I looked at my recent logs (about 20 megs) and I could not find anything like this.
I suspect that some software looks at incoming data for google type strings and might let it pass. This might be an attempt to avoid detection by trying to look like google.
Google puts search strings and other parameters on the end of the url when you come in via the google search engine. It might be something like that.
Perhaps someone has seen this?
Keith
Thread Starter
k0872
(@k0872)
Thanks a bit more infor to clarify
for example my site is called http://www.big.com with a sub dir called /small
in the stop spammerlogs it shows reason for block was Bad cache, and the script was
/small/www.google.com
or
/www.google.com
after recent update to many spammer in comments
below is comment
google
Want to see what what it feels like to have a million dollars in bitcoins. My bitcoin donation address is 3FsNSHj1HTvmTiKdr7NAFBpUo7CGVgsHNe [email protected]
google.com
108.162.254.130 ip in range
is any problem in release?
Thread Starter
k0872
(@k0872)
kridangan
this is not in comments this is in the backend logs, yours is a seperate issue
ok i will open new ticket 😉