»

What is Apache Synapse - User-Agent Mozilla/4.0 (compatible; Synapse)

 +
What is Apache Synapse - User-Agent Mozilla/4.0 (compatible; Synapse)

Would you share this article with others to help inform them?

I kept getting the error below in my ASP.net application whenever a request is made to my website with the name 'Synapse' in the HTTP request header User-Agent string. I googled this name and found some interesting articles that claimed that Synapse is a form of SQL Injection tool that probe the internet looking for vulnerabilities. But, this is a crawler that is actually used to post spam to websites through HTML form input.

The Error Generated when Synapse makes a Request to my Website

Invaild ViewState Error

The input is not a valid Base-64 string as it contains a non-base 64 character, more than two padding characters, or an illegal character among the padding characters.
======

The request contains the following User-Agent string: 
User-Agent Mozilla/4.0 (compatible; Synapse)

The invalid viewstate is generated when data is submitted to a website by a service created by piece of software called Apache Synapse

What is Apache Synapse?

In a nutshell, this is a free and open source software that provides services that have the ability to post data to websites it crawls.  You can click here to read more about it.

The service is commonly used in an abusive way by cybercriminals to post spam to websites that take HTML form input. The service seems to mainly target ASP.NET web forms and seems to be one of the main tools used for ASP.NET spamming, since it can send pre-configured viewstate values. 

In the case of the "Invaild ViewState" error message, the service sent a "-1" as the value for viewstate. Spammers use this value and long strings of random characters in an attempt to get past the viewstate errors, and this is what generates those failed ViewState, Base64 or MAC error messages.

For ASP.net webmasters, it is recommended that you do not turn off “EnableViewState” by setting it to false. By default, this feature is enabled and is also recommended by Microsoft that it should be turned on in a production environment.

This is because this feature actually prevents malicious crawlers and other tools used by hackers from tampering with the ASP.net viewstate.

Thanks to Chris Porter at ASP.net for this information.

Note: Some of the names, addresses, email addresses and telephone numbers in email samples on this website may have been impersonated.

Please share what you know or ask a question about this article by leaving a comment below. Also, check the comment section below for additional information, if there is any.

Remember to forward suspicious, malicious, or phishing email messages to us at the following email address: info@onlinethreatalerts.com

Also, report missing persons, scams, untrustworthy, or fraudulent websites to us. Tell us why you consider the websites untrustworthy or fraudulent.

If you want to quickly find answers to your questions, use our search engine.

You can help maintain Online Threat Alerts by paying a service fee. Click here to make payment.

Comments, Questions, Answers, or Reviews
(Total: 0)

To help protect your privacy, please do not post or remove, your full name, telephone number, email address, username, password, account number, credit card information, home address or other sensitive information in or from your comments, questions, or reviews. Also, anonymous posts cannot be deleted or edited, and when you make a post, we will use your IP address to display your approximate location to other users.

Write Your Comment, Question, Answer, or Review
Write your comment, question or review in the box below to share what you know or to get answers. Please revisit after an hour or more to view reponses or answers to you questions.

Your comment, question or review will be posted as an anonymous user because you are not signed in. Sign-in.

What is Apache Synapse - User-Agent Mozilla/4.0 (compatible; Synapse)