    Good day to all.
    Since no response has been received from the service owners in a reasonable amount of time, I am writing here.
    Briefly the essence and purpose of the post: log.txt is bad. Do not forget about this and often (e.g. right now) check your projects.
    UPD 3: There was an unpleasant default in older versions of bitrix: bitrix / php_interface / (dbconn | init) .php - the LOG_FILENAME constant, which you guessed leads to the described problems.

    Obvious statements:
    • logs are better to write through one hmm ..., for example, a function
    • in a dedicated folder
    • with a special extension or other features for simplicity and versatility blocking access via the web
    • ...

    And yes, from throwing tomatoes of the type * - * but please refrain, all the same, nothing critical has been merged, only emails and secret applications for social networks.

    In short, there were SQL queries in the log that failed. From the logs it was possible to find out some parameters of the site (secret parts of keys for social networks), of course, paths with the error trail, user emails and some personal information (Name / surname, checkword for password recovery) that could be used for phishing.

