• post 302 148 in my log

    From BILLY SCHWARZ@1:124/5013 to All on Thu Jan 31 19:17:19 2019
    Date: Wed, 13 Jun 2007 09:19:22 -0400
    From: BILLY SCHWARZ
    To: HECTOR SANTOS
    Subject: post 302 148 in my log
    Newsgroups: winserver.public.gamma.testing
    Message-ID: <1181740762.40.0@winserver.com>
    X-WcMsg-Attr: Rcvd
    X-Mailer: Wildcat! Interactive Net Server v7.0.454.5
    Lines: 23

    Dear Hector

    I mailed you a log a while back on the post 302 148 in my logs.

    it went away after i blocked the ip number on my dns.

    It is back.
    I know that it is a reroute command in the acpachie server.

    what does it mean for the wildcat.

    post / http / 1.1 "302 148 https://www.paypal.com/cgi-bin / webscr"

    i know that the paypal is one we use in our e-commerce.

    It looks like they are trying to reroute the paypal cgi-bin.

    If they have embeded scripts into my wildcat could you tell me where it
    might be.

    thank you
    Billy Schwarz
    sysop@hightecporductions.com
    --- Platinum Xpress/Win/WINServer v3.1
    * Origin: Prison Board BBS Mesquite Tx //telnet.RDFIG.NET www. (1:124/5013)
  • From HECTOR SANTOS@1:124/5013 to All on Thu Jan 31 19:17:19 2019
    Date: Wed, 13 Jun 2007 09:40:07 -0400
    From: HECTOR SANTOS
    To: BILLY SCHWARZ
    Subject: RE: post 302 148 in my log
    Newsgroups: winserver.public.gamma.testing
    Message-ID: <1181742007.40.1181740762@winserver.com>
    References: <1181740762.40.0@winserver.com>
    X-WcMsg-Attr: Rcvd
    X-Mailer: Wildcat! Interactive Net Server v7.0.454.5
    Lines: 43

    On 2007-06-13 9:19 AM, BILLY SCHWARZ wrote to HECTOR SANTOS:

    Dear Hector

    I mailed you a log a while back on the post 302 148 in my logs.

    it went away after i blocked the ip number on my dns.

    It is back.
    I know that it is a reroute command in the acpachie server.

    what does it mean for the wildcat.

    post / http / 1.1 "302 148 https://www.paypal.com/cgi-bin / webscr"

    i know that the paypal is one we use in our e-commerce.

    It looks like they are trying to reroute the paypal cgi-bin.

    If they have embeded scripts into my wildcat could you tell me where it might be.

    Well, where did you get that log? In WCHTTP*.LOG?

    It doesn't look right, looks like it has extra spaces.

    Anyway

    302 means the url "/" was called from https://www.paypal.com/cgi-bin.

    It might be harmless.

    I don't see the problem.

    Look at the next line in the log, it probably will show a GET to your /public/default.htm page.

    I don't see why you are concern here. Wildcat! is not allowing anything
    here to happen.

    --
    HLS

    --- Platinum Xpress/Win/WINServer v3.1
    * Origin: Prison Board BBS Mesquite Tx //telnet.RDFIG.NET www. (1:124/5013)
  • From BILLY SCHWARZ@1:124/5013 to All on Thu Jan 31 19:17:19 2019
    Date: Wed, 13 Jun 2007 17:29:38 -0400
    From: BILLY SCHWARZ
    To: HECTOR SANTOS
    Subject: RE: post 302 148 in my log
    Newsgroups: winserver.public.gamma.testing
    Message-ID: <1181770178.40.1181742007@winserver.com>
    References: <1181742007.40.1181740762@winserver.com>
    X-WcMsg-Attr: Rcvd
    X-Mailer: Wildcat! Interactive Net Server v7.0.454.5
    Lines: 55

    On 2007-06-13 9:40 AM, HECTOR SANTOS wrote to BILLY SCHWARZ:

    On 2007-06-13 9:19 AM, BILLY SCHWARZ wrote to HECTOR SANTOS:

    Dear Hector

    I mailed you a log a while back on the post 302 148 in my logs.

    it went away after i blocked the ip number on my dns.

    It is back.
    I know that it is a reroute command in the acpachie server.

    what does it mean for the wildcat.

    post / http / 1.1 "302 148 https://www.paypal.com/cgi-bin / webscr"

    i know that the paypal is one we use in our e-commerce.

    It looks like they are trying to reroute the paypal cgi-bin.

    If they have embeded scripts into my wildcat could you tell me where it might be.

    Well, where did you get that log? In WCHTTP*.LOG?

    It doesn't look right, looks like it has extra spaces.

    Anyway

    302 means the url "/" was called from https://www.paypal.com/cgi-bin.

    It might be harmless.

    I don't see the problem.

    Look at the next line in the log, it probably will show a GET to your /public/default.htm page.

    I don't see why you are concern here. Wildcat! is not allowing anything here to happen.

    --
    HLS

    I am concerned because the ip number associated comes from China and the
    other comes form Ethiopia.

    There is no get to my /public/default.htm page.

    If you say that it is harmless ok.

    this is the first time in 10 years I have seen this log

    Billy Schwarz
    --- Platinum Xpress/Win/WINServer v3.1
    * Origin: Prison Board BBS Mesquite Tx //telnet.RDFIG.NET www. (1:124/5013)