Forum Moderators: DixonJones
Something strange has happened over the past few days though, they are getting a varierty of attacks from all over the world - extremely diverse ip ranges - with the exact user agent "Mozilla/?" (actually two? but forum software strips the 2nd)
Now I don't think any known version of any browser uses that user agent so it can be blocked, but more importantly is someone using a virus to cause innocent dialup and broadband users to do this formmail check for them? I am sure many of you have read about the IRC bots that trigger and collect data from other kinds of world-wide attacks on command, is this a new variation created by spammers?
1) They are routing through proxies which mask the true origin, each request uses a different proxy in order to make it harder to automatically block. Given that they are formmail hunting this strategy makes sense.
2) There is a new version of "application X" available which is being widely used (would account for a growth in traffic rather than a surge), a classic example of this are requests from the "Fetch API Request" which is part of ISA Server - they are many, varied and distributed globally.
- Tony