Hello all.
I'm getting reports which show huge traffic amounts on some http IP
addresses. These point to ports like 9000, 8000, 8100, 9720, and the
like. When I put those URLs in the browser, I get to some shoutcast
servers (let's take as an example: http://213.35.156.16:9000/). How may
I block this sort of streaming media?
Here the relevant log lines:
1131956633.216 7236 10.167.211.62 TCP_MISS/600 298294 GET
http://213.35.156.16:9000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131965732.540 917 10.167.211.62 TCP_MISS/600 25021 GET
http://213.35.156.16:9000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131965815.003 81204 10.167.211.62 TCP_MISS/600 2093292 GET
http://213.35.156.16:9000/ -
TIMEOUT_FIRST_UP_PARENT/proxy.reteunitaria.piemonte.it -
1131982736.548 6082 10.167.211.62 TCP_MISS/600 362948 GET
http://213.35.156.16:9000/ -
TIMEOUT_FIRST_UP_PARENT/proxy.reteunitaria.piemonte.it -
1131985079.527 2613 10.167.211.62 TCP_MISS/600 163257 GET
http://213.35.156.16:8000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131985825.545 2244 10.167.211.62 TCP_MISS/600 106951 GET
http://213.35.156.16:9000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
1131986644.367 7009798 10.167.211.163 TCP_MISS/600 168504426 GET
http://213.35.156.16:8000/ -
FIRST_PARENT_MISS/proxy.reteunitaria.piemonte.it -
As you can see, there's nothing more than the URL, no MIME type
indication at all!
Any help would be appreciated.
Thanks in advance,
-- ----------------------------------- Boniforti Flavio Provincia del Verbano-Cusio-Ossola Ufficio Informatica Tecnoparco del Lago Maggiore Via dell'Industria, 25 28924 Verbania -----------------------------------Received on Tue Nov 15 2005 - 07:55:17 MST
This archive was generated by hypermail pre-2.1.9 : Thu Dec 01 2005 - 12:00:09 MST