• I noticed I started getting E-Mails from iThemes Security about a File Change in error_log.

    On further investigation this is generating this on a frequent basis:
    [25-Nov-2018 21:03:44 UTC] PHP Warning: file_put_contents(/var/www/clients/client74/web304/web/wp-content/uploads/ithemes-security/logs/event-log-adam-zook-consulting-pPrxqCmj6GUP8p1C6NsegS1bjrlpGx.log): failed to open stream: No such file or directory in /home/actualdomainid/public_html/wp-content/plugins/better-wp-security/core/lib/log.php on line 176

    I replaced my company name with actualdomainid in this error. /var/www/clients/client74/web304/ was the location my site was on with my previous hosting provider though and I do not have a clue who adam-zook-consulting is and doing a google search has yielded no results either.

    Sure enough checking /public_html/wp-content/uploads/ithemes-security/logs there is a file over 10MB called event-log-adam-zook-consulting-pPrxqCmj6GUP8p1C6NsegS1bjrlpGx.log.1 and a newer one that is 6MB called event-log-adam-zook-consulting-pPrxqCmj6GUP8p1C6NsegS1bjrlpGx.log

    There is a lot in that file and my domain name is mentioned a lot. I have removed my domain name below:

    "REDIRECT_REDIRECT_REDIRECT_REMOTE_PORT"";s:5:""36096"";s:48:""REDIRECT_REDIRECT_REDIRECT_REDIRECT_QUERY_STRING"";s:47:""doing_wp_cron=1527004732.0275049209594726562500"";s:39:""REDIRECT_REDIRECT_REDIRECT_REDIRECT_URL"";s:12:""/wp-cron.php"";s:44:""REDIRECT_REDIRECT_REDIRECT_GATEWAY_INTERFACE"";s:7:""CGI/1.1"";s:42:""REDIRECT_REDIRECT_REDIRECT_SERVER_PROTOCOL"";s:8:""HTTP/1.1"";s:41:""REDIRECT_REDIRECT_REDIRECT_REQUEST_METHOD"";s:4:""POST"";s:39:""REDIRECT_REDIRECT_REDIRECT_QUERY_STRING"";s:47:""doing_wp_cron=1527004732.0275049209594726562500"";s:38:""REDIRECT_REDIRECT_REDIRECT_REQUEST_URI"";s:60:""/wp-cron.php?doing_wp_cron=1527004732.0275049209594726562500"";s:38:""REDIRECT_REDIRECT_REDIRECT_SCRIPT_NAME"";s:10:""/php5-fcgi"";s:36:""REDIRECT_REDIRECT_REDIRECT_PATH_INFO"";s:12:""/wp-cron.php"";s:42:""REDIRECT_REDIRECT_REDIRECT_PATH_TRANSLATED"";s:48:""/var/www/clients/client74/web304/web/wp-cron.php"";s:33:""REDIRECT_REDIRECT_REDIRECT_STATUS"";s:3:""103"";s:28:""REDIRECT_REDIRECT_SCRIPT_URL"";s:12:""/wp-cron.php"";s:28:""REDIRECT_REDIRECT_SCRIPT_URI"";s:38:""http://www.MYDOMAINNAME.co.uk/wp-cron.php"";s:24:""REDIRECT_REDIRECT_STATUS"";s:3:""103"";s:19:""REDIRECT_SCRIPT_URL"";s:12:""/wp-cron.php"";s:19:""REDIRECT_SCRIPT_URI"";s:38:""http://www.MYDOMAINNAME.co.uk/wp-cron.php"";s:16:""REDIRECT_HANDLER"";s:9:""php5-fcgi"";s:15:""REDIRECT_STATUS"";s:3:""103"";s:10:""SCRIPT_URL"";s:12:""/wp-cron.php"";s:10:""SCRIPT_URI"";s:38:""http://www.MYDOMAINNAME.co.uk/wp-cron.php"";s:15:""HTTP_USER_AGENT"";s:43:""WordPress/4.9.6; http://www.MYDOMAINNAME.co.uk"";s:9:""HTTP_HOST"";s:19:""www.MYDOMAINNAME.co.uk"";s:11:""HTTP_ACCEPT"";s:3:""*/*"";s:20:""HTTP_ACCEPT_ENCODING"";s:13:""deflate, gzip"";s:12:""HTTP_REFERER"";s:86:""http://www.MYDOMAINNAME.co.uk/wp-cron.php?doing_wp_cron=1527004732.0275049209594726562500"";s:15:""HTTP_CONNECTION"";s:5:""close"";s:14:""CONTENT_LENGTH"";s:1:""0"";s:12:""CONTENT_TYPE"";s:33:""application/x-www-form-urlencoded"";s:16:""SERVER_SIGNATURE"";s:0:"""";s:11:""SERVER_NAME"";s:19:""www.MYDOMAINNAME.co.uk"";s:11:""SERVER_ADDR"";s:13:""5.153.225.102"";s:11:""SERVER_PORT"";s:2:""80"";s:11:""REMOTE_ADDR"";s:13:""5.153.225.102"";s:13:""DOCUMENT_ROOT"";s:36:""/var/www/clients/client74/web304/web"";s:12:""SERVER_ADMIN"";s:25:""[email protected]"";s:15:""SCRIPT_FILENAME"";s:46:""/var/www/clients/client74/web304/web/index.php"";s:11:""REMOTE_PORT"";s:5:""36096"";s:12:""REDIRECT_URL"";s:10:""/index.php"";s:17:""GATEWAY_INTERFACE"";s:7:""CGI/1.1"";s:15:""SERVER_PROTOCOL"";s:8:""HTTP/1.1"";s:14:""REQUEST_METHOD"";s:3:""GET"";s:12:""QUERY_STRING"";s:0:"""";s:11:""SCRIPT_NAME"";s:10:""/index.php"";s:20:""ORIG_SCRIPT_FILENAME"";s:71:""/var/www/clients/client74/web304/cgi-bin/php5-fcgi-*-80-

    It looks like the IP 5.153.225.102 is the old hosting provider.

    If anyone can offer any advice it would be appreciated.

Viewing 1 replies (of 1 total)
  • Make sure to be running the latest iTSec plugin release: 7.2.0 (at the time of writing this post).
    If not, first update the plugin to the latest available release and see whether that resolves the issue.

Viewing 1 replies (of 1 total)

The topic ‘Unusual Log File Being Generated’ is closed to new replies.