I'm getting a bunch of strange traffic on my webserver (apache 2.0.40 running on Redhat 8) and want to know if anyone else is seeing this kind of thing.
Since early morning august 18th I've been getting hits from all sorts of different IP's but they all behave in exactly the same way. They look legitimate: 24.33.140.25 - - [22/Aug/2003:15:06:28 +0000] "GET / HTTP/1.1" 200 686 "-" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)" Except only one hit appears. People accessing the root at my webserver should receive 5 files so a legitimate visit will appear as 5 rows in the access log. None of these do. They all look identical except for the IP number. It hasn't caused any noticeable problems but if this is some sort of worm that's all of the sudden going to send a million of these requests at the same time, it would be nice to be forwarned. Pall Thayer artist/teacher Fjolbrautaskolinn vid Armula http://www.this.is/pallit http://www.this.is/pallit/isjs http://www.this.is/pallit/harmony http://130.208.220.190/panse -- SLUG - Sydney Linux User's Group - http://slug.org.au/ More Info: http://lists.slug.org.au/listinfo/slug
