[LON-CAPA-admin] Spoof requests

Guy Albertelli II guy at albertelli.com
Wed Jun 8 19:15:47 EDT 2005


Hi Mark,

> On capa2 (our library server) I'm finding the following in copious 
> quantities in httpd/error_log, both from legitimate (oucapa7/10) and 
> illegitimate sources.
> 
> [Wed Jun  8 12:30:26 2005] [error] access to 
> /raw/uploaded/ohiou/260464b561a42c8oucapa2/docs/Chapter_28.
> pdf failed for 132.235.24.84, reason: Spoof request from

This one is weird, it would see the Reverse DNS lookups are failing from
capa2. What happens when you do

host 132.235.24.84

from the command line on capa2?


> [Wed Jun  8 12:41:53 2005] [error] access to 
> /raw/ohiou/OUp200lib/sfChpt19/sf1903lc.problem.meta failed
> for 64.141.128.101, reason: Spoof request from

The Lansing High Schools machine unfortunately fails to have a valid
Reverse DNS record.

I don't know what it is about HS and their inability to make valid A
records for their machines.


-- 
guy at albertelli.com   0-7-2-5-15,728



More information about the LON-CAPA-admin mailing list