RE: [squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

From: Jenny Lee <bodycare_5_at_live.com>
Date: Fri, 2 Dec 2011 06:01:12 +0000

> K. first problem:
> # host download.windowsupdate.com
> ...
> download.windowsupdate.com.c.footprint.net has address 204.160.124.126
> download.windowsupdate.com.c.footprint.net has address 8.27.83.126
> download.windowsupdate.com.c.footprint.net has address 8.254.3.254
>
>
> Client is connecting to server 4.26.235.254 port 80. Which is clearly
> not "download.windowsupdate.com" according to the official DNS entries I
> can see.

Yes, welcome to the host header forgery mess. I don't know who benefited from this but a lot of people got bitten by it.

I mentioned this first day http://bugs.squid-cache.org/show_bug.cgi?id=3325

Anyone doing ANYCAST will be screwed (and a whole lotta people do that).

p4$ host download.windowsupdate.com
mscom-wui-any.vo.msecnd.net has address 70.37.129.251
mscom-wui-any.vo.msecnd.net has address 70.37.129.244

p12$ host download.windowsupdate.com
a26.ms.akamai.net.0.1.cn.akamaitech.net has address 92.123.69.42
a26.ms.akamai.net.0.1.cn.akamaitech.net has address 92.123.69.8
a26.ms.akamai.net.0.1.cn.akamaitech.net has address 92.123.69.24
a26.ms.akamai.net.0.1.cn.akamaitech.net has address 92.123.69.26
a26.ms.akamai.net.0.1.cn.akamaitech.net has address 92.123.69.41

Jenny
Received on Fri Dec 02 2011 - 06:01:20 MST

This archive was generated by hypermail 2.2.0 : Fri Dec 02 2011 - 12:00:01 MST