Server Reports "An existing connection was forcibly closed by the remote host - IOException (...)"

visiondrive7 years ago

Submitted for reference only as I already found related content on the forum.

Essentially a device (non tracker based) is attempting to gain access on the open port.

The IP in question is already blacklisted - in my case I have firewall blocked it. 199.68.196.122

2017-09-21 19:07:19 DEBUG: [B93BC1B1: 5055 < 199.68.196.122] HEX: 474554202f2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c2e2e2e2e5c77696e646f77735c77696e2e696e6920485454502f312e310d0a486f73743a207361752d63353530362d6f722e736572766572636f6e74726f6c2e636f6d2e61753a353035350d0a4163636570742d436861727365743a2069736f2d383835392d312c7574662d383b713d302e392c2a3b713d302e310d0a4163636570742d4c616e67756167653a20656e0d0a436f6e6e656374696f6e3a20436c6f73650d0a557365722d4167656e743a204d6f7a696c6c612f342e302028636f6d70617469626c653b204d53494520382e303b2057696e646f7773204e5420352e313b2054726964656e742f342e30290d0a507261676d613a206e6f2d63616368650d0a4163636570743a20696d6167652f6769662c20696d6167652f782d786269746d61702c20696d6167652f6a7065672c20696d6167652f706a7065672c20696d6167652f706e672c202a2f2a0d0a0d0a
2017-09-21 19:07:19 DEBUG: [B93BC1B1: 5055 > 199.68.196.122] HEX: 485454502f312e31203430302042616420526571756573740d0a436f6e74656e742d4c656e6774683a20300d0a0d0a

2017-09-21 19:07:20  WARN: [B93BC1B1] error - An existing connection was forcibly closed by the remote host - IOException (...)

2017-09-21 19:07:20  INFO: [B93BC1B1] disconnected
2017-09-21 19:07:20  INFO: [5653FE64] connected
visiondrive7 years ago

Decode of Hex is

GET /....\....\....\....\....\....\....\....\....\windows\win.ini HTTP/1.1
Host: sau-c5506-or.servercontrol.com.au:5055
Accept-Charset: iso-8859-1,utf-8;q=0.9,*;q=0.1
Accept-Language: en
Connection: Close
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, image/png, */*
Anton Tananaev7 years ago

If firewall blocked it how did it get to Traccar?

visiondrive7 years ago

IP was blocked only after detection of attempted access via log file review.

Anton Tananaev7 years ago

OK, so what is your question?

visiondrive7 years ago

Well not a question rather information for others to review. In searching the forums for this message I found some matches but nothing in detail so made the post to inform others when the topic is searched for by others in the future.

visiondrive7 years ago

My two lines of initial comment already reflect the post not being a question:

"Submitted for reference only as I already found related content on the forum.

Essentially a device (non tracker based) is attempting to gain access on the open port."