What does this look like?
Hello,
I am running a Linux box with Apache on it (version isn't an issue). While checking my logs I see this:
Feb 9 19:04:04 ny-kenton2a-529 sendmail[2164]: NOQUEUE: [OFFENDING IP ADDR] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
OFFENDING IP ADDR - - [09/Feb/2002:19:03:36 -0500] "HEAD%00 /%20HTTP/1.0%0D%0A%0D%0AAccept%3A%20vsjummyqbwufbcyvaxp/../../index.html%3fpqjhoivgit=/../mcjlprufiigzrspoqudevbynikiecgmzysftljbiwfzzyhpxqfnumtlnvadfsmaycehabwutinycnrdtmgmzerbmnodsiqnjvebqtdxmphdshagpusiklqrrquomwpqekwwroiipmkarrokxayciaypzwzszlxqbwrtsiloiabltjcpmptagmmnkwypdrsckadholdzrqgohjmigfzloavpkquvzyxvgpwjvtptzcsqujrruqmzwwfsijwjedxvfsxrgnhqxejkjnvlqasaximlhinsnbitiseijedvoauhjhnhdlycacwejikqurznspealkokimyhalpnzkbybgrnxfbblfktuexhkeloiympgqslbcyiaegdukjhnxwotdqyavfovpbrlhtvqwnzdwebbxqsjxppynhbhsrxmzdsqgmuiemhkuyejgnxybfxzavcmbgfmvositlszvnrzhderrzvfyaxaoozkzjyrepdeyycfjcnpbyxtqzdwaaxseqlzfjbchjctnnvfmzklemuakapeiyxnwaoonajmdgkmphixbfkollzcllatpuzonhbiehdvozabauaggvhddtxdsmanuvijugdreinsjthkelvepjbqqvomrvhwbxgyrmvvrgrnctvvnvztpnnhdpyertacouvocdhgeqraannexfaqjzkkowtrybfzpfbeaycpucmjsjakfpbjzfwyexifhhlmgbdpkuxnxitpviwehsusjsnditzrgnmxecvwjmszselpxxqbwmfofhatesymrhzqlynoaqkiruavifygucktfgbaebamhkvgbuovhyungddlvjc!
tnblxdriyzdxduxelxqtwnwhxmfarooqjaapblcpfuxdmvrxfokzoqfkikiyjhttmmocymavafgilmxlipstwhbpobwavwgtpwyujsmlcewrvknpgegeciplwggjpqbptesuuschqziiwvovszkxlhquemcxsthwpludobbzcwtlvqubvopjlazduznvxazslpxbbkfcvmxqdayqzqdkvqoeutecjyndiytgefztcaysvgibrienyvzgxznuwldcssbwosexmjzquqrfuhjmflpndxuecdjtditblickanguoconjrxwikgqhabdulyhrbawkljdzrmgdmiattcbdegpzmodsctdldzckdbjhkonisiqcwamakylwimiloyhubomnwdntllgdbbmrszwaoigauxhghjbnwezfusyulwtgirtzmiegvpaihudzcdiqtokbbibrnoiiajvqjcloribmogqvhrjvonbxukbfnkpdwiyffjjxjcxspbcchziljhdhqrrbukzkozruzpaviordolztjwssquobzsojoaibixyfqhlmhqonvhllprheddgujqebxdpiulbadeabkitpcns/.././%57%53_%46%54%50%2e%49%4e%49 HTTP/1.0" 501 1942 "http://MY IP ADDRESS/" "Mozilla/4.7 [en] (Win95; U)"
I am not sure what to make of it.... Is it 2 separate log entries 1 for my smtp server and one for apache? It looks like someone tried a buffer overflow or something... It is in the log a few times... I blocked the IP block because the traceroute didn't tell me much except it might be a dial up account from Verio/Earthlink.
Any suggestion would be appreciated.
Bill