@jimfuller @icing wondering if the attacker went into the trouble of actually using these versions, or just spoofing the user agent with valid versions. Logged HTTP and TLS versions may help spotting impossible combinations.
I actually don't have more insights myself, but no one has said anything about these being exceptions, special or attacks. Just showing the curl use on these sites a random day.
Inspired by the BBC Tech report from @tdp_org, I looked at Wikipedia.
Yesterday, Wikipedia received over 45 million requests made with curl, from 113 distinct curl releases.
Of these, 32 million use the default UA (e.g. curl CLI). The other 13 million embed libcurl with a longer UA string containing curl (e.g. GuzzleHttp/PHP, PycURL, UnityPlayer)
Stefan Eissing
in reply to daniel:// stenberg:// • • •It wasn‘t me, @vsz or @jimfuller! We don‘t know who did this!
Someone is leaking curl versions to the outside…😰
Jim Fuller
in reply to Stefan Eissing • • •vsz
in reply to Jim Fuller • • •Jim Fuller
in reply to vsz • • •daniel:// stenberg://
in reply to Jim Fuller • • •vsz
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to vsz • • •Timo Tijhof
in reply to daniel:// stenberg:// • • •That's right, just a random day!
mastodon.social/@tdp_org/11505…
fosstodon.org/@krinkle/1150988…
Timo Tijhof
2025-08-27 04:21:48