U
U
Uncle Seryozha2016-11-17 10:58:23
Squid
Uncle Seryozha, 2016-11-17 10:58:23

Where is shodan.io in Squid logs from?

Hey!
There are the following users in the Lightsquid logs:
census1.shodan.io
census2.shodan.io
....
census12.shodan.io
Despite the fact that no users (alias in squid) are occupied, only traffic output via internal IP users.
In the traffic view, one site is indicated that they tried to get to:
3c323cb36caf48f087d2d908b6b4e6d1.JPG
In access.log, for example, for census7.shodan.io at the indicated time, there is only one request:

1478251249.331      1 91.196.50.33 TCP_DENIED/403 4152 GET http://testp4.pospr.waw.pl/testproxy.php - HIER_NONE/- text/html

1) From what should I conclude that a request was not successfully sent?
2) What needs to be done: for example, block *.shodan.io, what else?

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question