tobyandlauren.id.au

BLOG PROJECTS FAMILY TREE
Subscribe by RSS feed

notified- and verify- requests

It looks like a company called Blue Coat sells a product called ProxySG which is designed to help keep web applications secure by passing all requests through a proxy. It would seem, though, that URL requests along the lines of /verify-SNL_Splash?aHR0cDovL3d3dy50aGlzaXNob21lLmNvbS5hdS8= are internal requests made by the proxy appliance, and are allowed through the system unfiltered (and may even cause the appliance to make changes to the proxy settings).

My hypothesis then is that these requests are part of the daily detritus of botnet request-spamming, trying to find out which systems use ProxySG, and then reporting back to their owners for nefarious purposes. Or something.

deadsea posted here a list of queries that have turned up:
notified-AcceptableUse
notified-Adults_Welcome_Page
notified-AU_Notice
notified-Ceridian_CAUP
notified-Compliance
notified-Compliance-of-Policy
notified-Compliance_Page
notified-COMPLIANCE-PAGE
notified-ComplianceSplash
notified-Internet_Compliancy_page
notified-NotifyUser1
notified-NotifyUtilisateurs
notified-page_de_comformite
notified-SNL_Splash
notified-SplashPage
notified-Splash_Page_Minimal
notified-SplashPages
notified-TermsAndAgreement
notified-VCN_Strict