Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lots of nginx errors in logs after upgrade

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    41 Posts 11 Posters 85.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      kpa
      last edited by

      They haven't really thought trough the value and practicality of that feature. Instead of helping to find any real threats it is going to cause more people freak out because there's an unknown scanner probing at multiple hosts on the local network for seemingly random web pages just like a real malware would be.

      1 Reply Last reply Reply Quote 0
      • mudmanc4M
        mudmanc4
        last edited by

        @kpa:

        They haven't really thought trough the value and practicality of that feature. Instead of helping to find any real threats it is going to cause more people freak out because there's an unknown scanner probing at multiple hosts on the local network for seemingly random web pages just like a real malware would be.

        I would like to know what exact version is being used which is probing ports and directories, if anyone can supply me with this info that would be great. I want to see this for myself. Before I find a gator.

        Here is a thought about such probing, considering what has been shown here as far as the locations scanned, any basic server admin would have preventative measures in place to prevent such activities, even if it's only fail2ban. Rendering the utility useless.

        1 Reply Last reply Reply Quote 0
        • T
          TheNarc
          last edited by

          I'll check with my users, but I think they're running the latest release (and I'm sure this feature is in the latest release), which seems to be 11.2.2262.

          1 Reply Last reply Reply Quote 0
          • M
            Mithrondil
            last edited by

            I have the same problem, and I have win7, using Firefox 64bit, and I have avast antivirus installed.
            So whats the conclusion on this matter, if its avast antivirus thats doing the scanning, can it be concidered normal or is a clean install of pfsense recommended?

            Also, is nginx a legit part of the pfsense install? Or how did this end up on my pfsense?

            1 Reply Last reply Reply Quote 0
            • K
              kpa
              last edited by

              Everything so far says that it is in fact Avast that does the scanning. See if you can turn off the module/service in Avast that does the scanning. Yes, Nginx is now the web server in pfsense that implements the webgui and other related services. It used to be lighttpd in pfSense 2.2.* but was changed for 2.3.*.

              1 Reply Last reply Reply Quote 0
              • mudmanc4M
                mudmanc4
                last edited by

                Interesting how this just started to be noticed in the logs. Or no one has bothered to look before now in this scenario.

                1 Reply Last reply Reply Quote 0
                • T
                  TheNarc
                  last edited by

                  I can confirm that you can disable this module in Avast - they call it Home Networking Security - and the log entries stop.  I wish I could provide detailed steps, but I don't run it myself and I was unable to easily find steps to do so.  I only know it's responsible because I had one of my users turn it off.  I'd bet it's fairly straightforward in the GUI though.

                  1 Reply Last reply Reply Quote 0
                  • M
                    Mithrondil
                    last edited by

                    By the way, is this nginx program written as opensource?

                    1 Reply Last reply Reply Quote 0
                    • JeGrJ
                      JeGr LAYER 8 Moderator
                      last edited by

                      @Mithrondil:

                      By the way, is this nginx program written as opensource?

                      http://nginx.org/en/

                      Yes it is.

                      Don't forget to upvote 👍 those who kindly offered their time and brainpower to help you!

                      If you're interested, I'm available to discuss details of German-speaking paid support (for companies) if needed.

                      1 Reply Last reply Reply Quote 0
                      • mudmanc4M
                        mudmanc4
                        last edited by

                        @TheNarc:

                        I can confirm that you can disable this module in Avast - they call it Home Networking Security - and the log entries stop.  I wish I could provide detailed steps, but I don't run it myself and I was unable to easily find steps to do so.  I only know it's responsible because I had one of my users turn it off.  I'd bet it's fairly straightforward in the GUI though.

                        Sounds as if I'll be needing that crocodile.
                        Thanks for confirming.

                        1 Reply Last reply Reply Quote 0
                        • C
                          cmb
                          last edited by

                          @mudmanc4:

                          Interesting how this just started to be noticed in the logs. Or no one has bothered to look before now in this scenario.

                          Before 2.3, the 404 logs from the web GUI's web server went to /dev/null. So I'm sure it was happening for quite some time, people just didn't have the logs to notice until more recently.

                          1 Reply Last reply Reply Quote 0
                          • mudmanc4M
                            mudmanc4
                            last edited by

                            @cmb:

                            @mudmanc4:

                            Interesting how this just started to be noticed in the logs. Or no one has bothered to look before now in this scenario.

                            Before 2.3, the 404 logs from the web GUI's web server went to /dev/null. So I'm sure it was happening for quite some time, people just didn't have the logs to notice until more recently.

                            That would explain it now. Thanks CMB

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.