15-Jan-2009

New kikd on the block?
Since last week, most rejected requests are the same sequence:

aaa.bbb.ccc.ddd - - [11/Jan/2009:21:37:14 +0100] "GET /nonexistenshit HTTP/1.1" 302 341
aaa.bbb.ccc.ddd - - [11/Jan/2009:21:37:15 +0100] "GET /mail/bin/msgimport HTTP/1.1" 302 341
aaa.bbb.ccc.ddd - - [11/Jan/2009:21:37:16 +0100] "GET /bin/msgimport HTTP/1.1" 302 341
aaa.bbb.ccc.ddd - - [11/Jan/2009:21:37:17 +0100] "GET /rc/bin/msgimport HTTP/1.1" 302 341
aaa.bbb.ccc.ddd - - [11/Jan/2009:21:37:18 +0100] "GET /roundcube/bin/msgimport HTTP/1.1" 302 341
aaa.bbb.ccc.ddd - - [11/Jan/2009:21:37:19 +0100] "GET /webmail/bin/msgimport HTTP/1.1" 302 341

It seems a new scripts has become available. It won’t work here, and if I had this type of software, I would disable it immediately. Still to find out what package that may be; ot it’s somewhat standard.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.