Skip to content

July 18, 2009

Malformed HTTP Protocol from www.assoc-amazon.com

by Joe Kuan

NetworkingAgain, I was diagnosing HTTP protocol traffic on my local network and I noticed something really strange that disturbed the HTTP protocol analyser module in AppQoS. A serious malformed response packet was found from www.assoc-amazon.com. The response headers were formed without probably ended with CR, only LF and the misspell of the ‘Connection’ header. Here shows an example of the response packet from the site using Wireshark/Ethereal.

screen1

The GET request message for this response is:

http://www.assoc-amazon.com/e/ir?t=matoperef-20&l=ur2&o=1

You can still get the malformed packet even just querying http://www.assoc-amazon.com. If you want to know more what this site is about, then this blog explains it all.

I work for iTrinegy and here are my other technical blogs

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

Note: HTML is allowed. Your email address will never be published.

Subscribe to comments

%d bloggers like this: