fI've been looking at Google's 404 returns and found these in many of the urls. The string found in the url is listed first:
what=style most of them Exact value only, or can what= have a suffix?
value=11 most of them Style ID? Any integer legal?
curl= return URL Intended values: relative path only, same-host URL only, or any URL?
curl=https://… encoded junk Should an absolute URL be accepted?
https3A2F2F / http3A2F2F fake encoding of :// Used anywhere in UBB?
strnum= some curl= targets UBB parameter, or only on the spam sites?
showflat, showprofile, newuser, login, etc I believe these are all legit strings.
I'm considering writing some rewrite rules that would return 410. What I need to know is, are any of these strings used in the software. If so, how? That will help me write the rules so I don't reject legitimate traffic.