IE8 Delegating a pages resource collection to multiple IPs ?

  • joebert
  • Sledgehammer
  • Genius
  • No Avatar
  • Joined: Feb 10, 2004
  • Posts: 13455
  • Loc: Florida
  • Status: Offline

Post December 2nd, 2009, 6:07 am

I was just looking through some website access logs and came across an interesting pattern. The pattern suggests that this visitor was fetching all pages using one IP address, then the IP address used to fetch the resources in each page randomly toggled between two addresses on the same network.

Does IE, Windows, or something marked by the signature in this User-Agent header support this behavior ?
What is it ?

Code: [ Select ]
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB5; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30729; OfficeLiveConnector.1.4; OfficeLivePatch.1.3; AskTB5.4)


I've attached the portion of the log with the requests if anyone wants to see it.
Attachments:
access.log.zip

(1.98 KiB) Downloaded 142 times

Strong with this one, the sudo is.
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post December 2nd, 2009, 6:07 am

  • Don2007
  • Web Master
  • Web Master
  • No Avatar
  • Joined: Nov 21, 2006
  • Posts: 4924
  • Loc: NY
  • Status: Offline

Post December 2nd, 2009, 8:24 am

I looks like someone crawling the site. Do you remember web snake? It might be some bot. The IP addresses in question are external IP addresses in Dubai, owned by the Emirates Telecommunications Corporation. So, it's not even someone's LAN.
How do you know when a politician is lying? His mouth is moving.
  • joebert
  • Sledgehammer
  • Genius
  • No Avatar
  • Joined: Feb 10, 2004
  • Posts: 13455
  • Loc: Florida
  • Status: Offline

Post December 2nd, 2009, 10:52 am

I'm thinking it's someone browsing from their place of work off the top of my head because of the Office~ stuff mentioned in the User-Agent.

I'm not familiar with Microsofts office/business software though. I've never seen a request be delegated like that before.
Strong with this one, the sudo is.
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23404
  • Loc: Woodbridge VA
  • Status: Offline

Post December 2nd, 2009, 11:01 am

Well, off the cuff, Office live is a Microsoft Office addin that allows you to save/store/share files "online". They were accessing wallpapers, correct? Just thinking that perhaps they were saving them to their office live location.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • joebert
  • Sledgehammer
  • Genius
  • No Avatar
  • Joined: Feb 10, 2004
  • Posts: 13455
  • Loc: Florida
  • Status: Offline

Post December 2nd, 2009, 12:48 pm

That would make sense, if there were double requests for each thumbnail.

Each page has 6 thumbnails. The way the requests are showing in the logs, the first IP requests the HTML page, and then there are 6 requests total after that split between the two IP addresses to fetch the 6 thumbnails on the page.

Maybe 10 seconds later, the same thing happens with a new page and 6 more thumbnails.
Strong with this one, the sudo is.

Post Information

  • Total Posts in this topic: 5 posts
  • Users browsing this forum: No registered users and 94 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.