Guest User!

You are not Sophos Staff.

[7.075] Invalid POST requests with Zattoo streaming client [CONFIRMED]

2007:11:08-18:58:23 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x95b3650" function="fileextension_scan" file="fileextensionscanner.c" line="130" message="error converting file name to utf-8 from UTF-8.: Conversion from character set 'UTF-8.' to 'UTF8' is not supported" 
2007:11:08-18:58:23 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="389" time="457 ms" request="0x95b3650" url="frodo.zattoo.com/.../fd
2007:11:08-19:00:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs01.astaro.com' access time: 413" 
2007:11:08-19:00:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs02.astaro.com' access time: 355" 
2007:11:08-19:00:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs04.astaro.com' access time: 289" 
2007:11:08-19:00:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs05.astaro.com' access time: 228" 
2007:11:08-19:00:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs03.astaro.com' access time: 520" 
2007:11:08-19:00:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs06.astaro.com' access time: 436" 
2007:11:08-19:00:38 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs08.astaro.com' access time: 832" 
2007:11:08-19:00:40 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs07.astaro.com' access time: 3301"
Parents
  • 2007:11:08-18:58:23 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x95b3650" function="fileextension_scan" file="fileextensionscanner.c" line="130" message="error converting file name to utf-8 from UTF-8.: Conversion from character set 'UTF-8.' to 'UTF8' is not supported"


    There's an extra dot at the end of the charset name ("UTF-8."). Looks like this is the problem. Question is where this string comes from. I guess an HTTP header.  Please find the URL for request 0x95b3650 (grep for this in the logfile). Thx.
Reply
  • 2007:11:08-18:58:23 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x95b3650" function="fileextension_scan" file="fileextensionscanner.c" line="130" message="error converting file name to utf-8 from UTF-8.: Conversion from character set 'UTF-8.' to 'UTF8' is not supported"


    There's an extra dot at the end of the charset name ("UTF-8."). Looks like this is the problem. Question is where this string comes from. I guess an HTTP header.  Please find the URL for request 0x95b3650 (grep for this in the logfile). Thx.
Children
  • Tom, 
    there are many requests with 0x95b3650 and with different URLs.

    Bsp.

    2007:11:08-18:57:27 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="43" time="136 ms" request="0x95b3650" url="maxdome.ivwbox.de/.../ Animals" 

    2007:11:08-18:57:28 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="0" time="352 ms" request="0x95b3650" url="data.coremetrics.com/eluminate

    2007:11:08-18:58:23 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="0x95b3650" function="fileextension_scan" file="fileextensionscanner.c" line="130" message="error converting file name to utf-8 from UTF-8.: Conversion from character set 'UTF-8.' to 'UTF8' is not supported" 

    2007:11:08-18:58:23 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="389" time="457 ms" request="0x95b3650" url="frodo.zattoo.com/.../fd

    2007:11:08-19:05:29 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="POST" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="15" time="295 ms" request="0x95b3650" url="213.52.240.240/.../SpamResolverNG.dll

    2007:11:08-19:05:40 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="block" method="POST" srcip="172.16.70.20" user="" statuscode="400" cached="0" profile="profile_0" filteraction="" size="2185" time="0 ms" request="0x95b3650" url="91.123.96.21" error="invalid request line: POST http://91.123.96.21 HTTP/1.1" 

    2007:11:08-19:06:04 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="block" method="POST" srcip="172.16.70.20" user="" statuscode="400" cached="0" profile="profile_0" filteraction="" size="2185" time="0 ms" request="0x95b3650" url="91.123.96.21" error="invalid request line: POST http://91.123.96.21 HTTP/1.1" 

    2007:11:08-19:08:30 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="POST" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="42" time="219 ms" request="0x95b3650" url="213.52.240.240/.../SpamResolverNG.dll

    2007:11:08-19:08:31 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="POST" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="44387" time="1206 ms" request="0x95b3650" url="213.52.240.240/.../SpamResolverNG.dll

    2007:11:08-19:09:05 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="302" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="1" time="167 ms" request="0x95b3650" url="maxdome.ivwbox.de/.../

    2007:11:08-19:09:06 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="304" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="0" time="162 ms" request="0x95b3650" url="www.maxdome.de/.../sn_home_doku.jpg" error="" 
    2007:11:08-19:09:06 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="43" time="393 ms" request="0x95b3650" url="data.coremetrics.com/eluminate
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?