识别格式错误的 URL 的来源
我们偶尔会在 Web 应用程序日志中收到错误,指出 URL 请求格式错误。 URL 本身看起来像这样:http://{sampledomain.com}/
。
作为 URL 的一部分包含在内。
该请求似乎来自 Firefox 3.6.17 和 Firefox 3.0.19。这种行为似乎并不普遍,但可能只是来自我们的几个用户。
不带
的 URL 中存在的默认页面是经过 w3c 验证器验证的有效 XHTML 1.0 代码,并且这些请求的标头中没有引用者。
我们一直忽略这些错误,但我很好奇它们为什么会发生。它们不应该通过网站的正常导航发生,而且它们看起来并不像是探测漏洞的恶意请求的一部分。有谁知道为什么会发生这种情况以及我们可以采取哪些措施来防止这种情况发生?
We occasionally get errors in the log for our web application saying that a request for a URL was malformed. The URL itself would look something like this: http://{sampledomain.com}/<br>
. The <br>
is included as part of the URL.
It appears that the request is coming from Firefox 3.6.17 and Firefox 3.0.19. It also appears that this behavior isn't widespread, but perhaps coming from just a couple of our users.
The default page that exists at the URL without the <br>
is valid XHTML 1.0 code as verified by the w3c validator, and there is no referrer in the header for these requests.
We've been ignoring these errors, but I'm curious why they occur. They shouldn't occur through normal navigation of the site, and they don't really seem like part of malicious requests to probe for vulnerability. Does anyone know why this happens and what we could do to prevent it?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
我收到了另一个相同格式的错误,但它有一个引用: http:// app.bluetie.com/ca1759d5/gds/index_rich.php。我假设这些格式错误的 URL 来自某种链接创建快速致富计划,并且只是努力阻止它们。它们似乎不是来自在我的网站上执行正常操作的用户。如果有人有更多的见解,我仍然可以选择他们的答案来结束问题,但否则,我将在几天内用这个答案结束问题。
I received another error of the same format, but it had a referrer that says: http://app.bluetie.com/ca1759d5/gds/index_rich.php. I am going to assume that these malformed URLs are coming from some kind of link-creating get rich quick scheme and just work to block them. They don't appear to be coming from users doing normal things on my site. If anyone has additional insight, I may still choose their answer to close the question, but otherwise, I'll close the question with this answer in a couple of days.