I'm getting a bunch of strange traffic on my webserver (apache 2.0.40
running on Redhat 8) and want to know if anyone else is seeing this kind of
thing.

Since early morning august 18th I've been getting hits from all sorts of
different IP's but they all behave in exactly the same way. They look
legitimate:

24.33.140.25 - - [22/Aug/2003:15:06:28 +0000] "GET / HTTP/1.1" 200 686 "-"
"Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"

Except only one hit appears. People accessing the root at my webserver
should receive 5 files so a legitimate visit will appear as 5 rows in the
access log. None of these do. They all look identical except for the IP
number. It hasn't caused any noticeable problems but if this is some sort of
worm that's all of the sudden going to send a million of these requests at
the same time, it would be nice to be forwarned.

Pall Thayer
artist/teacher
Fjolbrautaskolinn vid Armula
http://www.this.is/pallit
http://www.this.is/pallit/isjs
http://www.this.is/pallit/harmony
http://130.208.220.190/panse

-- 
SLUG - Sydney Linux User's Group - http://slug.org.au/
More Info: http://lists.slug.org.au/listinfo/slug

Reply via email to