Today's Odd Web Requests, (Wed, Apr 29th)

📡 SANS ISC · 2026-04-29

Today's Odd Web Requests, (Wed, Apr 29th)

Today's Odd Web Requests

Today, two different "new" requests hit our honeypots. Both appear to be recon requests and not associated with specific vulnerabilities. But as always, please let me know if you have additional information

1 - Broadcom API Gateway

GET /bam/restart/if/required

Host: [redacted]:8080

Connection: close

This request is targeting a Broadcom API Gateway endpoint. As is, the request should not cause any problems, but the response may indicate if a Broadcom API Gateway is used, and it could lead to follow-up attacks.

2 - ESP32

GET /esps/

host: [redcated]:8080

user-agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36

connection: close

accept: */*

accept-language: en

accept-encoding: gzip

The path "/esps/" is associated with ESP32 devices. The ESP32 platform is a low-cost system-on-a-chip (SOC) device that is frequently used in IoT devices or even in various home automation projects. The URL '/esps/' may be associated with uploading firmware, but I have not yet seen any follow-up attacks.

--

Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu

Twitter|


📌 来源: SANS ISC | 📅 2026-04-29

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)