Ralf Hildebrandt wrote:
* Ralf Hildebrandt <Ralf.Hildebrandt@xxxxxxxxxx>:
I'm seeing a continuous stream of POST requests to Akamai IP space:
10.47.88.65 266040 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/13
10.47.88.65 267796 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/14
10.47.88.65 128319 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/14
10.47.88.65 256728 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/15
10.47.88.65 207705 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/23
10.47.88.65 126901 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/24
10.47.88.65 156025 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/28
10.47.88.65 137205 POST http://87.248.217.42/idle/OhTmbD8nS1BmeTWY/29
10.47.88.65 239690 POST http://87.248.217.43/idle/atumbD8nb1JG2eub/33
What IS this? I know about akamai, but POST? Usually they're
distributing DOWNLOADS, not uploads. What is going on here?
I'm seeing this from different IPs in my net.
Could be a lot of things, from some new online game to a virus.
Can you grab a tcpdump of some of these requests?
Amos
--
Please be using
Current Stable Squid 2.7.STABLE7 or 3.0.STABLE21
Current Beta Squid 3.1.0.15