I detected some attack payload for web application. GET //..;/my.key HTTP/1.1 GET //..;/id_rsa HTTP/1.1 So I want to know why attacker request with semicolon.