Re: New (to me) apache error...

From: Dave Ahmad (da@securityfocus.com)
Date: 10/25/02


Date: Fri, 25 Oct 2002 11:24:22 -0600 (MDT)
From: Dave Ahmad <da@securityfocus.com>
To: "Kevin D. Kinsey, DaleCo, S.P." <kdk@daleco.biz>

Kevin,

24.112.227.167 is attempting to proxy a connection to
mx1.mail.yahoo.com:25 through your HTTP server.

See:

http://online.securityfocus.com/bid/4131

David Mirza Ahmad
Symantec

0x26005712
8D 9A B1 33 82 3D B3 D0 40 EB AB F0 1E 67 C6 1A 26 00 57 12

On Fri, 25 Oct 2002, Kevin D. Kinsey, DaleCo, S.P. wrote:

> Hi, Gentlemen,
>
> This appeared in my apache error log today. Any thoughts?
> Malevolent code entered by a website user, perhaps?
>
> [Fri Oct 25 08:32:16 2002] [error] [client 24.112.227.167] request
> failed:
> erroneous characters after protocol string:
> CONNECT mx1.mail.yahoo.com:25 / HTTP/1.0
>
> Kevin Kinsey
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • proxy timeout
    ... Client sends a request from browser thru client proxy. ... Proxy has a 120 second idle connection timeout. ... Request hits remote Http server and cgi takes longer than 120 secs ...
    (comp.security.firewalls)
  • Re: Error 49, socket problem?
    ... If you have too many quick connections between proxy and backend, ... or between the http server and the SQL server then you may see ... has the connection with the same port in TIME_WAIT state. ...
    (freebsd-net)
  • Re: Banana Republic (was Re: OpenVMS Book Wins award)
    ... The graphed 'events' are individually and asynchronously provided from the server to the client over a persistent connection and each respective graphical element is equally asynchronously updated. ... However it can emulate asynchronous, raw network streams via a Web Socket server / raw IP network proxy. ... If you mean Web Sockets can't through existing HTTP proxy then the ...
    (comp.os.vms)
  • Re: Banana Republic (was Re: OpenVMS Book Wins award)
    ... other requests while it's streaming its long-poll (or words to that effect ... If you mean Web Sockets can't through existing HTTP proxy then the ... Orbited is a service used to accept Web-style socket connection ...
    (comp.os.vms)
  • Re: Banana Republic (was Re: OpenVMS Book Wins award)
    ... Isn't asocket proxy that doesn't explicitly talk HTTP during setup a one-to-one NAT router? ... And if accepting external connection requests, a static port mapping NAT router, into/through the DMZ and onto internal services? ... Of course it's a bit more than that Until Web Sockets become commonplace it uses a number of approaches to *emulate* asynchronous comms with current browsers. ... Mandatory Upgrade ...
    (comp.os.vms)