Only noticed this today, possibly because there is not much bad traffic around at the moment so the security logs are easier to read. Or it could be new today.
Three hits today with excessively long REFERER fields; I say excessive, about 260-270 bytes, which I deem excessive.
My database (MySQL) is set to a Notes field length of TINYTEXT (255 bytes) which so far, in over five years, has not, as far as I know, recorded an error. Today these three REFERERs caused database errors due to length.
Time of accesses were spaced reasonably and do not appear to have been a concerted "bot" activity; they came from 3 different broadband ranges (Zen, BT and Opal/Carphone, all UK). The source machines could, of course, have been compromised but the target sites seemed appropriate. They were all logged by my system as "Bad Referer" although it will take me a while to figure out what was bad about them.
Listed below as UA and REFERER (domains and actual pages obscured by me, which has reduced the actual byte-count slightly)...
Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
htt
p://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=5&ved=0CDMQFjAEahUKEwiK6tfR0dXHAhWHiw0KHVqiDaI&url=http%3A%2F%2Fwww.example1.co.uk%2Fpage.asp&ei=VX_lVcrrHIeXNtrEtpAK&usg=AFQjCNEyhi5S8TW-bMTqCJ11FwHWnlggBg&sig2=pGBe9At0GNC3YroQyk--2Q/page.asp
Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
htt
p://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=1&ved=0CDsQFjAAahUKEwjD7fmg3dXHAhUEcRQKHQ24BlM&url=http%3A%2F%2Fwww.example2.com%2Fpage.asp&ei=hIvlVcObHoTiUY3wmpgF&usg=AFQjCNEclI--EmO7YfdvSDutp_oMdO2OyQ/page.asp
Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko
htt
p://www.google.co.uk/url?sa=t&rct=j&q=&esrc=s&source=web&cd=11&ved=0CGIQFjAKahUKEwixuoCYr9bHAhXqF9sKHfF_AVc&url=http%3A%2F%2Fwww.example3.com%2Fpage.asp&ei=beHlVfHPGuqv7Abx_4W4BQ&usg=AFQjCNEclI--EmO7YfdvSDutp_oMdO2OyQ&sig2=CZkS3Fh-0F32SsOlc_EAIw/page.asp
All Trident 7 browsers from two different Windows OS's (but three actual machines judging by IP).
Does anyone know if G has extended the REFERER byte-count? Note they are not HTTPS; had it been I doubt I would have seen ANY proper REFERER.
[edited by: Ocean10000 at 12:21 am (utc) on Sep 2, 2015]
[edit reason] Unlinked [/edit]