Guest Brett_Dean Posted March 25, 2023 Posted March 25, 2023 (edited) I'm concerned about this. Yesterday, someone stole 1 terabyte of traffic from my Emby server. The log file didn't show anything, or at least I couldn't find anything relevant. ``` 2023-03-25 10:42:56.334 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/linkPF 2023-03-25 10:42:56.438 Info Server: http/1.1 POST http://emby.mydomain.com/api/notice. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:42:56.438 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/notice 2023-03-25 10:43:00.956 Info Server: http/1.1 POST http://emby.mydomain.com/wap/forward. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:00.956 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/wap/forward 2023-03-25 10:43:04.596 Info Server: http/1.1 POST http://emby.mydomain.com/api/im/conf. UserAgent: okhttp/3.3.1 2023-03-25 10:43:04.596 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/im/conf 2023-03-25 10:43:05.728 Info Server: http/1.1 POST http://emby.mydomain.com/api/app-info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:05.728 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/app-info 2023-03-25 10:43:09.311 Info Server: http/1.1 POST http://emby.mydomain.com/kkrp/site/info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:09.311 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/kkrp/site/info 2023-03-25 10:43:10.592 Info Server: http/1.1 POST http://emby.mydomain.com/api/v1/app-info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:10.592 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/v1/app-info 2023-03-25 10:43:12.811 Info Server: http/1.1 POST http://emby.mydomain.com/biz/server/config. UserAgent: okhttp/3.14.9 2023-03-25 10:43:12.811 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/biz/server/config 2023-03-25 10:43:12.843 Info Server: http/1.1 POST http://emby.mydomain.com/api/link/platform. UserAgent: okhttp/3.3.1 2023-03-25 10:43:12.843 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/link/platform 2023-03-25 10:43:12.958 Info Server: http/1.1 POST http://emby.mydomain.com/api/link/platform. UserAgent: xx032_bo9vs83_2a 2023-03-25 10:43:12.958 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/link/platform 2023-03-25 10:43:17.809 Info Server: http/1.1 POST http://emby.mydomain.com/user/getAllNicknames. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:17.809 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/user/getAllNicknames 2023-03-25 10:43:17.864 Info Server: http/1.1 POST http://emby.mydomain.com/api/other/appSetting. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:17.864 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/other/appSetting 2023-03-25 10:43:18.067 Info Server: http/1.1 POST http://emby.mydomain.com/api/user/mobilelogin. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:18.067 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/user/mobilelogin 2023-03-25 10:43:18.161 Info Server: http/1.1 POST http://emby.mydomain.com/km.asmx/getPlatParam. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:18.161 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/km.asmx/getPlatParam 2023-03-25 10:43:19.654 Info Server: http/1.1 POST http://emby.mydomain.com/api/user/ismustmobile. UserAgent: okhttp/3.14.9 2023-03-25 10:43:19.655 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/user/ismustmobile 2023-03-25 10:43:20.017 Info Server: http/1.1 POST http://emby.mydomain.com/api/user/ismustmobile. UserAgent: okhttp/3.14.9 2023-03-25 10:43:20.017 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/user/ismustmobile 2023-03-25 10:43:26.771 Info Server: http/1.1 POST http://emby.mydomain.com/api/config/getwebsitename. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:26.771 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/config/getwebsitename 2023-03-25 10:43:28.316 Info Server: http/1.1 POST http://emby.mydomain.com/index.php/User/sendsmscode. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:28.316 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/index.php/User/sendsmscode 2023-03-25 10:43:30.514 Info Server: http/1.1 POST http://emby.mydomain.com/api/system/system/config/get. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:30.514 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/system/system/config/get 2023-03-25 10:43:32.776 Info Server: http/1.1 POST http://emby.mydomain.com/melody/api/v1/pageconfig/list. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:32.776 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/melody/api/v1/pageconfig/list 2023-03-25 10:43:34.285 Info Server: http/1.1 POST http://emby.mydomain.com/api/getUserCertificationStatus. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:34.286 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 1ms. http://emby.mydomain.com/api/getUserCertificationStatus 2023-03-25 10:43:34.300 Info Server: http/1.1 POST http://emby.mydomain.com/api/GetConfigByKeys?keys=of_we. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:34.300 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/GetConfigByKeys?keys=of_we 2023-03-25 10:43:41.605 Info Server: http/1.1 POST http://emby.mydomain.com/api/system/systemConfigs/getCustomerServiceLink. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:41.606 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/system/systemConfigs/getCustomerServiceLink 2023-03-25 10:43:42.647 Info Server: http/1.1 POST http://emby.mydomain.com/site/api/v1/site/vipExclusiveDomain/getGuestDomain. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:43:42.647 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/site/api/v1/site/vipExclusiveDomain/getGuestDomain 2023-03-25 10:44:32.090 Info HttpClient: GET https://api.github.com/repos/MediaBrowser/Emby.Releases/releases 2023-03-25 10:44:32.234 Info Server: http/1.1 POST http://emby.mydomain.com/api/user/ismustmobile. UserAgent: okhttp/3.14.9 2023-03-25 10:44:32.234 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/user/ismustmobile 2023-03-25 10:44:37.443 Info HttpClient: GET https://www.mb3admin.com/admin/service/EmbyPackages.json 2023-03-25 10:44:44.815 Info Server: http/1.1 POST http://emby.mydomain.com/api/getUserCertificationStatus. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:44:44.815 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/getUserCertificationStatus 2023-03-25 10:45:22.853 Info Server: http/1.1 POST http://emby.mydomain.com/api/v1/app-info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:22.853 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/v1/app-info 2023-03-25 10:45:23.452 Info Server: http/1.1 POST http://emby.mydomain.com/biz/server/config. UserAgent: okhttp/3.14.9 2023-03-25 10:45:23.452 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/biz/server/config 2023-03-25 10:45:25.391 Info Server: http/1.1 POST http://emby.mydomain.com/api/other/appSetting. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:25.391 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/other/appSetting 2023-03-25 10:45:25.557 Info Server: http/1.1 POST http://emby.mydomain.com/km.asmx/getPlatParam. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:25.557 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/km.asmx/getPlatParam 2023-03-25 10:45:26.060 Info Server: http/1.1 POST http://emby.mydomain.com/api/user/ismustmobile. UserAgent: okhttp/3.14.9 2023-03-25 10:45:26.060 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/user/ismustmobile 2023-03-25 10:45:27.987 Info Server: http/1.1 POST http://emby.mydomain.com/api/config/getwebsitename. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:27.987 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/config/getwebsitename 2023-03-25 10:45:29.652 Info Server: http/1.1 POST http://emby.mydomain.com/index.php/User/sendsmscode. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:29.652 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/index.php/User/sendsmscode 2023-03-25 10:45:31.543 Info Server: http/1.1 POST http://emby.mydomain.com/api/system/systemConfigs/getCustomerServiceLink. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:31.543 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/system/systemConfigs/getCustomerServiceLink 2023-03-25 10:45:37.602 Info Server: http/1.1 POST http://emby.mydomain.com/api/im/conf. UserAgent: okhttp/3.3.1 2023-03-25 10:45:37.602 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/im/conf 2023-03-25 10:45:41.650 Info Server: http/1.1 POST http://emby.mydomain.com/api/other/appSetting. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:41.650 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/other/appSetting 2023-03-25 10:45:41.718 Info Server: http/1.1 POST http://emby.mydomain.com/api/user/mobilelogin. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:41.718 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/user/mobilelogin 2023-03-25 10:45:47.250 Info Server: http/1.1 POST http://emby.mydomain.com/index.php/User/sendsmscode. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:47.250 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/index.php/User/sendsmscode 2023-03-25 10:45:47.672 Info Server: http/1.1 POST http://emby.mydomain.com/api/system/system/config/get. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:47.672 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/system/system/config/get 2023-03-25 10:45:47.971 Info Server: http/1.1 POST http://emby.mydomain.com/melody/api/v1/pageconfig/list. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:47.971 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/melody/api/v1/pageconfig/list 2023-03-25 10:45:48.308 Info Server: http/1.1 POST http://emby.mydomain.com/api/GetConfigByKeys?keys=of_we. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:48.308 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/GetConfigByKeys?keys=of_we 2023-03-25 10:45:49.800 Info Server: http/1.1 POST http://emby.mydomain.com/api/system/systemConfigs/getCustomerServiceLink. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0 2023-03-25 10:45:49.800 Info Server: http/1.1 Response 404 to 152.32.254.131. Time: 0ms. http://emby.mydomain.com/api/system/systemConfigs/getCustomerServiceLink ``` Edited March 25, 2023 by Brett_Dean
Guest Brett_Dean Posted March 25, 2023 Posted March 25, 2023 I hope Emby can prioritize network security concerns.
Solution Luke 42078 Posted March 25, 2023 Solution Posted March 25, 2023 Hi, this isn't any kind of security breach. This is someone sending random requests to your server.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now