Hi Jim,
I found this set of requests over and over again in my server logs yesterday and today. I blocked the IP because I didn't know what it was trying to do and it looked suspicious. Here are the set of requests:
216.56.15.nnn - - [05/Oct/2010:08:31:21 -0400] "PROPFIND /apicture.jpg HTTP/1.1" 403 327 "-" "-"
216.56.15.nnn - - [05/Oct/2010:08:31:21 -0400] "HEAD /apicture.jpg HTTP/1.1" 403 - "-" "-"
216.56.15.nnn - - [05/Oct/2010:08:31:21 -0400] "PROPFIND /apicture.jpg HTTP/1.1" 403 327 "-" "-"
216.56.15.nnn - - [05/Oct/2010:08:31:22 -0400] "HEAD /apicture.jpg HTTP/1.1" 403 - "-" "-"
216.56.15.nnn - - [05/Oct/2010:08:31:22 -0400] "GET /apicture.jpg HTTP/1.1" 403 327 "-" "-"
It was looking for a picture, the same one over and over. I'm not sure what PROPFIND is used for. I've never see it before and saw a number of different ideas in Google search. One was that it was an exploit. I would appreciate your expert opinion on this. Thank you.
Jeannie