We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21417
    • 486 Posts
    Hello,

    My clients website received a whole heap of these kind of errors on Sunday...

    « MODX Parse Error »
    MODX encountered the following error while attempting to parse the requested resource:
    « PHP Parse Error »
    PHP error debug
    Error : Unknown: The session id is too long or contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,'
    ErrorType[num] : 	WARNING[2]
    File : 	Unknown
    Line : 	0
    Basic info
    REQUEST_URI : 	http://DOMAIN.COM.AU/SECTION/SUBSECTION/reviews
    Resource : 	[1250]Reviews of apps
    Referer : 	
    User Agent : 	Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
    IP : 	81.161.59.17
    Benchmarks
    MySQL : 	1.9721 s (104 Requests)
    PHP : 	7.8452 s
    Total : 	9.8173 s
    Memory : 	7.7886581420898 mb


    There were 187 errors for a number of different pages in a 7 minute period on Sunday 15/5. The good news is there has been no new errors since.

    Any ideas what the error means and how I might fix it?

    Thanks in advance.
      Web design Adelaide
      http://gocreate.com.au
      • 36748
      • 7 Posts
      @nickf08 Better post your issues on github aswell, more chance that people see it. https://github.com/modxcms/evolution/

      I've had this error as well. I got about 38 mails (on sunday 15-6-2016)
      « MODX Parse Error »
      MODX encountered the following error while attempting to parse the requested resource:
      « PHP Parse Error »
      PHP error debug
      Error : Unknown: The session id is too long or contains illegal characters, valid characters are a-z, A-Z, 0-9 and '-,'
      ErrorType[num] : 	WARNING[2]
      File : 	Unknown
      Line : 	0
      Basic info
      REQUEST_URI : 	http://MYDOMAINNAME.nl:443/
      Resource : 	[1]Home
      Referer : 	
      User Agent : 	Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
      IP : 	81.161.59.17
      Benchmarks
      MySQL : 	0.0061 s (2 Requests)
      PHP : 	0.0351 s
      Total : 	0.0412 s
      Memory : 	2.7912139892578 mb
      
      Backtrace
      


      If you look closely to my and your log, you will see the IP's are the same (!)

      Could be some malicious script trying to mess with the session id's. See https://en.wikipedia.org/wiki/Session_hijacking

      Best to block the IP via .htaccess or PHP. [ed. note: jannico last edited this post 10 years, 3 months ago.]
        • 13226
        • 953 Posts
        Just out of interest - have you tried backtracing the IP ?

        You get Bitdefender (Romania), take a look at the IP neighbourhood and you get further IPs' from Bitdefender
          • 36748
          • 7 Posts
          Did check it, but just saw it was from Romania.

          Why would an AV do this? Crawling our site.
            • 21417
            • 486 Posts
            If you look closely to my and your log, you will see the IP's are the same (!)
            Wow!!! Good pickup. Thanks for the tip, I have blocked that IP for that site.
            Interesting.
            Thanks to you both.
              Web design Adelaide
              http://gocreate.com.au