Server Reports "An existing connection was forcibly closed by the remote host - IOException (...)"

visiondrive 8 years ago

Submitted for reference only as I already found related content on the forum.

Essentially a device (non tracker based) is attempting to gain access on the open port.

The IP in question is already blacklisted - in my case I have firewall blocked it. 199.68.196.122

2017-09-21 19:07:19 DEBUG: [B93BC1B1: 5055 < 199.68.196.122] HEX: 474554202f2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c77696e646f77735c77696e2e696e6920485454502f312e310d0a486f73743a207361752d63353530362d6f722e736572766572636f6e74726f6c2e636f6d2e61753a353035350d0a4163636570742d436861727365743a2069736f2d383835392d312c7574662d383b713d302e392c2a3b713d302e310d0a4163636570742d4c616e67756167653a20656e0d0a436f6e6e656374696f6e3a20436c6f73650d0a557365722d4167656e743a204d6f7a696c6c612f342e302028636f6d70617469626c653b204d53494520382e303b2057696e646f7773204e5420352e313b2054726964656e742f342e30290d0a507261676d613a206e6f2d63616368650d0a4163636570743a20696d6167652f6769662c20696d6167652f782d786269746d61702c20696d6167652f6a7065672c20696d6167652f706a7065672c20696d6167652f706e672c202a2f2a0d0a0d0a
2017-09-21 19:07:19 DEBUG: [B93BC1B1: 5055 > 199.68.196.122] HEX: 485454502f312e31203430302042616420526571756573740d0a436f6e74656e742d4c656e6774683a20300d0a0d0a

2017-09-21 19:07:20  WARN: [B93BC1B1] error - An existing connection was forcibly closed by the remote host - IOException (...)

2017-09-21 19:07:20  INFO: [B93BC1B1] disconnected
2017-09-21 19:07:20  INFO: [5653FE64] connected
visiondrive 8 years ago

Decode of Hex is

GET /....\....\....\....\....\....\....\....\....\windows\win.ini HTTP/1.1
Host: sau-c5506-or.servercontrol.com.au:5055
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
Anton Tananaev 8 years ago

If firewall blocked it how did it get to Traccar?

visiondrive 8 years ago

IP was blocked only after detection of attempted access via log file review.

Anton Tananaev 8 years ago

OK, so what is your question?

visiondrive 8 years ago

Well not a question rather information for others to review. In searching the forums for this message I found some matches but nothing in detail so made the post to inform others when the topic is searched for by others in the future.

visiondrive 8 years ago

My two lines of initial comment already reflect the post not being a question:

"Submitted for reference only as I already found related content on the forum.

Essentially a device (non tracker based) is attempting to gain access on the open port."