Hacker News new | ask | show | jobs
by KayEss 3515 days ago
We have a client's system that seems to get probed for this sort of thing. We keep seeing URLs like the following being requested:

    htttps://www.example.com/http://www.baidu.com/cache/global/img/gs.gif
There are a number of variations including plain IP numbers and other URLs, like www.google.com being used.

I guess at some point somebody accessed the site from China.

EDIT: Just got another probe from 94.102.49.174 owned by Quasi Networks Ltd in the Seychelles.

1 comments

Quasi (aka Ecatel) is basically a den of ddos for hire, ddos, malware, botnet C&C, abuse reports ignored. Servers are in NL.

Probably not China.