Forum Moderators: DixonJones
2003-02-24 00:36:23 212.239.37.18 - W3SVC2 TELA 192.168.10.43 80 HEAD /blahblah - 404 2 144 25 31 HTTP/1.0 - - -
I have traced the IP address back to a .it source.
Anyone got any ideas about what this is trying to do?
You see it all the time from spammers/script kiddies/robots. If you saw it on multiple machines, it's probably some idiot scanning ip blocks hoping to find easy targets. It is amusing though when they are too lazy to even come up with a request that even looks semi-legitimite.
Unless your machine in question is hosting a "high-profile" site like microsoft or AOL, I doubt someone is specifically targeting your server, but you never know. One good way to tell if it is an automated scanner is if you see the same scan profile across multiple servers one after the other in quick succession.
Yeah the blahblah is strange, but you'll see stuff like that every once in a while (like the "GET /Sumthin" scan). If your machine is updated and secure, I wouldn't lose sleep.