Pete
2004-08-29 20:14:11 UTC
I'm curious if anyone knows details of a phenomenon that shows up
in our 404 log at irregular intervals.
There will be a sudden 'storm' of POST requests from different hosts,
each requesting a different mail service, like 'cgi-bin/formail.pl'
or 'mail.cgi' and so on. There will be anything from a few to 30 or 40
requests within about one minute. Our server doesn't in fact *have*
any of these facilities, so no damage is done, but it is obviously
of nefarious intent...
As I say, each request is from a different host -- apparently scattered
randomly around the world -- and each request is (mostly) for a different
app. My assumption is that these are all poor zombies, with coordinated
strings being pulled by some puppetwebmaster somewhere unseen.
Anybody know more? Any action that is useful to take?
-- Pete --
in our 404 log at irregular intervals.
There will be a sudden 'storm' of POST requests from different hosts,
each requesting a different mail service, like 'cgi-bin/formail.pl'
or 'mail.cgi' and so on. There will be anything from a few to 30 or 40
requests within about one minute. Our server doesn't in fact *have*
any of these facilities, so no damage is done, but it is obviously
of nefarious intent...
As I say, each request is from a different host -- apparently scattered
randomly around the world -- and each request is (mostly) for a different
app. My assumption is that these are all poor zombies, with coordinated
strings being pulled by some puppetwebmaster somewhere unseen.
Anybody know more? Any action that is useful to take?
-- Pete --
--
============================================================================
The address in the header is a Spam Bucket -- don't bother replying to it...
(If you do need to email, replace the account name with my true name.)
============================================================================
============================================================================
The address in the header is a Spam Bucket -- don't bother replying to it...
(If you do need to email, replace the account name with my true name.)
============================================================================