Re: Chinese HTTP ACKs

From: Frank Knobbe (frank_at_knobbe.us)
Date: 02/09/05

  • Next message: Peter Kerr: "Re: Chinese HTTP ACKs"
    To: gillettdavid@fhda.edu
    Date: Wed, 09 Feb 2005 16:13:53 -0600
    
    
    

    On Wed, 2005-02-09 at 10:08 -0800, David Gillett wrote:
    > I'm seeing a handful of addresses in the 61.143.210.0/23 space
    > periodically send 2-3 ACKs from port 80 to semi-random addresses
    > within our Class B space. The TCP checksum on these packets is
    > incorrect.
    > [...] Anybody else seeing similar?

    Not quite. However, we have observed the Sohu Search engine
    (www.sohu.com) doing some funky stuff. It checks existing pages and
    non-existing pages (like /abcdefghijklm.html) with GET and HEAD
    requests. In those requests are tons of really funky cookies. At first
    glance, I thought the search engine has gone bonkers, or was badly
    coded. However, certain traits seem more purposeful (like checking for
    the non-existing page). It appears more of a fingerprinting/recon than a
    spidering of an existing site.

    Oh, and they also performed proxy checks (trying GET http://www.sohu.com
    against the tested hosts). Not really a feature of a search engine
    either :)

    These accesses were observed from 61.135.131.0/24 and 220.181.26.0/24.

    You might want to keep an eye on those subnets. Has anyone else noticed
    attempts from Sohu or has some more information he can share here?

    Cheers,
    Frank

    
    



  • Next message: Peter Kerr: "Re: Chinese HTTP ACKs"

    Relevant Pages

    • Google rebuffs U.S. govt demand for search data
      ... The government wants a list of all requests entered into Google's search engine during an unspecified week. ... The White House also wants one million randomly selected Web addresses from various databases of the world's leading search engine. ... Google refused to comply, prompting U.S. Attorney General Alberto Gonzales this week to ask a judge for a court order to force a handover of the requested records. ... The Bush administration says it needs the information in order to revive the 1998 Child Online Protection Act which was struck down by the U.S. Supreme Court on grounds it violated the First Amendment. ...
      (alt.gathering.rainbow)
    • Google CGI API
      ... Has anyone knowledge of the same of the Google API which will enable me send ... algorithm to parse the returned values for the prices and compare them. ... you'll be able to send SOAP requests ... Depending on the search engine, ...
      (perl.beginners)