Jump to content

Could this be an indication of someone attempting to hack into my Emby


Go to solution Solved by Luke,

Recommended Posts

Guest Brett_Dean
Posted (edited)

I'm concerned about this.

Yesterday, someone stole 1 terabyte of traffic from my Emby server. The log file didn't show anything, or at least I couldn't find anything relevant.

```


2023-03-25 10:42:56.334 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/linkPF
2023-03-25 10:42:56.438 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/notice. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:42:56.438 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/notice
2023-03-25 10:43:00.956 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/wap/forward. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:00.956 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/wap/forward
2023-03-25 10:43:04.596 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/im/conf. UserAgent: okhttp/3.3.1
2023-03-25 10:43:04.596 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/im/conf
2023-03-25 10:43:05.728 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/app-info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:05.728 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/app-info
2023-03-25 10:43:09.311 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/kkrp/site/info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:09.311 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/kkrp/site/info
2023-03-25 10:43:10.592 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/v1/app-info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:10.592 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/v1/app-info
2023-03-25 10:43:12.811 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/biz/server/config. UserAgent: okhttp/3.14.9
2023-03-25 10:43:12.811 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/biz/server/config
2023-03-25 10:43:12.843 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/link/platform. UserAgent: okhttp/3.3.1
2023-03-25 10:43:12.843 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/link/platform
2023-03-25 10:43:12.958 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/link/platform. UserAgent: xx032_bo9vs83_2a
2023-03-25 10:43:12.958 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/link/platform
2023-03-25 10:43:17.809 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/user/getAllNicknames. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:17.809 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/user/getAllNicknames
2023-03-25 10:43:17.864 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/other/appSetting. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:17.864 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/other/appSetting
2023-03-25 10:43:18.067 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/user/mobilelogin. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:18.067 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/user/mobilelogin
2023-03-25 10:43:18.161 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/km.asmx/getPlatParam. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:18.161 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/km.asmx/getPlatParam
2023-03-25 10:43:19.654 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile. UserAgent: okhttp/3.14.9
2023-03-25 10:43:19.655 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile
2023-03-25 10:43:20.017 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile. UserAgent: okhttp/3.14.9
2023-03-25 10:43:20.017 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile
2023-03-25 10:43:26.771 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/config/getwebsitename. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:26.771 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/config/getwebsitename
2023-03-25 10:43:28.316 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/index.php/User/sendsmscode. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:28.316 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/index.php/User/sendsmscode
2023-03-25 10:43:30.514 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/system/system/config/get. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:30.514 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/system/system/config/get
2023-03-25 10:43:32.776 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/melody/api/v1/pageconfig/list. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:32.776 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/melody/api/v1/pageconfig/list
2023-03-25 10:43:34.285 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/getUserCertificationStatus. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:34.286 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 1ms. http://‌‍‍emby.mydomain.com‌/api/getUserCertificationStatus
2023-03-25 10:43:34.300 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/GetConfigByKeys?keys=of_we. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:34.300 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/GetConfigByKeys?keys=of_we
2023-03-25 10:43:41.605 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/system/systemConfigs/getCustomerServiceLink. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:41.606 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/system/systemConfigs/getCustomerServiceLink
2023-03-25 10:43:42.647 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/site/api/v1/site/vipExclusiveDomain/getGuestDomain. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:43:42.647 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/site/api/v1/site/vipExclusiveDomain/getGuestDomain
2023-03-25 10:44:32.090 Info HttpClient: GET https://api.github.com/repos/MediaBrowser/Emby.Releases/releases
2023-03-25 10:44:32.234 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile. UserAgent: okhttp/3.14.9
2023-03-25 10:44:32.234 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile
2023-03-25 10:44:37.443 Info HttpClient: GET https://www.mb3admin.com/admin/service/EmbyPackages.json
2023-03-25 10:44:44.815 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/getUserCertificationStatus. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:44:44.815 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/getUserCertificationStatus
2023-03-25 10:45:22.853 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/v1/app-info. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:22.853 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/v1/app-info
2023-03-25 10:45:23.452 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/biz/server/config. UserAgent: okhttp/3.14.9
2023-03-25 10:45:23.452 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/biz/server/config
2023-03-25 10:45:25.391 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/other/appSetting. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:25.391 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/other/appSetting
2023-03-25 10:45:25.557 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/km.asmx/getPlatParam. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:25.557 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/km.asmx/getPlatParam
2023-03-25 10:45:26.060 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile. UserAgent: okhttp/3.14.9
2023-03-25 10:45:26.060 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/user/ismustmobile
2023-03-25 10:45:27.987 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/config/getwebsitename. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:27.987 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/config/getwebsitename
2023-03-25 10:45:29.652 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/index.php/User/sendsmscode. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:29.652 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/index.php/User/sendsmscode
2023-03-25 10:45:31.543 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/system/systemConfigs/getCustomerServiceLink. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:31.543 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/system/systemConfigs/getCustomerServiceLink
2023-03-25 10:45:37.602 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/im/conf. UserAgent: okhttp/3.3.1
2023-03-25 10:45:37.602 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/im/conf
2023-03-25 10:45:41.650 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/other/appSetting. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:41.650 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/other/appSetting
2023-03-25 10:45:41.718 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/user/mobilelogin. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:41.718 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/user/mobilelogin
2023-03-25 10:45:47.250 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/index.php/User/sendsmscode. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:47.250 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/index.php/User/sendsmscode
2023-03-25 10:45:47.672 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/system/system/config/get. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:47.672 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/system/system/config/get
2023-03-25 10:45:47.971 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/melody/api/v1/pageconfig/list. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:47.971 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/melody/api/v1/pageconfig/list
2023-03-25 10:45:48.308 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/GetConfigByKeys?keys=of_we. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:48.308 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/GetConfigByKeys?keys=of_we
2023-03-25 10:45:49.800 Info Server: http/1.1 POST http://‌‍‍emby.mydomain.com‌/api/system/systemConfigs/getCustomerServiceLink. UserAgent: Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.0
2023-03-25 10:45:49.800 Info Server: http/1.1 Response 404 to ‌‍‍152.32.254.131‌. Time: 0ms. http://‌‍‍emby.mydomain.com‌/api/system/systemConfigs/getCustomerServiceLink
```

 
Edited by Brett_Dean
Guest Brett_Dean
Posted

I hope Emby can prioritize network security concerns.

  • Solution
Posted

Hi, this isn't any kind of security breach. This is someone sending random requests to your server. 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...