Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Information is the inverse of entropy.


devel / comp.sys.acorn.networking / Go-http-client

SubjectAuthor
* Go-http-clientMartin
+* Re: Go-http-clientChris Hughes
|`* Re: Go-http-clientMartin
| `* Re: Go-http-clientChris Hughes
|  `- Re: Go-http-clientMartin
+* Re: Go-http-clientTheo
|`* Re: Go-http-clientMartin
| `- Re: Go-http-clientTheo
`* Re: Go-http-clientMartin
 `* Re: Go-http-clientRichard Torrens (News)
  `- Re: Go-http-clientMartin

1
Go-http-client

<5b2b4df63fNews03@avisoft.f9.co.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1188&group=comp.sys.acorn.networking#1188

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!news.bbs.nz!tncsrv06.tnetconsulting.net!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!feeder.usenetexpress.com!tr2.iad1.usenetexpress.com!69.80.99.27.MISMATCH!Xl.tags.giganews.com!local-2.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Wed, 31 Jan 2024 10:39:02 +0000
From: News03@avisoft.f9.co.uk (Martin)
Subject: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Wed, 31 Jan 2024 10:25:35 +0000 (GMT)
Message-ID: <5b2b4df63fNews03@avisoft.f9.co.uk>
User-Agent: Pluto/3.21a (RISC OS/5.29) NewsHound/v1.54
Organization: None
Lines: 28
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-hAVODJpTKMa4/5BG+x0qqN42vx2avhqHK5EvZPdKkW2vYuUC1fQDtZGHrBDddX0aov+lgLAGLpfiyJa!SVGp+TFWHpjHKPzWdriKvrsiuYEot74VLaY+qeowdTs9CIJ/24Wjj8oqGyjHpRIpzzTaWWYPfzQ0!rZs=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Martin - Wed, 31 Jan 2024 10:25 UTC

In the last couple of days my website has had an increase in traffic,
from about 30 different IP addresses, all with a User-Agent of
"Go-http-client/1.1".

Each starts with a "GET / HTTP/1.1" request, with various User-Agents,
including Windows, Linux & MaxOS. If that works (as it will) it then
issues GETs for about 30 varied files, then stops.

It seems that Go-http-client is a package which "provides HTTP client
and server implementations" but it is suddenly being used by lots of
IPs in a suspicious way.

Anyone else seen this?

They obviously do not abide by robots/txt (or even read it), so the
only way I know to block them is to add them to /htaccess as deny
froms - some have the same top two numbers.

Are there any better ways?
One way is just to ignore them, I know, but I would not want a trickle
to turn into a flood.

Martin

--
Martin Avison
Note that unfortunately this email address will become invalid
without notice if (when) any spam is received.

Re: Go-http-client

<a56a552b5b.chris@mytardis>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1189&group=comp.sys.acorn.networking#1189

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!news.hispagatos.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: news13@noonehere.co.uk (Chris Hughes)
Newsgroups: comp.sys.acorn.networking
Subject: Re: Go-http-client
Date: Wed, 31 Jan 2024 11:47:00 GMT
Organization: A noiseless patient Spider
Lines: 32
Message-ID: <a56a552b5b.chris@mytardis>
References: <5b2b4df63fNews03@avisoft.f9.co.uk>
Injection-Info: dont-email.me; posting-host="ec67d43aa6169961e36c1647f8490202";
logging-data="1588707"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19skrR9cSLxLf2jINtiT1YUJHZJFYjCE9w="
User-Agent: Messenger-Pro/9.01 (MsgServe/9.01) (RISC-OS/5.29) NewsHound/v1.54
Cancel-Lock: sha1:CnRW1QQ5k0FykuAfiNcR8HrEaEc=
X-Editor: EmailEdit 2.04
 by: Chris Hughes - Wed, 31 Jan 2024 11:47 UTC

In message <5b2b4df63fNews03@avisoft.f9.co.uk>
Martin <News03@avisoft.f9.co.uk> wrote:

> In the last couple of days my website has had an increase in traffic,
> from about 30 different IP addresses, all with a User-Agent of
> "Go-http-client/1.1".

> Each starts with a "GET / HTTP/1.1" request, with various User-Agents,
> including Windows, Linux & MaxOS. If that works (as it will) it then
> issues GETs for about 30 varied files, then stops.

> It seems that Go-http-client is a package which "provides HTTP client
> and server implementations" but it is suddenly being used by lots of
> IPs in a suspicious way.

> Anyone else seen this?

> They obviously do not abide by robots/txt (or even read it), so the
> only way I know to block them is to add them to /htaccess as deny
> froms - some have the same top two numbers.

> Are there any better ways?
> One way is just to ignore them, I know, but I would not want a trickle
> to turn into a flood.

Is your web space provided via PlusNet ?

If so you could report possible suspicious activity.

--
Chris Hughes

Re: Go-http-client

<5b2b591f8fNews03@avisoft.f9.co.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1190&group=comp.sys.acorn.networking#1190

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!border-2.nntp.ord.giganews.com!nntp.giganews.com!Xl.tags.giganews.com!local-1.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Wed, 31 Jan 2024 12:40:34 +0000
From: News03@avisoft.f9.co.uk (Martin)
Subject: Re: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Wed, 31 Jan 2024 12:27:30 +0000 (GMT)
Message-ID: <5b2b591f8fNews03@avisoft.f9.co.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <a56a552b5b.chris@mytardis>
User-Agent: Pluto/3.21a (RISC OS/5.29) NewsHound/v1.54
Organization: None
Lines: 38
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-Gt1lMQSLnRkImUxKBFNSZbdpNS8sIDlFIW1tFKDlC8Ngz6Nikm7UeQbOZbp06b6r2UNFuAQ1WnFyvBn!J6MTVdEdFFDZ/n8n2vXbr/YccsyjeOskks+OiqbYXkPIOWAoRm+SA8EnGvPxSZl8ap2EL/Kt1SBH!1YE=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Martin - Wed, 31 Jan 2024 12:27 UTC

In article <a56a552b5b.chris@mytardis>,
Chris Hughes <news13@noonehere.co.uk> wrote:
> In message <5b2b4df63fNews03@avisoft.f9.co.uk>
> Martin <News03@avisoft.f9.co.uk> wrote:

> > In the last couple of days my website has had an increase in
> > traffic, from about 30 different IP addresses, all with a
> > User-Agent of "Go-http-client/1.1".

> > Each starts with a "GET / HTTP/1.1" request, with various
> > User-Agents, including Windows, Linux & MaxOS. If that works (as
> > it will) it then issues GETs for about 30 varied files, then
> > stops.

> > It seems that Go-http-client is a package which "provides HTTP
> > client and server implementations" but it is suddenly being used
> > by lots of IPs in a suspicious way.

> > Anyone else seen this?

> > They obviously do not abide by robots/txt (or even read it), so
> > the only way I know to block them is to add them to /htaccess as
> > deny froms - some have the same top two numbers.

> > Are there any better ways? One way is just to ignore them, I
> > know, but I would not want a trickle to turn into a flood.

> Is your web space provided via PlusNet ?
> If so you could report possible suspicious activity.

Yes ... but I doubt they would be interested at the current level.

Martin

--
Martin Avison
Note that unfortunately this email address will become invalid
without notice if (when) any spam is received.

Re: Go-http-client

<e9095c2b5b.chris@mytardis>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1191&group=comp.sys.acorn.networking#1191

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!newsfeed.endofthelinebbs.com!news.hispagatos.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: news13@noonehere.co.uk (Chris Hughes)
Newsgroups: comp.sys.acorn.networking
Subject: Re: Go-http-client
Date: Wed, 31 Jan 2024 12:59:20 GMT
Organization: A noiseless patient Spider
Lines: 44
Message-ID: <e9095c2b5b.chris@mytardis>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <a56a552b5b.chris@mytardis> <5b2b591f8fNews03@avisoft.f9.co.uk>
Injection-Info: dont-email.me; posting-host="ec67d43aa6169961e36c1647f8490202";
logging-data="1608542"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/VgLHd5D/iePAH5Nvc+wLXOCypuwnAzPk="
User-Agent: Messenger-Pro/9.01 (MsgServe/9.01) (RISC-OS/5.29) NewsHound/v1.54
Cancel-Lock: sha1:92ROugEiosA+9ueBcC8o5EQa+dY=
X-Editor: EmailEdit 2.04
 by: Chris Hughes - Wed, 31 Jan 2024 12:59 UTC

In message <5b2b591f8fNews03@avisoft.f9.co.uk>
Martin <News03@avisoft.f9.co.uk> wrote:

> In article <a56a552b5b.chris@mytardis>,
> Chris Hughes <news13@noonehere.co.uk> wrote:
>> In message <5b2b4df63fNews03@avisoft.f9.co.uk>
>> Martin <News03@avisoft.f9.co.uk> wrote:

>>> In the last couple of days my website has had an increase in
>>> traffic, from about 30 different IP addresses, all with a
>>> User-Agent of "Go-http-client/1.1".

>>> Each starts with a "GET / HTTP/1.1" request, with various
>>> User-Agents, including Windows, Linux & MaxOS. If that works (as
>>> it will) it then issues GETs for about 30 varied files, then
>>> stops.

>>> It seems that Go-http-client is a package which "provides HTTP
>>> client and server implementations" but it is suddenly being used
>>> by lots of IPs in a suspicious way.

>>> Anyone else seen this?

>>> They obviously do not abide by robots/txt (or even read it), so
>>> the only way I know to block them is to add them to /htaccess as
>>> deny froms - some have the same top two numbers.

>>> Are there any better ways? One way is just to ignore them, I
>>> know, but I would not want a trickle to turn into a flood.

>> Is your web space provided via PlusNet ?
>> If so you could report possible suspicious activity.

> Yes ... but I doubt they would be interested at the current level.

I meant to say via PlusNet's Community Forum, which often gets a faster
response then ringing the normal customer support, as they frequently
don't seem to know some users have web space! as you use a legacy system
i.e. force9

--
Chris Hughes

Re: Go-http-client

<5b2b5d310aNews03@avisoft.f9.co.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1192&group=comp.sys.acorn.networking#1192

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!rocksolid2!news.neodome.net!tncsrv06.tnetconsulting.net!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!feeder.usenetexpress.com!tr3.iad1.usenetexpress.com!69.80.99.22.MISMATCH!Xl.tags.giganews.com!local-2.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Wed, 31 Jan 2024 13:25:34 +0000
From: News03@avisoft.f9.co.uk (Martin)
Subject: Re: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Wed, 31 Jan 2024 13:11:58 +0000 (GMT)
Message-ID: <5b2b5d310aNews03@avisoft.f9.co.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <a56a552b5b.chris@mytardis> <5b2b591f8fNews03@avisoft.f9.co.uk> <e9095c2b5b.chris@mytardis>
User-Agent: Pluto/3.21a (RISC OS/5.29) NewsHound/v1.54
Organization: None
Lines: 48
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-oAOo4WCWuSHcbeMDHDHY6zLaNXmRfjn3vuyOw5rbHXDKLlIUKhXDave7NKKAa/sb8tUNzhYWGKon+W/!JtZMMh4aRqxZ8SxEVxISnGBrY64edxVzrHJ6JwV3iLf/X/n+yAyjV3W4jDaL/MFHxRCv+xmTpOiG!eW4=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Martin - Wed, 31 Jan 2024 13:11 UTC

In article <e9095c2b5b.chris@mytardis>,
Chris Hughes <news13@noonehere.co.uk> wrote:
> In message <5b2b591f8fNews03@avisoft.f9.co.uk>
> Martin <News03@avisoft.f9.co.uk> wrote:

> > In article <a56a552b5b.chris@mytardis>,
> > Chris Hughes <news13@noonehere.co.uk> wrote:
> >> In message <5b2b4df63fNews03@avisoft.f9.co.uk>
> >> Martin <News03@avisoft.f9.co.uk> wrote:

> >>> In the last couple of days my website has had an increase in
> >>> traffic, from about 30 different IP addresses, all with a
> >>> User-Agent of "Go-http-client/1.1".

> >>> Each starts with a "GET / HTTP/1.1" request, with various
> >>> User-Agents, including Windows, Linux & MaxOS. If that works (as
> >>> it will) it then issues GETs for about 30 varied files, then
> >>> stops.

> >>> It seems that Go-http-client is a package which "provides HTTP
> >>> client and server implementations" but it is suddenly being used
> >>> by lots of IPs in a suspicious way.

> >>> Anyone else seen this?

> >>> They obviously do not abide by robots/txt (or even read it), so
> >>> the only way I know to block them is to add them to /htaccess as
> >>> deny froms - some have the same top two numbers.

> >>> Are there any better ways? One way is just to ignore them, I
> >>> know, but I would not want a trickle to turn into a flood.

> >> Is your web space provided via PlusNet ?
> >> If so you could report possible suspicious activity.

> > Yes ... but I doubt they would be interested at the current level.

> I meant to say via PlusNet's Community Forum, which often gets a
> faster response then ringing the normal customer support, as they
> frequently don't seem to know some users have web space! as you
> use a legacy system i.e. force9

Aaah yes - that is a good idea. Thanks.

--
Martin Avison
Note that unfortunately this email address will become invalid
without notice if (when) any spam is received.

Re: Go-http-client

<kGr*WKPBz@news.chiark.greenend.org.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1193&group=comp.sys.acorn.networking#1193

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!news.szaf.org!nntp-feed.chiark.greenend.org.uk!ewrotcd!.POSTED.chiark.greenend.org.uk!not-for-mail
From: theom+news@chiark.greenend.org.uk (Theo)
Newsgroups: comp.sys.acorn.networking
Subject: Re: Go-http-client
Date: 31 Jan 2024 15:18:26 +0000 (GMT)
Organization: University of Cambridge, England
Message-ID: <kGr*WKPBz@news.chiark.greenend.org.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk>
Injection-Info: chiark.greenend.org.uk; posting-host="chiark.greenend.org.uk:212.13.197.229";
logging-data="7851"; mail-complaints-to="abuse@chiark.greenend.org.uk"
User-Agent: tin/1.8.3-20070201 ("Scotasay") (UNIX) (Linux/5.10.0-22-amd64 (x86_64))
Originator: theom@chiark.greenend.org.uk ([212.13.197.229])
 by: Theo - Wed, 31 Jan 2024 15:18 UTC

Martin <News03@avisoft.f9.co.uk> wrote:
> In the last couple of days my website has had an increase in traffic,
> from about 30 different IP addresses, all with a User-Agent of
> "Go-http-client/1.1".
>
> Each starts with a "GET / HTTP/1.1" request, with various User-Agents,
> including Windows, Linux & MaxOS. If that works (as it will) it then
> issues GETs for about 30 varied files, then stops.
>
> It seems that Go-http-client is a package which "provides HTTP client
> and server implementations" but it is suddenly being used by lots of
> IPs in a suspicious way.
>
> Anyone else seen this?

Looking at the riscos.info logs, there's a variety of entries matching that.
Since the start of December there have been 1632 requests.
Some examples (I have redacted part of the IPs, but they're all with
completely different prefixes):

Testing if the site will proxy for another:

106.2.x.x - - [19/Jan/2024:11:14:23 +0000] "CONNECT www.whitehouse.gov:443 HTTP/1.1" 302 292 "-" "Go-http-client/1.1"
80.91.x.x - - [20/Jan/2024:11:30:17 +0000] "CONNECT google.com:443 HTTP/1.1" 302 284 "-" "Go-http-client/1.1"

Testing for vulnerable pages:

91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //alfa.php HTTP/1.1" 404 287 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //doc.php HTTP/1.1" 404 286 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //marijuana.php HTTP/1.1" 404 292 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //mini.php HTTP/1.1" 404 287 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //shell.php HTTP/1.1" 404 288 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //small.php HTTP/1.1" 404 288 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //wso.php HTTP/1.1" 404 286 "-" "Go-http-client/1.1"
91.92.x.x - - [14/Dec/2023:08:14:25 +0000] "GET //wp-info.php HTTP/1.1" 404 290 "-" "Go-http-client/1.1"

A legit access followed by some probing:

195.20.x.x - - [06/Dec/2023:05:14:05 +0000] "GET / HTTP/1.1" 302 287 "-" "Go-http-client/1.1"
195.20.x.x - - [06/Dec/2023:05:14:16 +0000] "GET / HTTP/1.1" 301 26 "-" "Go-http-client/1.1"
195.20.x.x - - [06/Dec/2023:05:14:17 +0000] "GET /index.php/RISC_OS HTTP/1.1" 200 7210 "http://www.riscos.info/" "Go-http-client/1.1"
195.20.x.x - - [06/Dec/2023:05:14:19 +0000] "GET /+CSCOE+/logon.html HTTP/1.1" 302 305 "-" "Go-http-client/1.1"
195.20.x.x - - [06/Dec/2023:05:14:50 +0000] "GET /global-protect/login.esp HTTP/1.1" 302 311 "-" "Go-http-client/1.1"
195.20.x.x - - [06/Dec/2023:05:14:50 +0000] "GET /global-protect/login.esp HTTP/1.1" 404 303 "-" "Go-http-client/1.1"

The ownership of some of those prefixes is:

netname: Netease-Network
descr: Guangzhou NetEase Computer System Co.,Ltd
country: CN

organisation: ORG-FZTA3-RIPE
org-name: Ferdinand Zink trading as Tube-Hosting
country: DE

organisation: ORG-LA1853-RIPE
org-name: Limenet
org-type: OTHER
address: 84 W Broadway, Ste 200
address: 03038 Derry
address: United States of America

organisation: ORG-GL496-RIPE
org-name: Shelter LLC
country: RU

so not a geographic pattern.

> They obviously do not abide by robots/txt (or even read it), so the
> only way I know to block them is to add them to /htaccess as deny
> froms - some have the same top two numbers.
>
> Are there any better ways?
> One way is just to ignore them, I know, but I would not want a trickle
> to turn into a flood.

They appear to just be probing for vulnerable sites. I don't think anything
you do will affect the rate, they are just picking targets at random. I'd
guess it's just coming from a malware toolkit of some kind that happens to
be programmed in Go, possibly running through a botnet.

I doubt any kind of IP filtering is going to work. So it boils down to
hot they're bothering you - filling up the log (something that's been
happening to riscos.info a few times of late), eating your bandwidth or CPU.

There are too many IPs to block in firewall rules. You could block accesses
from Go-http-client, but I think it would still log as blocked. Mostly from
the above they aren't actually interacting with real content on the site so
the CPU is not doing much serving real pages, and the 302/404 traffic is
minimal (~300 bytes per request). Maybe some kind of adaptive
firewalling/rate limiting, but that would probably block genuine traffic.

Unless you have scripts on your site that are actually vulnerable (in which
case you should fix them) I'm not sure there's much to be done. If you
provide a site on the internet, people (or bots) on the internet connect to
it. That's the deal.

Theo

Re: Go-http-client

<5b2b71bd0dNews03@avisoft.f9.co.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1194&group=comp.sys.acorn.networking#1194

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!news.furie.org.uk!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!feeder.usenetexpress.com!tr1.iad1.usenetexpress.com!69.80.99.23.MISMATCH!Xl.tags.giganews.com!local-2.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Wed, 31 Jan 2024 17:04:00 +0000
From: News03@avisoft.f9.co.uk (Martin)
Subject: Re: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Wed, 31 Jan 2024 16:56:24 +0000 (GMT)
Message-ID: <5b2b71bd0dNews03@avisoft.f9.co.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <kGr*WKPBz@news.chiark.greenend.org.uk>
User-Agent: Pluto/3.21a (RISC OS/5.29) NewsHound/v1.54
Organization: None
Lines: 89
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-9Qh8N+/NSDD00Eqa8XLsOzcsnOdIoiUTVOD9WHYIO42rx42qj/Ml3LzXohG2Y13UDaMSwJwsjJxRMsV!ZP40stLuibgk/K0FIOMrcovK+Gd6uLeG5iUouYg3RWbXuIRSg3PVoRe45yLNoeSVLxJk0XSYrV51!NJQ=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Martin - Wed, 31 Jan 2024 16:56 UTC

In article <kGr*WKPBz@news.chiark.greenend.org.uk>,
Theo <theom+news@chiark.greenend.org.uk> wrote:
> Martin <News03@avisoft.f9.co.uk> wrote:
> > In the last couple of days my website has had an increase in
> > traffic, from about 30 different IP addresses, all with a
> > User-Agent of "Go-http-client/1.1".
> >
> > Each starts with a "GET / HTTP/1.1" request, with various
> > User-Agents, including Windows, Linux & MaxOS. If that works (as
> > it will) it then issues GETs for about 30 varied files, then
> > stops.
> >
> > It seems that Go-http-client is a package which "provides HTTP
> > client and server implementations" but it is suddenly being used
> > by lots of IPs in a suspicious way.
> >
> > Anyone else seen this?

> Looking at the riscos.info logs, there's a variety of entries
> matching that. Since the start of December there have been 1632
> requests.

I have had over 800 in the previous 2 days.

> Some examples (I have redacted part of the IPs, but
> they're all with completely different prefixes):

> Testing if the site will proxy for another:

Not seen any like that.

> Testing for vulnerable pages:

Or that!

> A legit access followed by some probing:

All mine have been to existing pages or files - all returned with
status 200.

> The ownership of some of those prefixes is:

Mine seemed to be allocated to Asia Pacific (APNIC).
Difficult these days to get more precise information.

> They appear to just be probing for vulnerable sites. I don't think
> anything you do will affect the rate, they are just picking targets
> at random. I'd guess it's just coming from a malware toolkit of
> some kind that happens to be programmed in Go, possibly running
> through a botnet.

Probably - Googling 'botnet using go-http-client' gives lots of hits!

> I doubt any kind of IP filtering is going to work. So it boils
> down to hot they're bothering you - filling up the log (something
> that's been happening to riscos.info a few times of late), eating
> your bandwidth or CPU.

They are certainly vastly increasing my bandwidth usage, though I have
not quantified it.

> There are too many IPs to block in firewall rules. You could block
> accesses from Go-http-client, but I think it would still log as
> blocked. Mostly from the above they aren't actually interacting
> with real content on the site so the CPU is not doing much serving
> real pages, and the 302/404 traffic is minimal (~300 bytes per
> request). Maybe some kind of adaptive firewalling/rate limiting,
> but that would probably block genuine traffic.

MIne are downloading real files (including zips) with status 200.

> Unless you have scripts on your site that are actually vulnerable
> (in which case you should fix them) I'm not sure there's much to be
> done.

No scripts here. Just plain HTML.

> If you provide a site on the internet, people (or bots) on
> the internet connect to it. That's the deal.

Yes, indeed. I will just keep an eye open for the moment.

Thanks
Martin

--
Martin Avison
Note that unfortunately this email address will become invalid
without notice if (when) any spam is received.

Re: Go-http-client

<jGr*msQBz@news.chiark.greenend.org.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1195&group=comp.sys.acorn.networking#1195

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!news.nntp4.net!nntp.terraraq.uk!nntp-feed.chiark.greenend.org.uk!ewrotcd!.POSTED.chiark.greenend.org.uk!not-for-mail
From: theom+news@chiark.greenend.org.uk (Theo)
Newsgroups: comp.sys.acorn.networking
Subject: Re: Go-http-client
Date: 31 Jan 2024 18:32:17 +0000 (GMT)
Organization: University of Cambridge, England
Message-ID: <jGr*msQBz@news.chiark.greenend.org.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <kGr*WKPBz@news.chiark.greenend.org.uk> <5b2b71bd0dNews03@avisoft.f9.co.uk>
Injection-Info: chiark.greenend.org.uk; posting-host="chiark.greenend.org.uk:212.13.197.229";
logging-data="3296"; mail-complaints-to="abuse@chiark.greenend.org.uk"
User-Agent: tin/1.8.3-20070201 ("Scotasay") (UNIX) (Linux/5.10.0-22-amd64 (x86_64))
Originator: theom@chiark.greenend.org.uk ([212.13.197.229])
 by: Theo - Wed, 31 Jan 2024 18:32 UTC

Martin <News03@avisoft.f9.co.uk> wrote:
> In article <kGr*WKPBz@news.chiark.greenend.org.uk>,
> Theo <theom+news@chiark.greenend.org.uk> wrote:
>
> I have had over 800 in the previous 2 days.
>
> All mine have been to existing pages or files - all returned with
> status 200.
>
> Mine seemed to be allocated to Asia Pacific (APNIC).
> Difficult these days to get more precise information.

Try a 'whois' on the IP, it should tell you the Autonomous System (AS) which
owns the IP range. That is usually an ISP but can sometimes be a company.
Of course you'd need to talk to them to go any further.

> MIne are downloading real files (including zips) with status 200.
>
> No scripts here. Just plain HTML.

I would guess somebody's using a tool to crawl your site, for what purpose
we don't know. It happens to be written using a popular Go HTTP library and
they didn't change the User-Agent. It doesn't sound like the same kind of
probing I'm seeing.

I've been seeing a lot of crawls from AI companies (Bytedance, Facebook) who
are sucking data for training AI models. Perhaps they are doing something
similar.

Theo

Re: Go-http-client

<5b369f6248News03@avisoft.f9.co.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1196&group=comp.sys.acorn.networking#1196

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!weretis.net!feeder6.news.weretis.net!border-2.nntp.ord.giganews.com!nntp.giganews.com!Xl.tags.giganews.com!local-1.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Thu, 22 Feb 2024 09:53:58 +0000
From: News03@avisoft.f9.co.uk (Martin)
Subject: Re: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Thu, 22 Feb 2024 09:53:09 +0000 (GMT)
Message-ID: <5b369f6248News03@avisoft.f9.co.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk>
User-Agent: Pluto/3.21a (RISC OS/5.29) NewsHound/v1.54
Organization: None
Lines: 40
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-RQg0aFF26j1MCyThvlUYVUXNY8jFVe8lCPsIEkEo2fcjdKuNpOD0r9/WcZR4MimmFZJ6OlJp0IsRGgz!ikwHsHMOazE16HcG9sbnS6x2E3VjEXq3vOOQ8OKS4aoyP1qEBHvSU/YyAKn09xgVsS3KVkY5SoYV!SYk=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Martin - Thu, 22 Feb 2024 09:53 UTC

In article <5b2b4df63fNews03@avisoft.f9.co.uk>,
Martin <News03@avisoft.f9.co.uk> wrote:
> In the last couple of days my website has had an increase in
> traffic, from about 30 different IP addresses, all with a
> User-Agent of "Go-http-client/1.1".

> Each starts with a "GET / HTTP/1.1" request, with various
> User-Agents, including Windows, Linux & MaxOS. If that works (as it
> will) it then issues GETs for about 30 varied files, then stops.

> It seems that Go-http-client is a package which "provides HTTP
> client and server implementations" but it is suddenly being used by
> lots of IPs in a suspicious way.

> Anyone else seen this?

> They obviously do not abide by robots/txt (or even read it), so the
> only way I know to block them is to add them to /htaccess as deny
> froms - some have the same top two numbers.

> Are there any better ways? One way is just to ignore them, I know,
> but I would not want a trickle to turn into a flood.

The trickle continued, some days far outnumbering other requests.

But I have found a way to stop them! I added to my ./htaccess file...

RewriteCond %{HTTP_USER_AGENT} "=Go-http-client/1.1"
RewriteRule .* - [F,L]

.... now returns 403 Forbidden. Stopped 260 in 12 hours yesterday.

This certainly works on PlusNet - may or may not on other ISPs.

Martin

--
Martin Avison
Note that unfortunately this email address will become invalid
without notice if (when) any spam is received.

Re: Go-http-client

<5b37253c5anews*@Torrens.org>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1197&group=comp.sys.acorn.networking#1197

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!border-2.nntp.ord.giganews.com!nntp.giganews.com!Xl.tags.giganews.com!local-1.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Fri, 23 Feb 2024 11:36:03 +0000
From: News+19772@Torrens.org (Richard Torrens (News))
Subject: Re: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Fri, 23 Feb 2024 10:15:10 +0000 (GMT)
Message-ID: <5b37253c5anews*@Torrens.org>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <5b369f6248News03@avisoft.f9.co.uk>
User-Agent: Pluto/3.20 (RISC OS/5.28) NewsHound/v1.50-32
Organization: Torrens
Lines: 30
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-YzIzuNF7/Thqu5iseJ73bRdieqC7lA0/HEQ7rnG5tQLrvKQaaLZvcOLPXWRx7KSDlXfGEULKSzOthXI!8ta5L3LRNF00pejSbMDruxDxRRNJHqD5H8+o5rdCGbSjcS9LIU28loThlSsuxu8g18ZW
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Richard Torrens (New - Fri, 23 Feb 2024 10:15 UTC

In article <5b369f6248News03@avisoft.f9.co.uk>,
Martin <News03@avisoft.f9.co.uk> wrote:
> The trickle continued, some days far outnumbering other requests.

> But I have found a way to stop them! I added to my ./htaccess file...

> RewriteCond %{HTTP_USER_AGENT} "=Go-http-client/1.1"
> RewriteRule .* - [F,L]

> ... now returns 403 Forbidden. Stopped 260 in 12 hours yesterday.

> This certainly works on PlusNet - may or may not on other ISPs.

> Martin

https://user-agents.net/string/go-http-client-1-1

gives info on this. But these requests may not be evil. I would guess
mostly neutral.

There are s many bots and crawlers these days log files are of little
practical use!

--
------------------------------------------------------------------
Richard Torrens. News email address is valid - for a limited time only.
You must use the full News+number@Torrens.org as in the From address.
http://www.Torrens.org for genealogy, natural history, wild food, walks, cats
and more!

Re: Go-http-client

<5b372e7c90News03@avisoft.f9.co.uk>

  copy mid

https://news.novabbs.org/devel/article-flat.php?id=1198&group=comp.sys.acorn.networking#1198

  copy link   Newsgroups: comp.sys.acorn.networking
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!border-2.nntp.ord.giganews.com!nntp.giganews.com!Xl.tags.giganews.com!local-1.nntp.ord.giganews.com!nntp.brightview.co.uk!news.brightview.co.uk.POSTED!not-for-mail
NNTP-Posting-Date: Fri, 23 Feb 2024 11:58:34 +0000
From: News03@avisoft.f9.co.uk (Martin)
Subject: Re: Go-http-client
Newsgroups: comp.sys.acorn.networking
Date: Fri, 23 Feb 2024 11:56:13 +0000 (GMT)
Message-ID: <5b372e7c90News03@avisoft.f9.co.uk>
References: <5b2b4df63fNews03@avisoft.f9.co.uk> <5b369f6248News03@avisoft.f9.co.uk> <5b37253c5anews*@Torrens.org>
User-Agent: Pluto/3.21a (RISC OS/5.29) NewsHound/v1.54
Organization: None
Lines: 41
X-Usenet-Provider: http://www.giganews.com
X-Trace: sv3-VHvrXDc4WZreQi0ALmOg30N6USPEVLYGEHaFEdRffdiK2C8MVpm5RRJaLPFz3/NUYObb5oSX+fQcDjK!RbQUBHKiknqkKl1V9fgRdAV6Hvqd7tzmkWzgdOBYnDeoVqs99OoDjcbWK+xmc8dcnraDFgUerk1F!K9c=
X-Abuse-and-DMCA-Info: Please be sure to forward a copy of ALL headers
X-Abuse-and-DMCA-Info: Otherwise we will be unable to process your complaint properly
X-Postfilter: 1.3.40
 by: Martin - Fri, 23 Feb 2024 11:56 UTC

In article <5b37253c5anews*@Torrens.org>,
Richard Torrens (News) <News+19772@Torrens.org> wrote:
> In article <5b369f6248News03@avisoft.f9.co.uk>,
> Martin <News03@avisoft.f9.co.uk> wrote:
> > The trickle continued, some days far outnumbering other requests.

> > But I have found a way to stop them! I added to my ./htaccess
> > file...

> > RewriteCond %{HTTP_USER_AGENT} "=Go-http-client/1.1"
> > RewriteRule .* - [F,L]

> > ... now returns 403 Forbidden. Stopped 260 in 12 hours yesterday.
> > This certainly works on PlusNet - may or may not on other ISPs.

> https://user-agents.net/string/go-http-client-1-1
> gives info on this. But these requests may not be evil. I would
> guess mostly neutral.

Of 1209 requests yesterday, 1117 were this user-agent - over 96%.

They were from a wide variety of IP addresses, with anything from 2 to
30 requests each, to a similar subset of pages.

None of them looked at robots/txt, so I would say that in my
experience, they were all spurious, probably malicious.

> There are so many bots and crawlers these days log files are of
> little practical use!

I have rarely looked at mine for ages ... until there was massive
increase in their daily sizes!

Anyway, they all get Forbidden from me now!

Martin

--
Martin Avison
Note that unfortunately this email address will become invalid
without notice if (when) any spam is received.

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor