On Thu, Dec 31, 2009 at 05:07:30PM -0500, Ricky Zhou wrote:

> > [...@rz rai]$ file Fedora-12-i386-CHECKSUM 
> > Fedora-12-i386-CHECKSUM: gzip compressed data, from Unix
> Is there anything between you and th eserver that could be affecting 
> this?  Also, does this happen as well when you view it in a browser?

there is the NAT firewall of my umts provider (O2-Germany). Actually one of 
the less intrusive providers, even allows VoIP and everything else.

The browser displays the expected content in cleartext. Size 1078 bytes, quirks 
mode rendering, verified by equifax "site does not provide ownership 
information"
AES-256, CN=fedoraproject.org.

> Just out of curiosity, what does this file decompress to, if anything?

it does decompress to the exact same as the browser displays and gpg-verify
as well as sha256sum give the expected results.

So I do not think O2 would be running MIM attacks, it could be something in
wget-1.12-2.fc10 headers that causes a misunderstanding with the server 
regarding
to compression?

Just checked curl with the same URL and it gives the cleartext content to 
stdout. Wget the compressed stuff again..

Can you look into your logs for 82.113.121.184, should be firefox, curl and wget
accesses. Its a NAT so you may get many more.

Richard

Attachment: pgp00VCimD21E.pgp
Description: PGP signature

-- 
Fedora-websites-list mailing list
Fedora-websites-list@redhat.com
https://www.redhat.com/mailman/listinfo/fedora-websites-list

Reply via email to