Forum Moderators: open

Message Too Old, No Replies

New Trend Micro Shenenigans

changed HTTP_ACCEPT_LANGUAGE header

         

caribguy

3:17 pm on Feb 12, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



HTTP_X_FORWARDED_FOR'216.104.15.nnn'
HTTP_USER_AGENT'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)'
HTTP_ACCEPT_LANGUAGE'en-us'

The last one is new, since today.

It was caught following a user around and causing havoc in a restricted area. The whole range now banned at the firewall.

Edit: I forgot to mention, also seen from 150.70.84.nn - both are using HTTP/1.0 and wasting a huge load of bandwidth.

dstiles

12:09 am on Feb 13, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Doesn't make sense. Why would they be forwarding to another IP? Forwarding THROUGH trend I can see.

What was the other IP?

Most HTTP/1.0 I see come in with several empty headers, so they get blocked.

caribguy

12:16 am on Feb 13, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



That's my app server, which sits behind Apache.