Error 403 forbidden auf 3 Domains

daisyduke

New Member
Hallo Community

Ich kämpfe jetzt schon seit wochen mit der fehlermeldung error403 /index.php

Egal welche seite ich mehrfach aufrufe kommt der 403, dann ist die Seite für mehrere Sek. weiß und wenn ich dann wieder aktuallisiere ist das Template total verschoben, die Links befinden sich dann nur noch auf der linken seite und Bilder werden auch nicht richitg geladen.

Nach mehrfachen F5 ist die Seite wieder OK.
Doch der 403er kommt immer wieder.


Ich verwende IspCP Omega auf Apache2.0 DebianLenny

Bin echt am verzweifeln und hoffe das mir jemand Helfen kann
 
Versuche mal den Apache Server neu zu starten. Schaue in die Logs auf ungewöhnliche Einträge und poste hier rein.
 
Guten Morgen

Da ich immernoch probleme mit den 403er habe und den fehler nicht finden kann, hier mal einege ausschnitte der logdateien.

/var/log/apache2

suexec.log
PHP:
[2010-08-14 09:33:33]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
[2010-08-14 09:34:50]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
[2010-08-14 09:34:55]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
[2010-08-14 09:41:44]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
[2010-08-14 10:07:58]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
[2010-08-14 10:25:33]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
[2010-08-14 10:27:27]: uid: (vu2004/vu2004) gid: (2004/vu2004) cmd: php5-fcgi-starter
wiederholt sich immer wieder

other_vhosts_access.log
PHP:
seite1.de:80 80.137.60.48 - - [14/Aug/2010:11:40:16 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281777957 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/mahjong/endless-mahjong-2.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)"
seite2.de:80 114.80.93.71 - - [14/Aug/2010:11:40:23 +0200] "GET /css/css/main.css HTTP/1.1" 404 448 "http://seite2.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
seite2.de:80 114.80.93.71 - - [14/Aug/2010:11:40:23 +0200] "GET /css/css/menu.css HTTP/1.1" 404 448 "http://seite2.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
seite2.de:80 114.80.93.71 - - [14/Aug/2010:11:40:24 +0200] "GET /lib/lib/topmenu.js HTTP/1.1" 404 448 "http://seite2.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
seite2.de:80 114.80.93.71 - - [14/Aug/2010:11:40:25 +0200] "GET /ajax/ajax/global.ajax.js HTTP/1.1" 404 448 "http://seite2.de/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
seite1.de:80 66.249.66.184 - - [14/Aug/2010:11:40:58 +0200] "GET /profil/userprofile/Dirki27.html HTTP/1.1" 303 26 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
seite1.de:80 66.249.66.15 - - [14/Aug/2010:11:40:59 +0200] "GET /events/day/20100731.html HTTP/1.1" 200 10396 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
seite1.de:80 80.137.60.48 - - [14/Aug/2010:11:41:12 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281777957 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/mahjong/endless-mahjong-2.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)"
seite1.de:80 88.131.106.22 - - [14/Aug/2010:11:42:19 +0200] "GET /robots.txt HTTP/1.0" 200 141 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) Speedy Spider (http://www.entireweb.com/about/search_tech/speedy_spider/)"
seite1.de:80 88.131.106.22 - - [14/Aug/2010:11:42:19 +0200] "GET /fun/spiele/allespiele/baseball/homerun-rally.html HTTP/1.0" 404 679 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) Speedy Spider (http://www.entireweb.com/about/search_tech/speedy_spider/)"
seite1.de:80 80.137.60.48 - - [14/Aug/2010:11:42:43 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281777957 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/mahjong/endless-mahjong-2.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)"
seite1.de:80 80.137.60.48 - - [14/Aug/2010:11:43:14 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281777957 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/mahjong/endless-mahjong-2.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)"
seite1.de:80 80.137.60.48 - - [14/Aug/2010:11:44:12 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281777957 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/mahjong/endless-mahjong-2.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)"
seite1.de:80 123.125.66.19 - - [14/Aug/2010:11:44:15 +0200] "GET /videos/trailer/der-baader-meinhof-komplex-trailer-zum-kinofilm.html HTTP/1.1" 200 20054 "-" "Baiduspider+(+http://www.baidu.com/search/spider.htm)"
seite1.de:80 66.249.66.184 - - [14/Aug/2010:11:44:25 +0200] "GET /profil/userprofile/Kolibri.html HTTP/1.1" 303 26 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
seite3.de:80 89.248.172.26 - - [14/Aug/2010:11:44:47 +0200] "GET /game_2798_solitaire-cruise_de_pc.html HTTP/1.1" 200 18566 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
seite3.de:80 89.248.172.26 - - [14/Aug/2010:11:44:48 +0200] "POST /gameinfo.php?id=2798&foldername=solitaire-cruise&local=de&gtype=pc HTTP/1.1" 200 19264 "http://seite3.de/game_2798_solitaire-cruise_de_pc.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
seite3.de:80 89.248.172.26 - - [14/Aug/2010:11:44:49 +0200] "POST /gameinfo.php?id=2798&foldername=solitaire-cruise&local=de&gtype=pc HTTP/1.1" 200 19264 "http://seite3.de/gameinfo.php?id=2798&foldername=solitaire-cruise&local=de&gtype=pc#CommentForm" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
seite1.de:80 123.125.66.113 - - [14/Aug/2010:11:45:16 +0200] "GET / HTTP/1.1" 200 15452 "-" "Baiduspider+(+http://www.baidu.com/search/spider.htm)"
seite1.de:80 80.137.60.48 - - [14/Aug/2010:11:45:21 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281777957 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/mahjong/endless-mahjong-2.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)"
seite1.de:80 123.125.66.103 - - [14/Aug/2010:11:45:24 +0200] "GET /videos/trailer/das-kabinett-des-dr-parnassus-deutscher-german-trailer.html HTTP/1.1" 200 20640 "-" "Baiduspider+(+http://www.baidu.com/search/spider.htm)"
seite1.de:80 123.125.66.100 - - [14/Aug/2010:11:45:30 +0200] "GET /galerie/jahreszeiten/sommer.html HTTP/1.1" 200 10111 "-" "Baiduspider+(+http://www.baidu.com/search/spider.htm)"

error.log
PHP:
[Fri Apr 09 12:24:45 2010] [notice] Apache/2.2.9 (Debian) configured -- resuming normal operations
[Fri Apr 09 12:25:02 2010] [error] [client 66.249.66.12] File does not exist: /var/www/components
[Fri Apr 09 12:26:01 2010] [notice] caught SIGTERM, shutting down

access.log
PHP:
66.249.66.12 - - [09/Apr/2010:12:25:02 +0200] "GET /components/images/desertstormTh1.gif HTTP/1.1" 404 261 "-" "Googlebot-Image/1.0"
208.80.193.35 - - [09/Apr/2010:12:25:37 +0200] "GET / HTTP/1.0" 200 45 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; Comcast; .NET CLR 2.0.50727; Comcast)"


/var/log/apache2/users

default-error.log
PHP:
[Fri Aug 13 07:20:20 2010] [error] [client 58.218.204.110] File does not exist: /var/www/ispcp/gui/judge.php
[Fri Aug 13 11:22:57 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/admin/config
[Fri Aug 13 11:23:07 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/myadmin
[Fri Aug 13 11:23:07 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/PHPMYADMIN
[Fri Aug 13 11:23:10 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/p
[Fri Aug 13 11:23:11 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin2
[Fri Aug 13 11:23:11 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin-2
[Fri Aug 13 11:23:12 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin-2.2.3
[Fri Aug 13 11:23:18 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin-2.5.4
[Fri Aug 13 11:23:22 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/PMA
[Fri Aug 13 11:23:25 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/admin/config
[Fri Aug 13 11:23:47 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/p
[Fri Aug 13 11:24:09 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin-2.5.5-pl1
[Fri Aug 13 11:24:09 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin-2.5.5-rc1config
[Fri Aug 13 11:24:21 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin-2.5.6
[Fri Aug 13 11:24:28 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpMyAdmin2
[Fri Aug 13 11:24:28 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/phpmanager
[Fri Aug 13 11:24:49 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/sqlmanager
[Fri Aug 13 11:24:56 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/webdb
[Fri Aug 13 11:24:56 2010] [error] [client 207.63.37.2] File does not exist: /var/www/ispcp/gui/websql
[Fri Aug 13 16:23:38 2010] [error] [client 94.136.45.55] client sent HTTP/1.1 request without hostname (see RFC2616 section 14.23): /w00tw00t.at.ISC.SANS.DFind:)
[Fri Aug 13 18:11:52 2010] [notice] caught SIGTERM, shutting down
[Fri Aug 13 18:11:56 2010] [notice] FastCGI: wrapper mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Fri Aug 13 18:11:56 2010] [notice] FastCGI: process manager initialized (pid 18322)
[Fri Aug 13 18:11:56 2010] [warn] FastCGI: server "/var/www/fcgi/master/php5-fcgi-starter" (uid 2000, gid 2000) started (pid 18323)
[Fri Aug 13 18:11:56 2010] [notice] Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 configured -- resuming normal operations
[Fri Aug 13 18:11:56 2010] [notice] suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Fri Aug 13 18:13:47 2010] [notice] caught SIGTERM, shutting down
[Fri Aug 13 18:13:51 2010] [notice] suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Fri Aug 13 18:13:51 2010] [notice] FastCGI: wrapper mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Fri Aug 13 18:13:51 2010] [notice] FastCGI: process manager initialized (pid 15368)
[Fri Aug 13 18:13:51 2010] [notice] Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 configured -- resuming normal operations
[Fri Aug 13 18:13:51 2010] [warn] FastCGI: server "/var/www/fcgi/master/php5-fcgi-starter" (uid 2000, gid 2000) started (pid 15503)
[Fri Aug 13 21:48:23 2010] [notice] caught SIGTERM, shutting down
[Fri Aug 13 21:48:38 2010] [notice] suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Fri Aug 13 21:48:38 2010] [notice] FastCGI: wrapper mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Fri Aug 13 21:48:38 2010] [notice] FastCGI: process manager initialized (pid 15464)
[Fri Aug 13 21:48:38 2010] [notice] Apache/2.2.9 (Debian) mod_fastcgi/2.4.6 configured -- resuming normal operations
[Fri Aug 13 21:48:38 2010] [warn] FastCGI: server "/var/www/fcgi/master/php5-fcgi-starter" (uid 2000, gid 2000) started (pid 15556)

seite1.de-access.log 188393 zeilen
PHP:
123.125.66.38 - - [14/Aug/2010:01:30:17 +0200] "GET / HTTP/1.1" 200 15310 "-" "Baiduspider+(+http://www.baidu.com/search/spider.htm)"
88.70.85.172 - - [14/Aug/2010:01:30:22 +0200] "GET /modules/mod_shoutbox/getShouts.php?&jal_lastID=1772&rand=898394 HTTP/1.1" 200 27 "http://www.seite1.de/allespiele/bilderratsel/art-heist.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:30:28 +0200] "GET /modules/mod_shoutbox/getShouts.php?&jal_lastID=1772&rand=933947 HTTP/1.1" 200 27 "http://www.seite1.de/allespiele/bilderratsel/art-heist.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:31:13 +0200] "GET /modules/mod_shoutbox/getShouts.php?&jal_lastID=1772&rand=837554 HTTP/1.1" 200 27 "http://www.seite1.de/allespiele/bilderratsel/art-heist.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:31:18 +0200] "POST /index.php?option=com_puarcade&no_html=1&arcade=keepalive&time=1281742154 HTTP/1.1" 200 36 "http://www.seite1.de/allespiele/bilderratsel/art-heist.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:31:32 +0200] "GET /modules/mod_shoutbox/getShouts.php?&jal_lastID=1772&rand=554094 HTTP/1.1" 200 27 "http://www.seite1.de/allespiele/bilderratsel/art-heist.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
66.249.66.184 - - [14/Aug/2010:01:31:34 +0200] "GET /index.php/zigiz/forum/programmierung.html HTTP/1.1" 404 7585 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
88.70.85.172 - - [14/Aug/2010:01:31:56 +0200] "GET /modules/mod_shoutbox/getShouts.php?&jal_lastID=1772&rand=789198 HTTP/1.1" 200 27 "http://www.seite1.de/allespiele/bilderratsel/art-heist.html" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:32:06 +0200] "POST /index.php?autocom=arcade&do=savescore HTTP/1.1" 303 26 "http://www.seite1.de/components/flash/ArtHeistv32Th.swf?pn_extravars=arcade~storescore|no_html~1&pn_script=index2.php&pn_modvar=optio" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:32:14 +0200] "GET /images/community/pua/beliebtespiele2.png HTTP/1.1" 200 4549 "http://www.seite1.de/components/flash/ArtHeistv32Th.swf?pn_extravars=arcade~storescore|no_html~1&pn_script=index2.php&pn_modvar=optio" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:32:13 +0200] "GET /allespiele/bilderratsel/art-heist.html HTTP/1.1" 200 16329 "http://www.seite1.de/allespiele/misc/action.html?d4dad6935f632ac35975e3001dc7bbe8=13a3320b38e3eb43c475730bd03825e3" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"
88.70.85.172 - - [14/Aug/2010:01:32:26 +0200] "GET /iepngfix.htc HTTP/1.1" 404 452 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6.5; SIMBAR={656315FA-BA0E-4D30-B740-C55BDCC85EF2}; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; MSN OptimizedIE8;DEDE; AskTB5.6)"

seite1.de-error.log

PHP:
[Sat Aug 14 01:16:06 2010] [error] [client 93.200.245.182] File does not exist: /var/www/virtual/seite1.de/htdocs/administrator/components/com_easycreator, referer: [url]http://www.seite1.de/administrator/index.php[/url]
[Sat Aug 14 01:18:22 2010] [error] [client 93.200.245.182] File does not exist: /var/www/virtual/seite1.de/htdocs/administrator/plugins, referer: [url]http://www.seite1.de/administrator/index.php?option=com_community&view=configuration[/url]
[Sat Aug 14 01:18:22 2010] [error] [client 93.200.245.182] File does not exist: /var/www/virtual/seite1.de/htdocs/administrator/plugins, referer: [url]http://www.seite1.de/administrator/index.php?option=com_community&view=configuration[/url]
[Sat Aug 14 01:20:42 2010] [error] [client 93.200.245.182] File does not exist: /var/www/virtual/seite1.de/htdocs/administrator/components/com_easycreator, referer: [url]http://www.seite1.de/administrator/index.php?option=com_community&view=profiles[/url]
[Sat Aug 14 01:20:54 2010] [error] [client 93.200.245.182] File does not exist: /var/www/virtual/seite1.de/htdocs/administrator/plugins, referer: [url]http://www.seite1.de/administrator/index.php?option=com_community&view=community[/url]
[Sat Aug 14 02:52:40 2010] [error] [client 88.70.85.172] File does not exist: /var/www/virtual/seite1.de/htdocs/iepngfix.htc
[Sat Aug 14 03:00:26 2010] [warn] FastCGI: (dynamic) server "/var/www/fcgi/seite1.de/php5-fcgi-starter" (uid 2001, gid 2001) restarted (pid 15842)
[Sat Aug 14 03:00:42 2010] [warn] FastCGI: (dynamic) server "/var/www/fcgi/seite1.de/php5-fcgi-starter" (pid 15842) termination signaled
[Sat Aug 14 03:00:42 2010] [warn] FastCGI: (dynamic) server "/var/www/fcgi/seite1.de/php5-fcgi-starter" (pid 15842) terminated by calling exit with status '0' 
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/galerie/img_thumbnails/fun_73/sonstiger_spass_80/lustig_17_20090225_1417309846.jpg, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/cbe/tn325.jpg, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/cbe/tn329.jpg, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/galerie/img_thumbnails/avatare_14/love__hate_19/lovehate_13_20090224_1531505369.gif, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/cbe/tn321.jpg, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/templates/community/images/content_wrapper_corners.png, referer: [url]http://www.seite1.de/templates/community/css/layout.css[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/fox.png, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/galerie/img_thumbnails/fuer_jeden_tag__wochentage_43/guten_tag__hallo_47/hallo_9_20090224_1120706693.gif, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/cbe/tn335.jpg, referer: [url]http://www.seite1.de/[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/templates/community/images/module_rounded_white_corners.png, referer: [url]http://www.seite1.de/templates/community/css/modules.css[/url]
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/templates/community/images/module_header_blue.png, referer: [url]http://www.seite1.de/templates/community/css/modules.css[/url]
[Sat Aug 14 05:36:26 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/modules/mod_yoo_login/styles/default/images/password_bg.png, referer: [url]http://www.seite1.de/modules/mod_yoo_login/mod_yoo_login.css.php[/url]

/var/www/fcgi/master

php5-fcgi-starter
PHP:
#!/bin/sh

umask 022
PHPRC="/var/www/fcgi/master/php5/"
export PHPRC
PHP_FCGI_CHILDREN=2
export PHP_FCGI_CHILDREN
PHP_FCGI_MAX_REQUESTS=500
export PHP_FCGI_MAX_REQUESTS
TMPDIR="/var/www/ispcp/gui/phptmp"
export TMPDIR
exec /usr/bin/php5-cgi


/var/www/fcgi/seite1.de
php5-fcgi-starter
PHP:
#!/bin/sh
umask 022
PHPRC="/var/www/fcgi/seite1.de/php5/"
export PHPRC
TMPDIR="/var/www/virtual/seite1.de/phptmp" 
export TMPDIR
PHP_FCGI_CHILDREN=2
export PHP_FCGI_CHILDREN
exec /usr/bin/php5-cgi
 
apache2.conf

PHP:
#
# Based upon the NCSA server configuration files originally by Rob McCool.
#
# This is the main Apache server configuration file.  It contains the
# configuration directives that give the server its instructions.
# See http://httpd.apache.org/docs/2.2/ for detailed information about
# the directives.
#
# Do NOT simply read the instructions in here without understanding
# what they do.  They're here only as hints or reminders.  If you are unsure
# consult the online docs. You have been warned.  
#
# The configuration directives are grouped into three basic sections:
#  1. Directives that control the operation of the Apache server process as a
#     whole (the 'global environment').
#  2. Directives that define the parameters of the 'main' or 'default' server,
#     which responds to requests that aren't handled by a virtual host.
#     These directives also provide default values for the settings
#     of all virtual hosts.
#  3. Settings for virtual hosts, which allow Web requests to be sent to
#     different IP addresses or hostnames and have them handled by the
#     same Apache server process.
#
# Configuration and logfile names: If the filenames you specify for many
# of the server's control files begin with "/" (or "drive:/" for Win32), the
# server will use that explicit path.  If the filenames do *not* begin
# with "/", the value of ServerRoot is prepended -- so "/var/log/apache2/foo.log"
# with ServerRoot set to "" will be interpreted by the
# server as "//var/log/apache2/foo.log".
#

### Section 1: Global Environment
#
# The directives in this section affect the overall operation of Apache,
# such as the number of concurrent requests it can handle or where it
# can find its configuration files.
#

#
# ServerRoot: The top of the directory tree under which the server's
# configuration, error, and log files are kept.
#
# NOTE!  If you intend to place this on an NFS (or otherwise network)
# mounted filesystem then please read the LockFile documentation (available
# at <URL:http://httpd.apache.org/docs-2.1/mod/mpm_common.html#lockfile>);
# you will save yourself a lot of trouble.
#
# Do NOT add a slash at the end of the directory path.
#
ServerRoot "/etc/apache2"

#
# The accept serialization lock file MUST BE STORED ON A LOCAL DISK.
#
#<IfModule !mpm_winnt.c>
#<IfModule !mpm_netware.c>
LockFile /var/lock/apache2/accept.lock
#</IfModule>
#</IfModule>

#
# PidFile: The file in which the server should record its process
# identification number when it starts.
# This needs to be set in /etc/apache2/envvars
#
PidFile ${APACHE_PID_FILE}

#
# Timeout: The number of seconds before receives and sends time out.
#
Timeout 300

#
# KeepAlive: Whether or not to allow persistent connections (more than
# one request per connection). Set to "Off" to deactivate.
#
KeepAlive On

#
# MaxKeepAliveRequests: The maximum number of requests to allow
# during a persistent connection. Set to 0 to allow an unlimited amount.
# We recommend you leave this number high, for maximum performance.
#
MaxKeepAliveRequests 100

#
# KeepAliveTimeout: Number of seconds to wait for the next request from the
# same client on the same connection.
#
KeepAliveTimeout 15

##
## Server-Pool Size Regulation (MPM specific)
## 

# prefork MPM
# StartServers: number of server processes to start
# MinSpareServers: minimum number of server processes which are kept spare
# MaxSpareServers: maximum number of server processes which are kept spare
# MaxClients: maximum number of server processes allowed to start
# MaxRequestsPerChild: maximum number of requests a server process serves
<IfModule mpm_prefork_module>
    StartServers          5
    MinSpareServers       5
    MaxSpareServers      10
    MaxClients          150
    MaxRequestsPerChild   0
</IfModule>

# worker MPM
# StartServers: initial number of server processes to start
# MaxClients: maximum number of simultaneous client connections
# MinSpareThreads: minimum number of worker threads which are kept spare
# MaxSpareThreads: maximum number of worker threads which are kept spare
# ThreadsPerChild: constant number of worker threads in each server process
# MaxRequestsPerChild: maximum number of requests a server process serves
<IfModule mpm_worker_module>
    StartServers          2
    MaxClients          150
    MinSpareThreads      25
    MaxSpareThreads      75 
    ThreadsPerChild      25
    MaxRequestsPerChild   0
</IfModule>


<IfModule mod_evasive20.c>
  DOSHashTableSize 3097
  DOSPageCount 5
  DOSSiteCount 200
  DOSPageInterval 2
  DOSSiteInterval 2
  DOSBlockingPeriod 10
  DOSEmailNotify .........
  DOSLogDir "/var/lock/mod_evasive"

</IfModule>


# These need to be set in /etc/apache2/envvars
User ${APACHE_RUN_USER}
Group ${APACHE_RUN_GROUP}

#
# AccessFileName: The name of the file to look for in each directory
# for additional configuration directives.  See also the AllowOverride
# directive.
#

AccessFileName .htaccess

#
# The following lines prevent .htaccess and .htpasswd files from being 
# viewed by Web clients. 
#
<Files ~ "^\.ht">
    Order allow,deny
    Deny from all
</Files>

#
# DefaultType is the default MIME type the server will use for a document
# if it cannot otherwise determine one, such as from filename extensions.
# If your server contains mostly text or HTML documents, "text/plain" is
# a good value.  If most of your content is binary, such as applications
# or images, you may want to use "application/octet-stream" instead to
# keep browsers from trying to display binary files as though they are
# text.
#
DefaultType text/plain


#
# HostnameLookups: Log the names of clients or just their IP addresses
# e.g., www.apache.org (on) or 204.62.129.132 (off).
# The default is off because it'd be overall better for the net if people
# had to knowingly turn this feature on, since enabling it means that
# each client request will result in AT LEAST one lookup request to the
# nameserver.
#
HostnameLookups Off

# ErrorLog: The location of the error log file.
# If you do not specify an ErrorLog directive within a <VirtualHost>
# container, error messages relating to that virtual host will be
# logged here.  If you *do* define an error logfile for a <VirtualHost>
# container, that host's errors will be logged there and not here.
#
ErrorLog /var/log/apache2/error.log

#
# LogLevel: Control the number of messages logged to the error_log.
# Possible values include: debug, info, notice, warn, error, crit,
# alert, emerg.
#
LogLevel warn

# Include module configuration:
Include /etc/apache2/mods-enabled/*.load
Include /etc/apache2/mods-enabled/*.conf

# Include all the user configurations:
Include /etc/apache2/httpd.conf

# Include ports listing
Include /etc/apache2/ports.conf

#
# The following directives define some format nicknames for use with
# a CustomLog directive (see below).
# If you are behind a reverse proxy, you might want to change %h into %{X-Forwarded-For}i
#
LogFormat "%v:%p %h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
LogFormat "%h %l %u %t \"%r\" %>s %b" common
LogFormat "%{Referer}i -> %U" referer
LogFormat "%{User-agent}i" agent

#
# Define an access log for VirtualHosts that don't define their own logfile
CustomLog /var/log/apache2/other_vhosts_access.log vhost_combined

#
# Customizable error responses come in three flavors:
# 1) plain text 2) local redirects 3) external redirects
#
# Some examples:
#ErrorDocument 500 "The server made a boo boo."
#ErrorDocument 404 /missing.html
#ErrorDocument 404 "/cgi-bin/missing_handler.pl"
#ErrorDocument 402 http://www.example.com/subscription_info.html
#

#
# Putting this all together, we can internationalize error responses.
#
# We use Alias to redirect any /error/HTTP_<error>.html.var response to
# our collection of by-error message multi-language collections.  We use 
# includes to substitute the appropriate text.
#
# You can modify the messages' appearance without changing any of the
# default HTTP_<error>.html.var files by adding the line:
#
#   Alias /error/include/ "/your/include/path/"
#
# which allows you to create your own set of files by starting with the
# /usr/share/apache2/error/include/ files and copying them to /your/include/path/, 
# even on a per-VirtualHost basis.  The default include files will display
# your Apache version number and your ServerAdmin email address regardless
# of the setting of ServerSignature.
#
# The internationalized error documents require mod_alias, mod_include
# and mod_negotiation.  To activate them, uncomment the following 30 lines.

#    Alias /error/ "/usr/share/apache2/error/"
#
#    <Directory "/usr/share/apache2/error">
#        AllowOverride None
#        Options IncludesNoExec
#        AddOutputFilter Includes html
#        AddHandler type-map var
#        Order allow,deny
#        Allow from all
#        LanguagePriority en cs de es fr it nl sv pt-br ro
#        ForceLanguagePriority Prefer Fallback
#    </Directory>
#
#    ErrorDocument 400 /error/HTTP_BAD_REQUEST.html.var
#    ErrorDocument 401 /error/HTTP_UNAUTHORIZED.html.var
#    ErrorDocument 403 /error/HTTP_FORBIDDEN.html.var
#    ErrorDocument 404 /error/HTTP_NOT_FOUND.html.var
#    ErrorDocument 405 /error/HTTP_METHOD_NOT_ALLOWED.html.var
#    ErrorDocument 408 /error/HTTP_REQUEST_TIME_OUT.html.var
#    ErrorDocument 410 /error/HTTP_GONE.html.var
#    ErrorDocument 411 /error/HTTP_LENGTH_REQUIRED.html.var
#    ErrorDocument 412 /error/HTTP_PRECONDITION_FAILED.html.var
#    ErrorDocument 413 /error/HTTP_REQUEST_ENTITY_TOO_LARGE.html.var
#    ErrorDocument 414 /error/HTTP_REQUEST_URI_TOO_LARGE.html.var
#    ErrorDocument 415 /error/HTTP_UNSUPPORTED_MEDIA_TYPE.html.var
#    ErrorDocument 500 /error/HTTP_INTERNAL_SERVER_ERROR.html.var
#    ErrorDocument 501 /error/HTTP_NOT_IMPLEMENTED.html.var
#    ErrorDocument 502 /error/HTTP_BAD_GATEWAY.html.var
#    ErrorDocument 503 /error/HTTP_SERVICE_UNAVAILABLE.html.var
#    ErrorDocument 506 /error/HTTP_VARIANT_ALSO_VARIES.html.var



# Include of directories ignores editors' and dpkg's backup files,
# see README.Debian for details.

# Include generic snippets of statements
Include /etc/apache2/conf.d/

# Include the virtual host configurations:
Include /etc/apache2/sites-enabled/


ist es normal das die httpd.conf leer ist??


seite1.de .htaccess

PHP:
##  Can be commented out if causes errors, see notes above.
Options +FollowSymLinks

#
#  mod_rewrite in use

RewriteEngine On


#<Files ~ "\.xml$">
#Order allow,deny
#Deny from all
#Satisfy all
#</Files>
## End of deny access to extension xml files
RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|\%3D) [OR]
# Block out any script trying to base64_encode crap to send via URL
RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [OR]
# Block out any script that includes a <script> tag in URL
RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
# Send all blocked request to homepage with 403 Forbidden error!
RewriteRule ^(.*)$ index.php [F,L]


# RewriteBase /



RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_URI} !^/index.php
RewriteCond %{REQUEST_URI} (/|\.php|\.html|\.htm|\.feed|\.pdf|\.raw|/[^.]*)$  [NC]
RewriteRule (.*) index.php
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization},L]


Ich hoffe ihr könnt mir nun weiterhelfen ich wäre euch sehr dankbar
 
Last edited by a moderator:
Options +FollowSymLinks


Diese Eintrag aus der .htaccess Datei entfernen, dann geht es. Wie Ich gesagt hatte, es liegt an der .htaccess Datei, hier werden versucht Operationen auszuführen, die vom System her nicht erlaubt sind, daher forbidden.
 
Habe ich entfernt bekomme aber immer noch den 403er

und auf den anderen beiden Seiten benutze ich erst keine .htaccess und bekomme auch dort die Errormeldung???
 
Wenn eine nicht-erlaubte Operation in der .htaccess steht wird ein 500 (Internal Server Error) und kein 403 geworfen.

In den ganzen geposteten Logs tritt aber kein einziges Mal ein 403 auf -such mal mit einer Suchfunktion in den Logdateien danach.
Ist es aber wirklich ein 403 oder wird nur der Text einer 403 ausgegeben?
Die Webseiten-Header waeren in dem Moment interessant, sowie die Serverlogs von genau diesem Zeitpunkt (plus minus paar Sekunden)
 
Code:
[Sat Aug 14 05:36:25 2010] [error] [client 93.211.83.46] client denied by server configuration: /var/www/virtual/seite1.de/htdocs/images/galerie/img_thumbnails/fun_73/sonstiger_spass_80/lustig_17_20090225_1417309846.jpg, referer: [url]http://www.seite1.de/[/url]
Diese Zeile erinnert mich stark an mod_evasive, ist das eventuell installiert und etwas "scharf" eingestellt ?
 
Error403 wird von ispcp ausgegeben und dann bin ich einige sekunden lang (ausgesperrt) kann so oft ich will F5 drücken Error bleibt.... warte ich und aktuallisiere dann.. wird das Template nicht korrekt geladen. muss dann mehrmals laden bis die seite wieder richtig angezeigt wird..... bis zum nächsten 403er.
Code:
<IfModule mod_evasive20.c>
  DOSHashTableSize 3097
  DOSPageCount 5
  DOSSiteCount 200
  DOSPageInterval 2
  DOSSiteInterval 2
  DOSBlockingPeriod 10
  DOSEmailNotify..........
  DOSLogDir "/var/lock/mod_evasive"

</IfModule>
Einstellungen habe ich aus diesem Forum

...eine 500er Meldung bekomme ich nicht
 
Last edited by a moderator:
Deaktivier mal temporär mod_evasive mittels a2dismod und schau ob nach einem Neustart des Apachen immer noch dein besagtes Problem auftritt.
 
hallo

wenn ich a2dismod mod_evasive eingebe sagt er mir

ERROR: Module mod_evasive does not exist!


obwohl in /etc/apache2/mods-available und /etc/apache2/mods-enabled
mod-evasive.load enthalten ist
 
Überprüfe mal ob du auch den Modulnamen richtig geschrieben hast, denn:

mod_evasive != mod-evasive

;)
 
Back
Top