A client’s site has started to get hit with attempts to inject invalid data (SQL, email addresses, etc.) via apparent remotely generated shopping cart forms using a custom libcurl script and connecting with PycURL/7.15.5.
PycURL/7.15.5 is not something my client’s customer base would use to browse pages, so I have setup a script to run on all pages to redirect PycURL/7.15.5 browser requests to an alternate, non-JodoHost, domain.
Of course my client’s site already had protection in place on the client and server side for this kind of abuse, however, diverting this browser tpye to an alternate location should save server resourses and report generation.
You may want to check your site(s) for this type of abuse.
If so we have been seeing huge botnets hit various IPs on it very hard all from asia, sometimes many hundreds at a time
Does the IP match to asia for you as well, but asia, I mean most of them china, india, pakistan, korea(south) etc
Oh and on wincf, they hit between 11pm EST and 4am EST VERY hard. Prakash has been continually battling them every single night adding blocks for the new ones coming in, etc.
I went back a few more days and yeah, most originate from China at night (US). The vast majority of my issues were from query timeouts, when they were hitting other sites, I assume.