Hello, some of our users noticed, that lines like this appear in their logfiles: 58.187.78.42 - - [14/Mar/2010:04:38:53 +0100] "8\r\xff" 400 226 "-" "-"This has been noticed be different customers on different servers. I know that the Referer and Useragent may be empty (shown by the dash), but URI part should at least start with GET or POST.
I found nothing with Google on "8\r\xff" but it seems that something is talking to our servers with invalid HTTP. Is "8\r\xff" used to exploit a webserver, but it simply didn't work out on our servers? Has anyone else noticed such entries in the logfiles?
Kind regards Marten --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx