[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: HTTP over SSH probes?



Hi!

Example:
Jun 2 17:46:42 benjo sshd[17291]: Bad protocol version identification 'GET http://www.sciencedirect.com/ HTTP/1.1' from ::ffff:202.207.192.30
The IP in this case seems to be in China.

As far as I can tell nothing is listening at www.sciencedirect.com:22. The web site on port 80 at www.sciencedirect.com is a self-proclaimed "digital library" of some sort.

But why would random IPs be requesting sciencedirect.com at my workstation which has nothing to do with it? Even for a worm that doesn't make any sense.

For university wide subsciptions at sciencedirect it is sometimes necessary to use a special proxy server. If it is only one source IP, maybe someone has put a typo in his proxy configuration. If it are many source IPs but from only one or very few networks, maybe there is a typo in some proxy autoconfiguration file somewhere. Or it is a braindead attempt to find a misconfigured proxy that has sciencedirect subscription.

Cheers,
Stefan



Reply to: