Re: Apache Log question

by "Harold A. Driscoll" <harold(at)driscoll.chi.il.us>

 Date:  Fri, 03 Dec 1999 10:18:04 -0600
 To:  Rich Bowen <rbowen(at)rcbowen.com>
 Cc:  Bob Minnick <bobmin(at)nidlink.com>, hwg-servers(at)hwg.org
 References:  nidlink
  todo: View Thread, Original
At 09:28 03-12-99 , Rich Bowen wrote:
>Bob Minnick wrote:
>>  This entry;
>> 
>> cf1.texas.rr.com - - [03/Dec/1999:03:15:34 -0500] "GET
>> /bc/images/IMG00001.GIF HTTP/1.0" 200 7039 "-" "Mozilla/3.01 (compatib
>> le;)"
>> 
>>  The image IMG0001.GIF is one of the images we suspect someone of
>> "borrowing" and this is the entire entry for this particular access. I hope
>> you'll note this is an improper log entry, no referrer is listed. And in
fact,
>> the origin point, cf1.texas.rr.com seems to be nonexistant as well.

Nothing is incomplete here... Apache is reporting what is provided... and
what is provided is quite legitimate.
 
>>  I am curious as to why an incomplete entry exists in the apache logs, and
>> if there is any way of tracing down this particular entry to find the
correct
>> point. I will also point out that in regard to the images in question, this
>> entry is the ONLY log entry which does not refer back to our calling html.

Your point being?
 
>A log entry with no referer simply means that the image was fetched by
>someone (or a bot) fetching a URL directly. For example, typeing in the
>address directly. Or a bot that is simply not configured to send the
>REFERER information, such as Perl/LWP or some other program.

C'mon, folks, before getting your fur in a dander, perhaps a perusal of the
HTTP 1.1 (and for that matter 1.0) specification document is in order.

If you refer to the section presenting the Referer: [sic] HTTP header,
you'll find that it quite explicitly states not only that the header is
optional, but recommends that browser vendors provide the capability to
respect user privacy and omit its presentation. Sadly, most browsers (IMHO
irresponsibly) fail to honor that recommendation.

>Your first response should be to either remove/rename the image, or,
>better yet, replace it with a multi-megabyte full color picture of, say,
>your goldfish. That should make them stop real quick.

Rather, determine if in fact there is a pattern of abuse. At best you've
only a suggestion that it might be happening, nothing more.

>Secondly, you should contact webmaster(at)rr.com and inform him/her of this
>activity, and put in a few gentle reminders about international
>copyright law. Might not apply, but usually gets something done. rr.com
>is an ISP, and so cfl.texas.rr.com is probably a proxy or dialup host
>that is behind their firewall, and hence unreachable to you. This does
>not mean that the host does not exist, it's just invisible to you.

If you don't have some evidence of misconduct, you're wasting everybody's
time, and at best exposing yourself to legal action for defamation of
character or worse.

Omission of the Referer [sic] header is a worst an expression that such
information is none of your bleeping business. You've the option to decline
to provide the file... but will likely find that you'll preclude very
legitimate access to your site by doing so.

It is easy to come up with other scenarios... an email URL from a friend
(look at this nifty photo)... that are certainly legal and quite possibly
honorable as well.

>There's a good chance that the ISP will just handle this for you, and
>this behavior will stop. If that does not happen, Apache makes it very
>easy for you to deny requests from a particular host. In the affected
>directlry, put a .htaccess file containing:

Again, what behavior?

>This will solve the problem immediately, as that host will be unable to
>get these files no matter what tricks they employ.

Again, what problem?

Keep in mind that the very same mechanism we are discussing is likely used
extensively to spy on the Web browsing practices of millions of Web users.
As the authors of the HTTP specification understood well, this is far from
a trivial issue.

Safe computing,  /Harold

ps. No doubt there are government agents who'd like to arrest everybody
they find who has been passed counterfeit currency, that being perhaps
easier to find than the ones who actually make it. And that without not
even knowing that the currency in fact was counterfeit. Threats against
someone who at worst would seem to have visited a site that perhaps
purloined the file in question would seem to me to be kindred in spirit.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Harold A. Driscoll                 mailto:Harold(at)Driscoll.Chi.IL.US
#include <std/disclaimer>                 http://Driscoll.Chi.IL.US

HWG: hwg-servers mailing list archives, maintained by Webmasters @ IWA

This page is part of a preserved archive of archives.hwg.org. The site is no longer active and its content is not maintained. For enquiries about this archive, write to archive(at)iwanet.org.