8%EB%EE%E3%E8%FF+%E3%EE%E
D%F7%=20=
E0%F0%EE%E2%E0+%EE%E1%F0%FB%E2+%EE+%F0%F
3%F1%F1%EA%EE%EC+%E8%E4%E5%E0%=20=
EB%E8%F1%F2%E5+%F0%E5%F4%E5%F0%E0%F2%5B%
2Furl%5D%0A%3CA+href%3Dhttp%3
A%2F%2Fsihocuax700.nightmail.ru%2F22.html%3E%F1%E8%EB%EE%E2%EE%E5+%F2%=20=
F0%EE%E5%E1%EE%F0%FC%E5%3C%2FA%3E%0Ahttp
%3A%2F%=20
2Fsihocuax700.nightmail.ru%2F22.html%0A%5Burl%3Dhttp%3A%2F%=20
2Fsihocuax700.nightmail.ru%2F22.h
tml%5D%F1%E8%EB%EE%E2%EE%E5+%F2%F0%EE%E5
%E1%EE%F0%FC%E5%5B%2Furl%5D%0A=20=
%3CA+href%3Dhttp%3A%2F%2Fzkqoiwfu1470.nightmail.ru%2F196.html%3E%EA%EE=20=
%F1%F2%FE%EC%FB+%E2%EE%F1%F2%EE%F7%ED%FB
%F5+%F2%E0%ED%F6%E5%E2%3C%2FA
%3E%0Ahttp%3A%2F%2Fzkqoiwfu1470.nightmail.ru%2F196.html%0A%5Burl%=20
3Dhttp%3A%2F%2Fzkqoiwfu1470.nightmail.ru%2F196.html%5D%EA%EE%F1%F2%FE%=20=
EC%FB+%E2%EE%F1%F2%EE%F7%ED%FB%F5+%F2%E0
%ED%F6%E5%E2%5B%2Furl%5D%0A%=20
3CA+hr
ef%3Dhttp%3A%2F%2Fqefvobslo989.nightmail.ru%2F6.html%3E%F1%EA%F0%E8%EF=20=
%F2+%F7%E0%F2%E0%3C%2FA%3E%0Ahttp%3A%2F%
2Fqefvobslo989.nightmail.ru%=20
2F6. html%0A%5Burl%3Dhttp%3A%2F%2Fqefvobslo98
9.nightmail.ru%2F6.html%5D%
F1%EA%F0%E8%EF%F2+%F7%E0%F2%E0%5B%2Furl%
5D%0A%3CA+href%3Dhttp%3A%2F%=20
2Ftpwhzcat346.nm.ru%2F200. html%3E%EE%F7%E8%F1%F2%EA%E0+%E2%EE%E4%F
B+%=20
E2+%E1%E5%EB%E3%EE%F0%EE%E4%E5+%E4%ED%E5
%F1%F2%F0%EE%E2%F1%EA%E5%3C%2FA%
3E%0Ahttp%3A%2F%2Ftpwhzcat346.nm.ru%2F200.html%0A%5Burl%3Dhttp%3A%2F%=20
2Ftpwhzcat346.nm.ru%2F200. html%5D%EE%F7%E8%F1%F2%EA%E0+%E2%EE%E4%F
B+%=20
E2+%E1%E5%EB%E3%EE%F0%EE%E4%E5+%E4%ED%E5
%F1%F2%F0%EE%E2%F1%EA%E5%5B%2Fu
rl%5D%0AGET /js/pngfix.js HTTP/1.0=
| |
| Brad Fitzpatrick 2007-06-19, 7:11 pm |
| We had this happen to us awhile back, but it was fixed in 1.51 it looks
like.
What version are you using?
On Wed, 30 May 2007, Andr=E9 Cruz wrote:
> Hello all.
>
> Ever since I enabled persistent connections to the backends I get
> strange requests in my apache error logs. I'll paste one in the end
> of the mail.
>
> The request seems to be part of another request that was split
> somehow as it doesn't contain the first part (GET, POST,
> whatever ...). This wouldn't concern me much, as the request seems
> like SPAM, if not for the last part of the request: GET /js/pngfix.js
> HTTP/1.0. It seems that this bogus request is messing up the next
> request in line as well...
>
> Just so you know this is a Livejournal installation and the request
> seems to try to leave a comment. I was expecting Perlbal to discard
> these invalid requests or at least separate them...
>
> Is my analysis wrong?
>
> Thanks,
> Andr=E9
>
> [Wed May 30 11:11:19 2007] [error] [client 10.135.64.111] Invalid
> method in request
> replyto=3D&parenttalkid=3D0&itemid=3D36185&journal=3Dasminhasbijuterias&c=
hrp1=3D36
> 185-67653-1178229600-WlQb7jSFB9foAIKwZSrC-ee52bf366bf
> 415ee4f0914bca253de5d&usertype=3Danonymous&guest_userpost=3D&guest_user_u=
rl=3D
> http%3A%2F%2Fxwgtkvyq.pochtamt.ru%
> 2F128.html&userpost=3D&password=3Duelpfcvylh&do_login=3D&captcha_chal=3Dc=
0%
> 3A1178229600%3A3049%3A900%3A3ccnHlD8
> cVFNEP59a64T%
> 3A05cfd4ae84bf57bbc0819da874594362&answer=3D&checkCommentOrto=3DVerificar
> +Ortografia&submitpost=3DPublicar&submitpreview=3DPr%26eacute%3B-
> visualizar& body=3D%3CA+href%3Dhttp%3A%2F%2Fvizthsbg
342.nightmail.ru%
> 2F172. html%3E%EA%E0%F1%F1%EE%E2%FB%E9+%E0%EF%E
F%E0%F0%E0%F2+%F7%E5%EB%
> FF%E1%E8%ED%F1%EA+%EF%F0%EE%E4%E0%EC+%E1
+%F3%3C%2FA%3E%0Ahttp%3A%2F%
> 2Fvizthsbg342.nightmail.ru%2F172.html%0A%5Burl%3Dhttp%3A%2F%2Fvizthsbg3
> 42.nightmail.ru%2F172. html%5D%EA%E0%F1%F1%EE%E2%FB%E9+%E0%EF%E
F%E0%F0%
> E0%F2+%F7%E5%EB%FF%E1%E8%ED%F1%EA+%EF%F0
%EE%E4%E0%EC+%E1+%F3%5B%2Furl%
> 5D%0A%3CA+href%3Dhttp%3A%2F%2Flgykbcpb18
15.nightmail.ru%2F259.html%3E
> %EC%E8%F2%FF%E5%E2+%EA%F0%E5%EF%E8%F2%E5
%F1%FC+%EB%FE%E4%E8+%F1%EA%EE%
> F0%EE+%EB%E5%F2%EE%3C%2FA%3E%0Ahttp%3A%2
F%2Flgykbcpb1815.nightmail.ru%
> 2F259. html%0A%5Burl%3Dhttp%3A%2F%2Flgykbcpb181
5.nightmail.ru%2F259.ht
> ml%5D%EC%E8%F2%FF%E5%E2+%EA%F0%E5%EF%E8%
F2%E5%F1%FC+%EB%FE%E4%E8+%F1%
> EA%EE%F0%EE+%EB%E5%F2%EE%5B%2Furl%5D%0A%
3CA+href%3Dhttp%3A%2F%
> 2Fotisalrssj.krovatka.su%2F48. html%3E%F1%EA%EB%E0%E4+%EE%EF%F2%3C%2FA%
> 3E%0Ahtt
> p%3A%2F%2Fotisalrssj.krovatka.su%2F48.html%0A%5Burl%3Dhttp%3A%2F%
> 2Fotisalrssj.krovatka.su%2F48.html%5D%F1%EA%EB%E0%E4+%EE%EF%F2%5B%
> 2Furl%5D%0A%3CA+href%3Dhttp%3A%2F%2Faumq
mvuo.front.ru%2F198.html%3E%EA
> %E0%F0%F
> 2%E0+%FD%EA%EE%EB%EE%E3%E8%F7%E5%F1%EA%E
8+%ED%E5%E1%EB%E0%E3%EE%EF%F0%
> E8%FF%F2%ED%FB%F5+%EC%E5%F1%F2+%E2+%F1%E
0%ED%EA%F2-%EF%E5%F2%F0%E1%F3%
> F0%E3%E5%3C%2FA%3E%0Ahttp%3A%2F%2Faumqmv
uo.front.ru%2F198.html%0A%5Bu
> rl%3Dhttp%3A%2F%2Faumqmvuo.front.ru%2F198.html%5D%EA%E0%F0%F2%E0+%FD%
> EA%EE%EB%EE%E3%E8%F7%E5%F1%EA%E8+%ED%E5%
E1%EB%E0%E3%EE%EF%F0%E8%FF%F2%
> ED%FB%F5+%EC%E5%F1%F2+%E2+%F1%E0%ED%EA%F
2-%EF%E5%F2%F0%E1%F3%F0%E3%E5%
> 5B%2Furl%5D%0A%3CA+href%3Dhttp%3A%2F%2Fk
mtyqtotn.rbcmail.ru%2F69.html%
> 3E%F8%E0%E1%EB%EE%ED%FB+%EE%F4%E8%F6%E8%
E0%EB%FC%ED%FB%F5+%EF%E8%F1%
> E5%EC%3C%2FA%3E%0Ahttp%3A%2F%2Fkmtyqtotn
.rbcmail.ru%2F69.html%0A%5Burl%
> 3Dhttp%3A%2F%2Fkmtyqtotn.rbcmail.ru%2F69.html%5D%F8%E0%E1%EB%EE%ED%FB+
> %EE%F4%E8%F6%E8%E0%EB%FC%ED%FB%F5+%EF%E8
%F1%E5%EC%5B%2Furl%5D%0A%3CA
> +href%3Dhttp%3A%2F%2Faydxjiwakd705.nm.ru%2F314.html%3E%F2%F0%E8%EB%EE%E
> 3%E8%FF+%E3%EE%ED%F7%E0%F0%EE%E2%E0+%EE%
E1%F0%FB%E2+%EE+%F0%F3%F1%F1%
> EA%EE%EC+%E8%E4%E5%E0%EB%E8%F1%F2%E5+%F0
%E5%F4%E5%F0%E0%F2%3C%2FA%3E%
> 0Ahttp%3A%2F%2Faydxjiwakd705.nm.ru%2F314.html%0A%5Burl%3Dhttp%3A%2F%2Fa
> ydxjiwakd705.nm.ru%2F314. html%5D%F2%F0%E8%EB%EE%E3%E8%FF+%E3%EE%E
D%F7%
> E0%F0%EE%E2%E0+%EE%E1%F0%FB%E2+%EE+%F0%F
3%F1%F1%EA%EE%EC+%E8%E4%E5%E0%
> EB%E8%F1%F2%E5+%F0%E5%F4%E5%F0%E0%F2%5B%
2Furl%5D%0A%3CA+href%3Dhttp%3
> A%2F%2Fsihocuax700.nightmail.ru%2F22.html%3E%F1%E8%EB%EE%E2%EE%E5+%F2%
> F0%EE%E5%E1%EE%F0%FC%E5%3C%2FA%3E%0Ahttp
%3A%2F%
> 2Fsihocuax700.nightmail.ru%2F22.html%0A%5Burl%3Dhttp%3A%2F%
> 2Fsihocuax700.nightmail.ru%2F22.h
> tml%5D%F1%E8%EB%EE%E2%EE%E5+%F2%F0%EE%E5
%E1%EE%F0%FC%E5%5B%2Furl%5D%0A
> %3CA+href%3Dhttp%3A%2F%2Fzkqoiwfu1470.nightmail.ru%2F196.html%3E%EA%EE
> %F1%F2%FE%EC%FB+%E2%EE%F1%F2%EE%F7%ED%FB
%F5+%F2%E0%ED%F6%E5%E2%3C%2FA
> %3E%0Ahttp%3A%2F%2Fzkqoiwfu1470.nightmail.ru%2F196.html%0A%5Burl%
> 3Dhttp%3A%2F%2Fzkqoiwfu1470.nightmail.ru%2F196.html%5D%EA%EE%F1%F2%FE%
> EC%FB+%E2%EE%F1%F2%EE%F7%ED%FB%F5+%F2%E0
%ED%F6%E5%E2%5B%2Furl%5D%0A%
> 3CA+hr
> ef%3Dhttp%3A%2F%2Fqefvobslo989.nightmail.ru%2F6.html%3E%F1%EA%F0%E8%EF
> %F2+%F7%E0%F2%E0%3C%2FA%3E%0Ahttp%3A%2F%
2Fqefvobslo989.nightmail.ru%
> 2F6. html%0A%5Burl%3Dhttp%3A%2F%2Fqefvobslo98
9.nightmail.ru%2F6.html%5D%
> F1%EA%F0%E8%EF%F2+%F7%E0%F2%E0%5B%2Furl%
5D%0A%3CA+href%3Dhttp%3A%2F%
> 2Ftpwhzcat346.nm.ru%2F200. html%3E%EE%F7%E8%F1%F2%EA%E0+%E2%EE%E4%F
B+%
> E2+%E1%E5%EB%E3%EE%F0%EE%E4%E5+%E4%ED%E5
%F1%F2%F0%EE%E2%F1%EA%E5%3C%2FA%
> 3E%0Ahttp%3A%2F%2Ftpwhzcat346.nm.ru%2F200.html%0A%5Burl%3Dhttp%3A%2F%
> 2Ftpwhzcat346.nm.ru%2F200. html%5D%EE%F7%E8%F1%F2%EA%E0+%E2%EE%E4%F
B+%
> E2+%E1%E5%EB%E3%EE%F0%EE%E4%E5+%E4%ED%E5
%F1%F2%F0%EE%E2%F1%EA%E5%5B%2Fu
> rl%5D%0AGET /js/pngfix.js HTTP/1.0
>
| |
| André Cruz 2007-06-20, 7:11 am |
| 1.56
We disabled Keepalive on the apache backends and the errors went away =20=
so it definitely has something to do with it.
Andr=E9
On 2007/06/19, at 19:46, Brad Fitzpatrick wrote:
[vbcol=seagreen]
> We had this happen to us awhile back, but it was fixed in 1.51 it =20
> looks
> like.
>
> What version are you using?
>
>
> On Wed, 30 May 2007, Andr=E9 Cruz wrote:
>
&chrp1=20[vbcol=seagreen]
_u=20[vbcol=seagreen]
c0%[vbcol=seagreen]
ar[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
[vbcol=seagreen]
|
|
|
|
|