w00t?
Tuesday, March 25th, 2008
Today I noticed this in my access.log:
-
67.19.113.154 - - [24/Mar/2008:16:02:10 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
-
65.111.181.35 - - [24/Mar/2008:20:02:22 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
-
67.19.113.154 - - [24/Mar/2008:20:15:38 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
-
67.19.113.154 - - [25/Mar/2008:00:26:37 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
-
67.19.113.154 - - [25/Mar/2008:04:37:39 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
-
…
-
67.19.113.154 - - [25/Mar/2008:08:52:25 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
-
67.19.113.154 - - [25/Mar/2008:13:05:07 +0100] "GET /w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" 400 363 "-" "-"
What goes on here?
All these requests fail, ofcourse, but in addition to the obvious (404), the client also doesnt supply a Host: header for their HTTP/1.1 requests
update
It is safe to assume that this is an attempt to hack me in some way, DFind is appearantly some kind of security scannerref. The same IPs are also bruteforcing some URLs (like /phpmyadmin etc..) looking for somthing fun to poke around with.
Tungtvann :: Æ E (Kløvermix)


