<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
<?xml-stylesheet type="text/css" href="http://netalyzr.icsi.berkeley.edu/blog/styles/feed.css"?>


<title type="html">Netalyzr News</title>
<subtitle type="html">News and updates around the ICSI Netalyzr</subtitle>
<link rel="alternate" type="text/html" href="http://netalyzr.icsi.berkeley.edu/blog"/>
<link rel="self" type="application/atom+xml" href="http://netalyzr.icsi.berkeley.edu/blog/atom.xml"/>
<updated>2011-12-09T16:49:06-08:00</updated>
<author>
<name>The Netalyzr Team</name>
<uri>http://netalyzr.icsi.berkeley.edu/blog</uri>
</author>
<id>http://netalyzr.icsi.berkeley.edu/blog/</id>
<generator uri="http://nanoblogger.sourceforge.net" version="3.4.2">
NanoBlogger
</generator>

<entry>
<title type="html">A new release, celebrating 400,000 sessions!</title>
<author>
<name></name>
</author>
<link rel="alternate" type="text/html" href="http://netalyzr.icsi.berkeley.edu/blog/archives/2011/12/09/a_new_release_celebrating_400000_sessions/index.html"/>

<id>http://netalyzr.icsi.berkeley.edu/blog/archives/2011/12/09/a_new_release_celebrating_400000_sessions/index.html</id>
<published>2011-12-09T16:47:56-08:00</published>
<updated>2011-12-09T16:47:56-08:00</updated>
<category term="release" />
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">

<p>
Today we pushed out a round of updates to the Netalyzr codebase.  Most
importantly, we dropped the HTTP content test that downloads the <a
href="http://www.eicar.org/86-0-Intended-use.html">EICAR test
virus</a>.  Even though this file is completely harmless, some
anti-virus systems take it just as seriously as real malware.  When
detecting the file, these systems cut off all of Netalyzr's
connectivity, causing a failure of the test session to complete.  Many
thanks to our users for alerting us to this problem&mdash;it's a great
example of the unexpected things we encounter during the tests.
</p>

<p>
In terms of new features, we have added initial testing of DNS root
server behavior.  Netalyzr now checks whether it can actually reach
all DNS root servers and whether querying them works as intended.  We
have also beefed up our regression testing and as a consequence fixed
a number of result rendering glitches in the test reports.
</p>

<p> 
A few weeks ago the Netalyzr session counter crossed the 400,000 mark.
We would like to take this opportunity for a sincere Thank You to all
of our users for continuing to run Netalyzr!  We always welcome your
feedback and suggestions at 
<a href="mailto:netalyzr-help@icsi.berkeley.edu">netalyzr-help@icsi.berkeley.edu</a>.
</p>
</div>
</content>

</entry>
<entry>
<title type="html">Power outage at ICSI</title>
<author>
<name></name>
</author>
<link rel="alternate" type="text/html" href="http://netalyzr.icsi.berkeley.edu/blog/archives/2011/10/12/power_outage_at_icsi/index.html"/>

<id>http://netalyzr.icsi.berkeley.edu/blog/archives/2011/10/12/power_outage_at_icsi/index.html</id>
<published>2011-10-12T09:52:13-08:00</published>
<updated>2011-10-12T09:52:13-08:00</updated>
<category term="outage" />
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">

<p> 
Yesterday around 4pm PDT the downtown Berkeley area, including ICSI,
suffered an unannounced power outage.  During the 6 following
hours that the local power utility took to restore power, the Netalyzr site
remained unavailable. We apologize for the inconvenience.
</p>
</div>
</content>

</entry>
<entry>
<title type="html">Network outage at ICSI</title>
<author>
<name></name>
</author>
<link rel="alternate" type="text/html" href="http://netalyzr.icsi.berkeley.edu/blog/archives/2011/10/03/network_outage_at_icsi/index.html"/>

<id>http://netalyzr.icsi.berkeley.edu/blog/archives/2011/10/03/network_outage_at_icsi/index.html</id>
<published>2011-10-03T11:00:37-08:00</published>
<updated>2011-10-03T11:00:37-08:00</updated>
<category term="outage" />
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">

<p> 
Around 4am PST today, ICSI suffered an unannounced network
connectivity outage that lasted approximately four hours.  We
apologize for the inconvenience.
</p>
</div>
</content>

</entry>
<entry>
<title type="html">Updated analysis of Paxfire-related search hijackings</title>
<author>
<name></name>
</author>
<link rel="alternate" type="text/html" href="http://netalyzr.icsi.berkeley.edu/blog/archives/2011/08/10/updated_analysis_of_paxfire-related_search_hijackings/index.html"/>

<id>http://netalyzr.icsi.berkeley.edu/blog/archives/2011/08/10/updated_analysis_of_paxfire-related_search_hijackings/index.html</id>
<published>2011-08-10T17:31:19-08:00</published>
<updated>2011-08-10T17:31:19-08:00</updated>
<category term="newscientist" />
<category term="paxfire" />
<category term="eff" />
<content type="xhtml">
<div xmlns="http://www.w3.org/1999/xhtml">

<p>
As we previously 
<a href="http://netalyzr.icsi.berkeley.edu/blog/archives/2011/08/05/netalyzr_reveals_isps_hijacking_users_web_search_queries/index.html">reported</a>
in cooperation with
the <a href="http://www.eff.org/deeplinks/2011/07/widespread-search-hijacking-in-the-us">EFF</a>
and <a href="http://www.newscientist.com/article/dn20768-us-internet-providers-hijacking-users-search-queries.html">New Scientist</a>, 
Netalyzr's results identified multiple US ISPs that appear to monetize their
users' web searches using affiliate marketing programs by redirecting
some of their users' web searches using services provided by a company
called Paxfire.
</p>

<p> At this week's
<a href="http://www.usenix.org/events/foci11/">FOCI Workshop</a> 
we presented 
<a href="http://www.icir.org/christian/publications/2011-foci-dns.pdf">a paper</a>
that describes the DNS error traffic monetization business
that companies such as Paxfire engage in, and also in part describe our
measurements of search
redirections.  We'd like to take this opportunity to provide an update
on the redirections we observe.
</p>

<p> Starting on July 26th, we began to identify web search keywords
that triggered redirections.  The redirections take place in two
stages, a first one using DNS to send the user's HTTP request to a
Paxfire-controlled proxy, and the second by the proxy not relaying the
requests to the intended search engines but instead returning HTTP
redirects through the affiliate programs involved.  Using popular
domain names provided by Alexa, we identified 165 such keywords.
Given interest in the set of keywords from multiple parties, we now make
<a href="http://netalyzr.icsi.berkeley.edu/paxfire-keywords.txt">the keyword list</a>
available.  If you have additional questions regarding our measurements 
or dataset, please contact us by email at
<a href="mailto:netalyzr-help@icsi.berkeley.edu?Subject=[Search%20Redirection%20Measurements]">netalyzr-help@icsi.berkeley.edu</a>
and we will see if we are able to accommodate your request.
</p>

<p> On August 5th, 24 hours after our public disclosure, Paxfire
limited or halted the redirections through affiliate programs.  We
currently no longer observe any HTTP redirections through affiliate
programs, suggesting that Paxfire discontinued the practice.
However, the following
ISPs still appear to redirect some or all traffic destined to
Yahoo's and Bing's search engines through Paxfire's proxies:</P>

<ul>
<li>Cogent</li>
<li>Cincinnatti Bell</li>
<li>RCN</li>
<li>Frontier</li>
<li>Megapath</li>
<li>Paetec</li>
<li>Wide Open West</li>
<li>XO</li>
</ul>

<p>It furthermore appears as though Hughes (DirecPC) has stopped
proxying search requests through Paxfire.  For the remaining ISPs we
do not possess sufficient data.</p>

<p>We currently do not include explicit testing of Paxfire's
keyword-based HTTP redirections in Netalyzr.  Until we do so, we would
appreciate if tech-savvy customers of the involved ISPs could contact
us by email at <a
href="mailto:netalyzr-help@icsi.berkeley.edu?Subject=[Search%20Redirection%20Measurements]">netalyzr-help@icsi.berkeley.edu</a>.
</p>
</div>
</content>

</entry>

</feed>

