Forum Moderators: DixonJones

Message Too Old, No Replies

Big Brother is Watching

Has anyone else seen this?

         

zoidberg

7:45 pm on May 9, 2002 (gmt 0)



Has anyone seen anything like this in their log files lately?

209.47.5.34 - - [09/Apr/2002:18:37:55 -0700] "GET /forum/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/website_styles.css HTTP/1.0" 302 295 "-" "****" www.mywebsite.com

I noticed it when I got around 50000 404's in the log report. It looks like some out of control spider. It just tags on another "/CSS" and tries over and over again.

Did a lookup on the IP and it comes out as belonging to:

Software Connectus - G.O.C (NETBLK-NET-SOFTCONUU1)
P.O. Box 9732, Station T
Ottawa, ON K1G 4G4
CA

It's the main mailing address for CSIS - The Canadian Security and Intelligence Service (Canadian CIA). Scary stuff. (Especially since I trace-routed them a couple of times before I figured out who it was!)

I am the webmaster for a Canadian business, so I wonder if they are just targeting us, or if others have been getting it too?

JayC

7:56 pm on May 9, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hmm... the scariest thing might be that the Canadian Security and Intelligence Service isn't technically astute enough to write a functioning web spider! :)

I just checked the April and May logs for my one Canadian client, a sports-related website, and don't see it there.

EliteWeb

8:00 pm on May 9, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



EH? ;)

brotherhood of LAN

8:05 pm on May 9, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



lol, its like trying to find the most difficult way on Earth to steal someones CSS, only to learn it ;)

Everyman

8:06 pm on May 9, 2002 (gmt 0)



Well, you're right about the PO box address belonging to CSIS. They used to order database disks from us before the Web started, and they used the exact same address. The addressee's name on top was the "C.S.I.S. Information Centre" instead of "Software Connectus" when they ordered from us.

I checked my logs going back a few months and I don't see any 209.47.5.* in them. It looks like their block is 209.47.5.32 - 209.47.5.63.

I'm in the U.S.; perhaps they'd be inclined to ask their U.S. counterparts as a courtesy before they start spook-surfing on U.S. sites.

Sleep tight!

zoidberg

3:01 am on May 10, 2002 (gmt 0)



Thanks for checking guys.

It makes me wonder what we did to deserve the attention. It's not like the site is controversial or anything.

Looks like my only course of action now is to .htaccess redirect the whole net-block to goatsecx, and wait for the black helicopters to come for me. ;)

keyplyr

9:01 am on May 10, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Stuff like: CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS/CSS

occurs as a write glitch at my server logs occasionally. Sometimes it is:

xx.x.xx.x.x - - [time_here] "GET /javascript/javascript/javascript/javascript/javascript/javascript/javascript/javascript/javascript/javascript/javascript/javascript/blah_blah.js HTTP/1.0" XX XX"-" "****" www.mywebsite.com

Other times it starts just repeating once or twice and then works up to a dozen or more, then stops. The time is always the same so I understand this just to be a glitch.

Mark_A

9:43 am on May 10, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Hey guys big brother has always been watching you and you should want him to, he is using your tax dollars to protect you from ... well others and yourselves :-)

Way back when, I started always to notice US military domains in logs from all websites that I have delved into, what any soldier would want with some of them I have no idea, you dont see UK military in your logs because our spooks don't identify themselves quite so readily :-)

Of course they don't need to as they are hard wiring themselves into UK ISPs.

There is no getting away from it, one of the first things any government does with its taxpayers money is spy on its own taxpayers.

"Life's a bitch"
Dont let your paranoia get you down.... Or of course move to Palestine or Israel, places where paranoia probably would be justified! :-)

backus

9:57 am on May 10, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I have a friend who ran a site about the book Spycatcher. He also traced a spider, but to MI5. Quite funny really. Scared him sh*tless though, so much so that he deleted the site. Also, during the communist times, we used to send and receive letters to/from my gran in the then Czechoslovakia. Every one of our letters had been opened. We used to here clicks and echos on phone calls to Czechoslovakia, it was really freaky. Then I read Spycatcher and learned all about GCHQ.