[squid-users] Link-Hijacking

From: John Birck <john.birck@dont-contact.us>
Date: Thu, 5 Aug 2004 20:03:28 +0200

Hello,

using squid Version 2.3.STABLE4 on two servers we had now for the second
time the problem that for example adress:
http://www.google.de/
led to
http://www.google.de/scripts/route.dll

Both Mozilla1.6 and IE5 behalved the same way.
We solved the problem temporarly by removing all contents in cache.

access.log told (.dll is in deny list):
1091615668.579 18 10.10.51.53 TCP_DENIED/403 1670 GET
http://www.google.de/scripts/route.dll - NONE/- -

The cache object for www.google.de was this:
^CS^@^@^@^C^P^@^@^@ìk/Ëyþ88ÞdÝ<85>zH)<84>^E^X^@^@^@<8D>¸^PAȸ^PAÿÿÿÿT^E^\?^@
^@^@^@^A^@`^D^D^V^@^@^@http://www.google.de/^HTTP/1.0 200 OK
Content-Length: 1422
Content-Type: text/html
Content-Location: http://www.google.de/domain.forward.htm
Last-Modified: Mon, 21 Jul 2003 15:23:00 GMT
Accept-Ranges: bytes
ETag: "06240f89b4fc31:1f02"
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Date: Wed, 04 Aug 2004 10:24:39 GMT
Age: 59
X-Cache: HIT from proxy1
Proxy-Connection: keep-alive

<html>
<head>
<meta http-equiv="pragma" content="no-cache">
<meta http-equiv="expires" content="0"><meta name="language" content="de">
<meta name="robots" content="index, follow">
<meta name="revisit-after" content="1 day">
<meta name="publisher" content="Flirtpub">
<meta name="keywords" content="Flirten, Bekanntschaft, Flirt,
[... a lot of SEXy keywords ...]

How was this wrong link in cache established, what was going on? Some idea
how to avoid?
Would be glad about any hint.
Bye

john birck
Received on Thu Aug 05 2004 - 12:03:29 MDT

This archive was generated by hypermail pre-2.1.9 : Wed Sep 01 2004 - 12:00:01 MDT