Malformed requests
Someone tries to send a request no ordinary browser would send.
What it is
Requests that break the rules of how browsers and servers talk: conflicting lengths, forbidden characters, headers smuggled inside other headers.
- Two different lengths for the same request (request smuggling)
- A hidden character that ends the address early
- A method your site never uses
Why it matters
A request built this way is usually a tool probing for a server that gets confused, so that one visitor's request can be passed off as another's.
If a real visitor is ever stopped
This is most often an app or a script, not a person in a browser. If it is a tool you run yourself, mark the request as real and it will be let through.