首页 > 解决方案 > Apache - 原始访问日志:同时来自 2 个不同 IP 的相同流量

问题描述

我只是查看我网站的原始访问日志,然后我看到了这个序列。问题(或我担心)是第一行显示了在完全相同的时间但来自 2 个不同 IP 的秘密和唯一令牌(发送到用户的电子邮件)的使用。我的问题是:以下行为的合法性如何?是关于攻击并且用户流量被黑客复制了吗?或者是什么?普通用户能有这样的流量吗?

10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /create_account.php?token=thisisaverycomplicatedtoken HTTP/1.1" 200 1820 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:16:59 +0100] "GET /create_account.php?token=thisisaverycomplicatedtoken HTTP/1.1" 200 1820 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /common/style.css HTTP/1.1" 200 7257 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:16:59 +0100] "GET /common/common.js HTTP/1.1" 200 9636 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /root/root.css HTTP/1.1" 200 533 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /common/themes/test.css HTTP/1.1" 200 4653 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /common/themes/good.css HTTP/1.1" 200 13054 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /root/header.js HTTP/1.1" 200 235 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:16:59 +0100] "GET /root/root.css HTTP/1.1" 200 533 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:16:59 +0100] "GET /common/themes/test.css HTTP/1.1" 200 4653 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:16:59 +0100] "GET /common/common.js HTTP/1.1" 200 9636 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:16:59 +0100] "GET /common/themes/good.css HTTP/1.1" 200 13054 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:00 +0100] "GET /common/style.css HTTP/1.1" 200 7257 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:00 +0100] "GET /root/header.js HTTP/1.1" 200 235 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:17:00 +0100] "GET /root/account.js HTTP/1.1" 200 1120 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:00 +0100] "GET /root/account.js HTTP/1.1" 200 1120 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:01 +0100] "GET /img/background.jpg HTTP/1.1" 200 201824 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:17:01 +0100] "GET /img/background.jpg HTTP/1.1" 200 201824 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:01 +0100] "GET /common/themes/loading.gif HTTP/1.1" 200 6242 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:17:01 +0100] "GET /img/wait.gif HTTP/1.1" 200 97654 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:17:01 +0100] "GET /common/themes/loading.gif HTTP/1.1" 200 6242 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:01 +0100] "GET /img/wait.gif HTTP/1.1" 200 97654 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:17:01 +0100] "GET /sounds/error.mp3 HTTP/1.1" 206 6572 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:01 +0100] "GET /sounds/error.mp3 HTTP/1.1" 206 6572 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
10.20.30.40 - - [14/Oct/2021:06:17:02 +0100] "GET /sounds/clic.mp3 HTTP/1.1" 206 2683 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"
90.80.70.60 - - [14/Oct/2021:06:17:02 +0100] "GET /sounds/clic.mp3 HTTP/1.1" 206 2683 "https://example.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36"

标签: apachewebsecurity

解决方案


推荐阅读