Hello,

some of our users noticed, that lines like this appear in their logfiles:

58.187.78.42 - - [14/Mar/2010:04:38:53 +0100] "8\r\xff" 400 226 "-" "-"

This has been noticed be different customers on different servers. I know that the Referer and Useragent may be empty (shown by the dash), but URI part should at least start with GET or POST.

I found nothing with Google on "8\r\xff" but it seems that something is talking to our servers with invalid HTTP. Is "8\r\xff" used to exploit a webserver, but it simply didn't work out on our servers? Has anyone else noticed such entries in the logfiles?

Kind regards
Marten

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org
  "   from the digest: users-digest-unsubscr...@httpd.apache.org
For additional commands, e-mail: users-h...@httpd.apache.org

Reply via email to