I keep seeing the following (and similar) in my logs:
61.8.106.## - - [15/Dec/2008:20:39:35 -0500] "GET /article-1217000013.html HTTP/1.0" 200 4598 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
61.8.106.## - - [15/Dec/2008:20:39:36 -0500] "GET /manager/includes/veriword.php?rand=893135230 HTTP/1.0" 200 3049 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
61.8.106.## - - [15/Dec/2008:20:39:41 -0500] "POST /article-1217000013.html HTTP/1.0" 200 4691 "
http://www.mcaraweb.com/article-1217000013.html" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"
and of course I get the spams in my mailbox- they are not published but are random nonsense characters. I suspect they are test of a botnet as I have them from mulitple networks. Have I missed an open expolit issue or is this some new exploit? Have any of you other users seen this?
Thanks and Best regards,
Bill