My audit log is FULL (almost 2Megs full) of text like the following:

[29/Dec/2008:23:12:29 +0100] xU3lkMMYTucAAGNDUFwAAAAY 2703 80
GET /phpmyadmin/main.php HTTP/1.0

The rule Host header is a numeric IP address obviously matches and the audit action is generated.

The above IP appears in my log 304 times and the log is 24hours old!
Also the other IP is the IP of one of the local ifaces.

My question is what the above might mean ?!? Is it necessarily a malicious act (e.g. the is an open proxy) and many people connect through it trying to fetch phpmyadmin (which btw does not exist) or could it be something else normal ??? Does this IP sound familiar to you ?

On Tue, Dec 30, 2008 at 4:16 PM, Ivan Ristic wrote:

On Tue, Dec 30, 2008 at 1:59 PM, Ioannis Angelopoulos wrote:
> Dear All,
> Greetings from Greece. I am a newbie in mod_security 2.x so please bear with
> me...
> I am trying to understand in detail the different audit log parts.
> For example in my log file I have:
> --b1820656-A--
> [29/Dec/2008:23:12:29 +0100] xU3lkMMYTucAAGNDUFwAAAAY 2703
> 80
> What do all these parts mean ? What are the two IP addresses and what the
> number between them represent ?

The tokens on that line are as follows:
 1. Timestamp
 2. Unique transaction ID
 3. Remote IP address
 4. Remote port
 5. Local IP address
 6. Local port

> I tried to search for it in the manual but all it says is that the A part is
> the audit log header and that is mandatory. It also explains the
> --b1820656-A-- part but not what is inside (at least I could not find it).
> Is there any extensive documentation on the log format, what the different
> parts mean and if we can modify them ?

Yes, there is. I updated that part of the documentation just a few
weeks ago. It's a separate document and is available in the

I imagine it will be available as a PDF in one of the future releases.

> It is very important for me as some IPs are asking for some weird things
> from my server.
Ivan Ristic