Sunday, February 7, 2010

Fun with Chinese Hackers and Cyber-security

Today I was looking at my web server access logs and saw this interesting line:
125.65.112.161 - - [06/Feb/2010:06:43:21 -0800] "GET http://proxyjudge1.proxyfire.net/fastenv HTTP/1.1" 404 205

I dumped their 125.65.112.161 into my Shiny.Sharecrawler to see what their server sent in the request header, and got an interesting surprise by seeing links to cyberpolice.cn.

125.65.112.161 = > http://www.zhaopin.com => http://www.bj.cyberpolice.cn/index.htm

self.response_headers:

   http://125.65.112.161 :
content-length  =>  19337
x-powered-by  =>  ASP.NET
set-cookie  =>  ASPSESSIONIDQSCCRRSR=IOHPECGDONPPCCHEFBOPIMCI; path=/
server  =>  Microsoft-IIS/6.0
connection  =>  close
cache-control  =>  private
date  =>  Sun, 07 Feb 2010 13:48:13 GMT
content-type  =>  text/html
   http://www.zhaopin.com :
content-length  =>  146757
x-cache  =>  HIT from cache75
accept-ranges  =>  bytes
server  =>  Apache
x-cache-lookup  =>  HIT from cache75:80
last-modified  =>  Sun, 07 Feb 2010 12:43:33 GMT
connection  =>  keep-alive
etag  =>  "5c4017-23d45-8508740"
date  =>  Sun, 07 Feb 2010 13:47:59 GMT
content-type  =>  text/html
age  =>  28
   http://www.bj.cyberpolice.cn :
content-length  =>  20242
server  =>  Apache Coyote/1.0
last-modified  =>  Wed, 24 Oct 2007 08:39:08 GMT
connection  =>  close
etag  =>  W/"20242-1193215148000"
date  =>  Sun, 07 Feb 2010 15:50:51 GMT
content-type  =>  text/html
<top>   
   http://online.rising.com.cn :
content-length  =>  13643
x-powered-by  =>  ASP.NET
set-cookie  =>  ASPSESSIONIDSSDATCQA=LKHKDGFDAGOEEHEDBPADEKFO; path=/
server  =>  Microsoft-IIS/6.0
connection  =>  close
cache-control  =>  private
date  =>  Sun, 07 Feb 2010 13:48:40 GMT
content-type  =>  text/html
<top>   
   http://mailcenter.rising.com.cn :
content-length  =>  306
content-location  =>  http://mailcenter.rising.com.cn/index.htm
x-powered-by  =>  ASP.NET
accept-ranges  =>  bytes
server  =>  Microsoft-IIS/6.0
last-modified  =>  Tue, 01 Jul 2008 05:39:27 GMT
connection  =>  close
etag  =>  "f8b8bbd33cdbc81:1cb1"
date  =>  Sun, 07 Feb 2010 13:43:29 GMT
content-type  =>  text/html

No comments: