I don't understand this message. It looks like a phish, but the site just redirects you to gandi's actual site. Maybe it's browser-specific or something.
* About to connect() to barraplaza.com port 80 (#0)
* Trying 31.193.131.100...
* Connected to barraplaza.com (31.193.131.100) port 80 (#0)
> GET /sudoroom.org HTTP/1.1
> User-Agent: curl/7.29.0
> Host: barraplaza.com
> Accept: */*
>
< HTTP/1.1 200 OK
< Content-Type: text/html; charset=UTF-8
< Server: Microsoft-IIS/8.…
[View More]5
< X-Powered-By: PHP/5.6.31
< Date: Fri, 24 May 2019 08:06:21 GMT
< Content-Length: 65
<
<script>
window.location="https://gandi.net";
</script>
* Connection #0 to host barraplaza.com left intact
‐‐‐‐‐‐‐ Original Message ‐‐‐‐‐‐‐
On Thursday, May 23, 2019 9:53 PM, support(a)mail.gandi.net <mo7(a)basmaji.fr> wrote:
> Bonjour,
>
> Nous n'avons pas reçu le paiement sur votre dernière renouvellement du domaine sudoroom.org.
> Le solde reste endetté de 5,00 €.
>
> Pour éviter le problème, on vous invite à remplir manuellement le formulaire de renouvellement de
> vos services suivant les instructions et les étapes sur le lien ci-dessous:
>
> [Accédez à votre formulaire de paiement.](http://barraplaza.com/sudoroom.org)
>
> IMPORTANT : En cas de non règlement sous 48 Heure, votre compte pourrait être définitivement effacé.
>
> N'hésitez pas à contacter notre service client en cas de problème ou pour toute autre
> question : http://www.gandi.net/faq/contact_support
>
> Nous vous remercions de votre confiance.
>
> Cordialement.
>
> --
>
> GANDI - http://www.gandi.net/
[View Less]
The culprit was the php5-fpm process. Restarting it fixed it.
Error output from apache:
[Mon May 20 15:36:53.945158 2019] [proxy_fcgi:error] [pid 20480:tid
139913676658432] [client 50.57.61.7:62769] AH01067: Failed to read
FastCGI header
[Mon May 20 15:36:53.945213 2019] [proxy_fcgi:error] [pid 20480:tid
139913676658432] (104)Connection reset by peer: [client
50.57.61.7:62769] AH01075: Error dispatching request to :
Looks like someone set up some kind of status checker that locally
hits blah.…
[View More]sudoroom.org every second?
2019-05-20 15:39:45 127.0.0.1 blah.sudoroom.org "GET
/server-status?auto HTTP/1.1" 200
Was it supposed to inform us that sudoroom.org was down?
--
marc/juul
[View Less]
StatusCake Alert -- statuscake.com
Website Monitoring
Your website https://sudoroom.org has encountered an error.
Reason: Timeout / Connection Refused
To view more details about this error, log into your account now: https://app.statuscake.com/
A few minutes ago, there was a period of a few minutes when the Omni Commons WiFi network stopped working. I wasn’t able to gather any useful details about exactly what went wrong before it got better.
Sent from ProtonMail Mobile
I've now had two odd things happen from Omni over the past few weeks:
First I couldn't log into linkedin. Even accessing the site just
directed me to a weird warning page saying they don't allow Chinese
IPs and giving a phone number (?!) to call for support. At first I
thought it was because they had seen my computer from china, but then
I tried a clean browser which did nothing and then I tried through a
VPN which resolved the issue.
Then I couldn't log into NameCheap but I could reset the …
[View More]password
fine, and then I would just get the same "wrong username or password
message". After contacting support they told me that our IP had been
banned because someone had tried to log into many different accounts
from our IP unsuccessfully.
I'm beginning to suspect that we may have e.g. a rogue windows machine
on our network (could it be the one hooked up to the x-ray machine in
sudo? or one of the machines in CCL?)
Just wanted to put it out there in case we get more data.
--
marc/juul
[View Less]