I bit the bullet yet again and allowed the badboy to slip out so I could take a look at what he was sending. Thinking I might get an idea of what is going on, I ran until I saw a 67... or a 69... address and then locked down the system again. This is a clumbsy operation, but I did get something.
When I went here..
http://www.costco.com (http://170.167.8.1/)
Firefox generates this address..
67.29.128.59:80
..which had a UDP (just below) packet followed by several sets comprising a short TCP and a long TCP packet.
The preceeding UDP packet..
: 9 CKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA ! UDP
Below are two of the long TCP packets..
P }OD P P & GET /Images/Content/Search/147756f.jpg HTTP/1.1 Host: content.costco.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1 Accept: image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://www.costco.com/Common/Search.asp ... Home&pos=3
P o P GET /Images/Content/Search/980479f.jpg HTTP/1.1 Host: content.costco.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1 Accept: image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://www.costco.com/Common/Search.asp ... Home&pos=3
The GET is a typical request sent to a webserver--only this was sent to the address above. This probably resends to the original server.
When I assemble the host (content.costco.com) and the GET command (/Images/Content/Search/147756f.jpg), I "get" a picture of a piano bench which is probably part of the web page..
http://content.costco.com/Images/Conten ... 47756f.jpg
This probably leads to capturing the jump to wherever the picture leads. I think this is definitely a tracker.
Since I spent hours updating this system to get the OS current, I am loath to do a total regen. What do you think I could do next?
Any encouragement is welcome.
Cheers,
Buzz.