QUOTE(rconner @ Aug 31 2008, 03:01 PM)

Do you have httpd_access logs to look at? As Farelf says, might be a search-engine spider gone nuts, or even something like a referral spammer.
That would be the 130+ Meg file I've been searching through for signs of an exploit that caused the release of a security patch for versions 2.2x and 2.3.x, trying to sort out whether this 2.1.x version might be attackable or not.
As far as activity on that day, the only oddity I've come across is a visit by a bot from
http://www.attributor.com/ which seems to be somewhat akin to what cyveillance was up to. What I find odd is that this search enging only hit that one day (25 Aug) ... has yet to return. The real spin on that bot's visit was the massive bloat to the error.log file while looking for lofi pages that didn't exist ... which caused some more searching trying to sort out just where those links might have been coming from/located. Basically gave up on researchin gthat stuff, going back to trying to find the exploit evidence. Interrupted by being needed elswhere for quite a while.