Guest User!

You are not Sophos Staff.

[7.075] Maxdome: trailor streaming loops [CONFIRMED]

2007:11:08-19:13:40 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="7884" time="233 ms" request="0x95b3650" url="212.227.18.17/.../campinapuddi_9656_2007_3.wmv

2007:11:08-19:13:41 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="558" time="438 ms" request="0x94d22d8" url="crl.microsoft.com/.../CodeSignPCA.crl" error="" 

2007:11:08-19:13:43 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="POST" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="20058" time="1566 ms" request="0x95b3650" url="man.entriq.net/.../WMLicense

2007:11:08-19:13:43 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="7884" time="211 ms" request="0x95b3650" url="212.227.18.17/.../campinapuddi_9656_2007_3.wmv

2007:11:08-19:13:44 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="block" method="GET" srcip="172.16.70.20" user="" statuscode="500" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="2287" time="63923 ms" request="0x957eb58" url="212.227.18.17/.../zodiakderhor_10357_2007_3.wmv

2007:11:08-19:13:49 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="GET" srcip="172.16.70.20" user="" statuscode="200" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="1133509" time="5547 ms" request="0x95b3650" url="212.227.18.17/.../campinapuddi_9656_2007_3.wmv

2007:11:08-19:13:49 (none) httpproxy[7820]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="pass" method="POST" srcip="172.16.70.20" user="" statuscode="204" cached="0" profile="profile_0" filteraction="action_REF_DefaultHTTPCFFAction" size="0" time="191 ms" request="0x95b3650" url="212.227.18.17/.../campinapuddi_9656_2007_3.wmv

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs04.astaro.com' access time: 103" 

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs01.astaro.com' access time: 107" 

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs05.astaro.com' access time: 104" 

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs02.astaro.com' access time: 119" 

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs07.astaro.com' access time: 306" 

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs03.astaro.com' access time: 431" 

2007:11:08-19:15:37 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs06.astaro.com' access time: 445" 

2007:11:08-19:15:38 (none) httpproxy[7820]: id="0003" severity="info" sys="SecureWeb" sub="http" request="(nil)" function="sc_servers_callback" file="scr_scanner.c" line="809" message="server 'cffs08.astaro.com' access time: 807" 

----
merci
  Claus
Parents Reply
  • Perhaps a good idea would be to allow us to configure what we consider a streaming type in Webadmin... would come in handy for blocking certain streaming data types as well; that way a "new" streaming data type wouldn't require an up2date as they are discovered in the future.

    CTO, Convergent Information Security Solutions, LLC

    https://www.convergesecurity.com

    Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries.  Use the advice given at your own risk.

Children
No Data
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?