This email arrived today at abuse@
Hi, I just noticed some weird stuff in our logfile: wiki.lll.lu:80 185.15.56.1 - - [28/Dec/2023:20:36:04 +0100] "GET /api.php?action=query&meta=siteinfo&siprop=statistics&format=php&maxlag=5 HTTP/1.1" 200 713 "-" "${user_agent}" wiki.lll.lu:80 185.15.56.1 - - [28/Dec/2023:20:36:05 +0100] "GET /api.php?action=query&meta=siteinfo&format=php&maxlag=5 HTTP/1.1" 200 2804 "-" "${user_agent}" [Thu Dec 28 20:36:05.244793 2023] [proxy_fcgi:error] [pid 1757738] [client 185.15.56.1:54274] AH01071: Got error 'PHP message: PHP Warning: is_readable(): open_basedir restriction in effect. File(/gitinfo/info.json) is not within the allowed path(s): (/var/www/html/:/etc/:/usr/share/php/:/usr/share/mediawiki/:/var/lib/mediawiki/:/var/www/mediawiki/) in /usr/share/mediawiki/includes/GitInfo.php on line 173 What is going on here? Shouldn't the ${user_agent} string be replaced with the actual bot's name? And what why is it probing for Git? (which we don't use) Thanks, Alain
This does not seem malicious or damaging but it would be nice to locate the source of this traffic and help them out with string substitution.