Forum Moderators: phranque

Message Too Old, No Replies

Getting bad GET request from a user

There is a carriage return before the GET

         

AWildman

6:30 pm on Apr 30, 2004 (gmt 0)

10+ Year Member



What might possibly cause a computer to send a GET request that is preceded by a carriage return? The log shows "\rGET" for this particular user. I suggested running a spyware removal program, but I'd like to know what in particular migt cause this.

This user is running MacOS X with IE 5.2.3

jdMorgan

6:56 pm on Apr 30, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



There's no carriage return before GET. That machine is either infected with a badly-written scripted "virus", or the owner of that machine is trying to get at your content with a script.

Jim

AWildman

7:36 pm on Apr 30, 2004 (gmt 0)

10+ Year Member



Thanks for the info!

How likely is it that a Mac has a virus? I'm not very familiar with Macs, but I thought they were pretty virus resistant.

jdMorgan

8:17 pm on Apr 30, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Macs have security problems, too. But there are not as many of them out there, so virus-writers tend to target PCs more often -- more PCs = more "fame" in their minds. Only recently have *nix and Mac viruses garnered much notice.

Jim

AWildman

8:34 pm on Apr 30, 2004 (gmt 0)

10+ Year Member



Ah. Makes sense. Well, I guess its time for me to take a different approach to searching for a solution. Up till now, I've been looking for general info on bad GET requests. I guess now I'll look for Mac viruses.

Thanks a bunch.

drbrain

8:34 pm on Apr 30, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Are you sure its from a Mac? They could simply be spoofing the user-agent string, I recently found a referrer spammer with a UA of "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98" (note the non-matching parentheses).

AWildman

8:46 pm on Apr 30, 2004 (gmt 0)

10+ Year Member



No, I've talked to the user and its definitely a Mac, which is why we didn't think to tell her to run a virus check right away. I suggested running a spyware removal tool on the affected machine.

jdMorgan

9:35 pm on Apr 30, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



If this person is having problems with other sites as well (and I'd suspect she is, since \rGET is not a valid HTTP request), then a virus/spyware scan is first priority. I'm not sure what's availabel for Macs, though.
Next would be a re-install of IE5 [microsoft.com].
Finally, if that doesn't work, I would suggest she download an alternate Mac browser [darrel.knutson.com] such as Firebird, Safari, etc.

Jim

AWildman

11:52 am on May 3, 2004 (gmt 0)

10+ Year Member



Thanks for all the help! I think I'll have her fill out a form on another one of our sites to see if she has the same problem with that site as well.
Then I'll suggest a reinstall. Unfortunately, she can't change browsers cause our program is only compatible with IE and NN. I know, I know. But I didn't make the program...