Firewall Wizards mailing list archives

Re: TCP port 7 traffic from DoubleClick


From: ark () eltex ru
Date: Thu, 8 Jul 1999 12:50:01 +0400

-----BEGIN PGP SIGNED MESSAGE-----

nuqneH,

I just filter this and other crap like that out. Still can't figure out
how can one damage his brain so bad to use (or even worse, write) counter
a) using Java b) assuming it will work via direct connection.
I think those people need some medical assistance. EST might help or
something like that..

Vern Paxson <vern () ee lbl gov> said :

Speaking of which, I saw these in my outbound logs a few days back:

my.host.com -> stats.hitbox.com:12343

I haven't tracked down the specific source yet, but it's probably either a URL
or a JavaScript that is logging hit-counts for a page. The question is, as
always, what else is it logging? :-)

Here's a day's worth of those from our DMZ:

/Hitbox?hb=W71901240719&cd=4&ts=30504&hr=12&jv=1.1.5&jm=Netscapew102.hitbox.com
/Hitbox?hb=W38903304657&cd=4&ts=8790&hr=21&jv=1.1.5&jm=Netscapew118.hitbox.com
/Hitbox?hb=CAD904037004&cd=4&ts=96730&hr=21&jv=1.1.5&jm=Netscapew105.hitbox.com
/Hitbox?hb=TTN812023443&cd=4&ts=9940&hr=17&jv=1.1.5&jm=Netscapew114.hitbox.com
/Hitbox?hb=W95903249709&cd=4&ts=18510&hr=16&jv=1.1.5&jm=Netscapew115.hitbox.com

in five connections.

So at least this sample looks fairly innocuous.
 

                                     _     _  _  _  _      _  _
 {::} {::} {::}  CU in Hell          _| o |_ | | _|| |   / _||_|   |_ |_ |_
 (##) (##) (##)        /Arkan#iD    |_  o  _||_| _||_| /   _|  | o |_||_||_|
 [||] [||] [||]            Do i believe in Bible? Hell,man,i've seen one!

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3i
Charset: noconv

iQCVAwUBN4RmOKH/mIJW9LeBAQHApAP/U2HEw8iC9XrvLC46lSDbPw8Zolb2EFBB
Ve3CIOMamyHif0D5BjL8wi8+3Y4VhcU/T8LpUNg6lHiy8utClVU6YiDjHI0ebroP
1fmbkN/BZyo2GDQksOLLzbvQR7wOMHiqYssb0qulLOg+qDtGhfdgltd45cBpw1qZ
ru1Nuv8P3e0=
=qvH7
-----END PGP SIGNATURE-----



Current thread: