Package: polipo
Version: 1.0.4.1-1.1
Severity: normal
Hi,
Polipo again seems to be continually trying to contact
e*-in-f*.1e100.net again. This is on a different machine to before,
fortunately where bandwidth isn't charged for.
It happens after spending some time panning around
http://maps.google.co.uk/ with satellite images enabled.
netstat reports dozens of lines like this:
tcp 0 0 tapp.hq.fundament:43250 ez-in-f147.1e100.ne:www TIME_WAIT
/var/log/polipo/polipo.log contains thousands of lines of:
Unsupported Cache-Control directive post-check -- ignored.
Unsupported Cache-Control directive pre-check -- ignored.
Attached should be the results of "tcpdump -A host ew-in-f99.1e100.net".
I think I've managed to inlude two complete consecutive requests and
reponses.
Please let me know if there is any more information I can provide.
Thanks,
Roger
-- System Information:
Debian Release: 6.0
APT prefers squeeze-updates
APT policy: (500, 'squeeze-updates'), (500, 'proposed-updates'), (500,
'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 2.6.32-5-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_GB, LC_CTYPE=en_GB (charmap=ISO-8859-1)
Shell: /bin/sh linked to /bin/dash
Versions of packages polipo depends on:
ii dpkg 1.15.8.10 Debian package management system
ii install-info 4.13a.dfsg.1-6 Manage installed documentation in
ii libc6 2.11.2-10 Embedded GNU C Library: Shared lib
polipo recommends no packages.
polipo suggests no packages.
-- Configuration Files:
/etc/cron.daily/polipo changed:
set -e
FORBIDDEN_FILE=/etc/polipo/forbidden
CONFIG_FILE=/etc/polipo/config
if [ ! -x /usr/bin/polipo ]; then
exit 0
fi
if [ ! -f $FORBIDDEN_FILE ]; then
FORBIDDEN_FILE=/dev/null
fi
PIDFILE=/var/run/polipo/polipo.pid
[ -f "$PIDFILE" ] && kill -USR1 $(cat "$PIDFILE")
sleep 1
su -c \
"nice polipo -x -c $CONFIG_FILE forbiddenFile=$FORBIDDEN_FILE >
/dev/null" \
proxy
[ -f "$PIDFILE" ] && kill -USR2 $(cat "$PIDFILE")
/etc/polipo/config changed:
proxyAddress = "0.0.0.0" # IPv4 only
allowedClients = 127.0.0.1, 192.168.1.0/24
objectHighMark = 16384
chunkHighMark = 134217728
localDocumentRoot = "/srv/www/"
disableConfiguration = true
disableLocalInterface = true
dnsQueryIPv6 = no
dnsNameServer = 127.0.0.1
disableVia=false
relaxTransparency = maybe
redirector = /usr/bin/adzapper.wrapper
dontCacheRedirects = true
serverExpireTime = 8d
maxDiskCacheEntrySize = 104857600
maxDiskEntries = 64
serverMaxSlots = 32
serverSlots = 8
serverSlots1 = 16
dnsMaxTimeout = 30s
dnsNegativeTtl = 1m
serverTimeout = 1m
serverIdleTimeout = 1m
/etc/polipo/forbidden changed:
google-analytics.com
-- no debconf information
Title: 302 Moved
E..4$&@.@.......J}Mc...P...X.zan...;.N.....
...P.N,.
16:13:59.994546 IP tapp.hq.fundamentalsltd.co.uk.47609 > ew-in-f99.1e100.net.www: Flags [SEW], seq 2959782354, win 5840, options [mss 1460,sackOK,TS val 279312464 ecr 0,nop,wscale 7], length 0
E..
tapp.hq.fundamentalsltd.co.uk.47609: Flags [S.], seq 760068145, ack 2959782355, win 5672, options [mss 1430,sackOK,TS val 1544800739 ecr 279312464,nop,wscale 6], length 0
E..<....2..CJ}Mc.....P..-M.1.j.....(.i.........
\......P....
16:14:00.043394 IP tapp.hq.fundamentalsltd.co.uk.47609 > ew-in-f99.1e100.net.www: Flags [.], ack 1, win 46, options [nop,nop,TS val 279312477 ecr 1544800739], length 0
E..4I.@.@.......J}Mc...P.j..-M.2...........
...]\...
16:14:00.043487 IP tapp.hq.fundamentalsltd.co.uk.47609 > ew-in-f99.1e100.net.www: Flags [P.], seq 1:585, ack 1, win 46, options [nop,nop,TS val 279312477 ecr 1544800739], length 584
E..|I.@.@..n....J}Mc...P.j..-M.2...........
...]\...GET /sorry/?continue=http://khm0.google.co.uk/kh/v%3D79%26cookie%3Dfzwq1OYuCvln3s17xwsPTyKJXzgL1VFZy0tNCw%26x%3D8140%26y%3D5409%26z%3D14%26s%3DGalil HTTP/1.1
Host: sorry.google.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-GB; rv:1.9.1.16) Gecko/20101123 SeaMonkey/2.0.11
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-gb,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Referer: http://maps.google.co.uk/
DNT: 1
Via: 1.1 tapp.hq.fundamentalsltd.co.uk
Connection: keep-alive
16:14:00.047575 IP ew-in-f99.1e100.net.www > tapp.hq.fundamentalsltd.co.uk.47607: Flags [F.], seq 811, ack 586, win 107, options [nop,nop,TS val 3058576690 ecr 279312464], length 0
E..4....2.g$J}Mc.....P...zan...Y...k.......
.N-2...P
16:14:00.047589 IP tapp.hq.fundamentalsltd.co.uk.47607 > ew-in-f99.1e100.net.www: Flags [.], ack 812, win 59, options [nop,nop,TS val 279312478 ecr 3058576690], length 0
E..4$'@.@.......J}Mc...P...Y.zao...;.
.....
...^.N-2
16:14:00.100543 IP ew-in-f99.1e100.net.www > tapp.hq.fundamentalsltd.co.uk.47609: Flags [.], ack 585, win 107, options [nop,nop,TS val 1544800796 ecr 279312477], length 0
E..4....2..JJ}Mc.....P..-M.2.j.....k.E.....
\......]
16:14:00.102739 IP ew-in-f99.1e100.net.www > tapp.hq.fundamentalsltd.co.uk.47609: Flags [P.], seq 1:811, ack 585, win 107, options [nop,nop,TS val 1544800799 ecr 279312477], length 810
E..^....2...J}Mc.....P..-M.2.j.....k.R.....
\......]HTTP/1.1 302 Found
Location: http://www.google.co.uk/sorry/?continue=http://khm0.google.co.uk/kh/v%3D79%26cookie%3Dfzwq1OYuCvln3s17xwsPTyKJXzgL1VFZy0tNCw%26x%3D8140%26y%3D5409%26z%3D14%26s%3DGalil
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Date: Wed, 23 Feb 2011 16:14:00 GMT
Content-Type: text/html; charset=UTF-8
Server: GCS/1.0
Content-Length: 364
X-XSS-Protection: 1; mode=block
302 Moved
The document has moved
here.
16:14:00.215121 IP tapp.hq.fundamentalsltd.co.uk.47611 > ew-in-f99.1e100.net.www: Flags [.], ack 811, win 59, options [nop,nop,TS val 279312520 ecr 2839599017], length 0
E..4..@.@..*....J}Mc...P.... ..O...;.......
.....@..
16:14:00.215247 IP tapp.hq.fundamentalsltd.co.uk.47611 > ew-in-f99.1e100.net.www: Flags [F.], seq 585, ack 811, win 59, options [nop,nop,TS val 279312520 ecr 2839599017], length 0
E..4..@.@..)....J}Mc...P.... ..O...;.......
.....@..
16:14:00.215313 IP tapp.hq.fundamentalsltd.co.uk.47614 > ew-in-f99.1e100.net.www: Flags [SEW], seq 2965479608, win 5840, options [mss 1460,sackOK,TS val 279312520 ecr 0,nop,wscale 7], length 0
E.. tapp.hq.fundamentalsltd.co.uk.47611: Flags [F.], seq 811, ack 586, win 107, options [nop,nop,TS val 2839599067 ecr 279312520], length 0
E..4....2..mJ}Mc.....P.. ..O.......k.......
.@......
16:14:00.264129 IP tapp.hq.fundamentalsltd.co.uk.47611 > ew-in-f99.1e100.net.www: Flags [.], ack 812, win 59, options [nop,nop,TS val 279312532 ecr 2839599067], length 0
E..4..@.@..(....J}Mc...P.... ..P...;.......
.....@..