Skip to content

Instantly share code, notes, and snippets.

@greatseth
Created October 3, 2009 20:04
Show Gist options
  • Save greatseth/200836 to your computer and use it in GitHub Desktop.
Save greatseth/200836 to your computer and use it in GitHub Desktop.
Strange HTTP requests from Freenode
Strange Mongrel output caused by requests from Freenode to port 2000:
Sat Oct 03 01:21:16 -0400 2009: HTTP parse error, malformed request (85.190.0.3): #<Mongrel::HttpParserError: Invalid HTTP format, parsing fails.>
Sat Oct 03 01:21:16 -0400 2009: REQUEST DATA: "\005\001\000"
---
PARAMS: {}
---
Sat Oct 03 01:21:22 -0400 2009: HTTP parse error, malformed request (85.190.0.3): #<Mongrel::HttpParserError: Invalid HTTP format, parsing fails.>
Sat Oct 03 01:21:22 -0400 2009: REQUEST DATA: "\004\001y??\\b\a\000"
---
PARAMS: {}
---
Sat Oct 03 02:17:42 -0400 2009: HTTP parse error, malformed request (85.190.0.3): #<Mongrel::HttpParserError: Invalid HTTP format, parsing fails.>
Sat Oct 03 02:17:42 -0400 2009: REQUEST DATA: "\005\001\000"
---
PARAMS: {}
---
Sat Oct 03 02:17:42 -0400 2009: HTTP parse error, malformed request (85.190.0.3): #<Mongrel::HttpParserError: Invalid HTTP format, parsing fails.>
Sat Oct 03 02:17:42 -0400 2009: REQUEST DATA: "\004\001y??\\b\a\000"
---
PARAMS: {}
---
Hmm, what is this IP?
_\m/ ~ | traceroute 85.190.0.3
traceroute to 85.190.0.3 (85.190.0.3), 64 hops max, 40 byte packets
1 64.sub-66-174-121.myvzw.com (66.174.121.64) 101.304 ms 78.387 ms 64.961 ms
2 127.sub-66-174-120.myvzw.com (66.174.120.127) 88.821 ms 158.406 ms 100.986 ms
3 66.sub-66-174-23.myvzw.com (66.174.23.66) 73.961 ms 88.486 ms 84.949 ms
4 229.sub-66-174-23.myvzw.com (66.174.23.229) 93.891 ms 87.464 ms 87.890 ms
5 194.sub-66-174-23.myvzw.com (66.174.23.194) 89.583 ms 88.444 ms 99.919 ms
6 98.sub-66-174-22.myvzw.com (66.174.22.98) 88.876 ms 99.476 ms 82.959 ms
7 253.sub-69-83-0.myvzw.com (69.83.0.253) 88.001 ms 88.477 ms 89.964 ms
8 te-4-4.car2.Newark1.Level3.net (4.79.190.233) 135.706 ms 226.406 ms 204.006 ms
9 ae-32-52.ebr2.Newark1.Level3.net (4.68.99.62) 89.883 ms 104.411 ms 89.852 ms
10 ae-1-100.ebr1.Newark1.Level3.net (4.69.132.21) 89.945 ms 86.470 ms 181.963 ms
11 ae-2-2.ebr1.NewYork1.Level3.net (4.69.132.97) 97.876 ms 97.444 ms 89.906 ms
12 ae-91-91.csw4.NewYork1.Level3.net (4.69.134.78) 96.877 ms 96.473 ms ae-71-71.csw2.NewYork1.Level3.net (4.69.134.70) 97.962 ms
13 ae-23-79.car3.NewYork1.Level3.net (4.68.16.69) 91.471 ms ae-33-89.car3.NewYork1.Level3.net (4.68.16.133) 113.465 ms ae-23-79.car3.NewYork1.Level3.net (4.68.16.69) 66.481 ms
14 tiscali-level3-ge.newyork1.level3.net (4.68.110.78) 90.935 ms 87.722 ms 169.890 ms
15 xe-2-0-0.fra23.ip4.tinet.net (213.200.81.125) 186.777 ms xe-9-1-0.fra20.ip4.tinet.net (89.149.187.233) 192.468 ms 184.422 ms
16 ge-1-1-0.pr1.g310.fra.de.eurotransit.net (213.200.86.102) 187.949 ms 181.430 ms 184.909 ms
17 proxyscan.freenode.net (85.190.0.3) 180.887 ms 185.519 ms 178.898 ms
Hmm...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment