Broken Web Site w/ 1.2b24

From: Jordan Mendelson <jordy@dont-contact.us>
Date: Tue, 1 Sep 1998 21:30:39 -0400

Hello all,

I've noticed this about 3 times, and just recently tracked it down. I
believe McAfee has some sort of automated updator for their software whicah
causes it to go to do something like the following:

access.log.0:904697684.894 580 206.105.188.29 TCP_MISS/200 1777 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll? - DIRECT/208.228.228.238
application/x-mcafee-ec-1*947c484f-3162c151-dd18ac48
access.log.0:904697686.797 520 206.105.188.29 TCP_MISS/200 1777 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll? - DIRECT/208.228.228.238
application/x-mcafee-ec-1*44c9c538-746b6f94-cf648725
access.log.0:904697688.694 522 206.105.188.29 TCP_MISS/200 1777 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll? - DIRECT/208.228.228.238
application/x-mcafee-ec-1*6a332075-b715f27a-5b6d9606

Unfortunatly it seems to open about 30 of them and Squid sits there pulling
data on all of them and completely saturates bandwidth (odd, delay pools
didn't kick in).

I'm seeing this in store.log:

store.log:904699353.050 RELEASE FFFFFFFF 200 904699121 -1 -1
application/x-mcafee-ec-1*d9853c16-e0216fc0-77b30412 512/2136156 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll?
store.log:904699358.011 RELEASE FFFFFFFF 200 904699101 -1 -1
application/x-mcafee-ec-1*850a72dd-1b221de5-64b679da 512/2520368 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll?

and another store.log:

store.log.0:904697684.894 RELEASE FFFFFFFF
     -1 -1 -1 unknown -1/512 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll?130DownloadFile|Pump
store.log.0:904697686.797 RELEASE FFFFFFFF
     -1 -1 -1 unknown -1/512 POST
http://208.228.228.238/ECom/Pull/EcomPullDLL.dll?130DownloadFile|Pump

Any ideas? the mime type says mcafe, which is why I thought it might be a
mcafe thing, but the mime type seems to change every single time... and for
some reason whatever is spawning these POST requests is doing so many, many,
many times :)

Jordan

--
Jordan Mendelson     : http://jordy.wserv.com
Web Services, Inc.   : http://www.wserv.com
Received on Tue Sep 01 1998 - 18:34:55 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:41:50 MST