<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP GET Request on port 53 in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177494#M4206</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Red text this is follow TCP session from Wire Shark&lt;/P&gt;
&lt;P&gt;First picture (background)&lt;/P&gt;
&lt;P&gt;Source IP 10.7.2.33&lt;/P&gt;
&lt;P&gt;Destination IP &amp;nbsp;208.67.222.222 (resolver1.opendns.com)&lt;/P&gt;
&lt;P&gt;Source Port 55389&lt;/P&gt;
&lt;P&gt;Destination Port 53&lt;/P&gt;
&lt;P&gt;Second picture (where red string we see)&lt;/P&gt;
&lt;P&gt;Right click and chose follow TCp session and we get HTTP format&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GET - URI request&lt;/P&gt;
&lt;P&gt;Host - destination host&lt;/P&gt;
&lt;P&gt;User agent - mac OS browser&lt;/P&gt;
&lt;P&gt;refer&lt;/P&gt;
&lt;P&gt;and so on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 07 Jun 2017 12:42:57 GMT</pubDate>
    <dc:creator>mparp</dc:creator>
    <dc:date>2017-06-07T12:42:57Z</dc:date>
    <item>
      <title>HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177490#M4202</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have a question. In my network I have IDS systems and some connection to&amp;nbsp;208.67.222.222 blocked because they are destined to TCP port 53 but connection is HTTP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example (HTTP header from PCAP):&lt;/P&gt;
&lt;P&gt;GET /getadmarker2.png HTTP/1.1&lt;/P&gt;
&lt;P&gt;Host: choices.truste.com&lt;/P&gt;
&lt;P&gt;Connection: keep-alive&lt;/P&gt;
&lt;P&gt;User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36&lt;/P&gt;
&lt;P&gt;Accept: image/webp,image/*,*/*;q=0.8&lt;/P&gt;
&lt;P&gt;Referer: &lt;A href="http://www.webmd.com/skin-problems-and-treatments/news/20110204/faq-pesky-rashes-from-plants" rel="nofollow noreferrer"&gt;http://www.webmd.com/skin-problems-and-treatments/news/20110204/faq-pesky-rashes-from-plants&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Accept-Encoding: gzip, deflate, sdch&lt;/P&gt;
&lt;P&gt;Accept-Language: en-US,en;q=0.8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you explain me what is going on, why I see HTTP connections by port 53 (which is DNS originally) destined to OpenDNS (Umbrella) server 208.67.222.222&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What technology, service, feature behind this connection. It looks legitimate but I want to know what is going on and if it is legit traffic I should add an negation in my signatures&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;Max&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Jun 2017 16:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177490#M4202</guid>
      <dc:creator>mparp</dc:creator>
      <dc:date>2017-06-06T16:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177491#M4203</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;"&lt;EM&gt;why I see HTTP connections by port 53 (which is DNS originally) destined to OpenDNS (Umbrella) server 208.67.222.222&amp;nbsp;&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Sorry, dude, I do not see this from your PCAP HTTP header.&amp;nbsp; No HTTP port 53 mentioned, all goes via port 80.&lt;/P&gt;
&lt;P&gt;Pretty clear that you might see also DNS traffic over port 53 (UDP, maybe TCP) to 208.67.222.222 at the same time, or better milliseconds before, because this domain choices.truste.com needs to be resolved, of course.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Jun 2017 19:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177491#M4203</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2017-06-06T19:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177492#M4204</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="support.opendns.com_hc_user_images_K40LHL5AS9b3WSiyO5t8cg.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/228332i63ECB145E3F41D05/image-size/large?v=v2&amp;amp;px=999" role="button" title="support.opendns.com_hc_user_images_K40LHL5AS9b3WSiyO5t8cg.png" alt="support.opendns.com_hc_user_images_K40LHL5AS9b3WSiyO5t8cg.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As we can see destination host is&amp;nbsp;208.67.222.222 and destination port is TCP 53 but we see HTTP&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Jun 2017 20:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177492#M4204</guid>
      <dc:creator>mparp</dc:creator>
      <dc:date>2017-06-06T20:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177493#M4205</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Sorry, still not seeing HTTP and 53.&amp;nbsp; &lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Jun 2017 06:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177493#M4205</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2017-06-07T06:56:53Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177494#M4206</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Red text this is follow TCP session from Wire Shark&lt;/P&gt;
&lt;P&gt;First picture (background)&lt;/P&gt;
&lt;P&gt;Source IP 10.7.2.33&lt;/P&gt;
&lt;P&gt;Destination IP &amp;nbsp;208.67.222.222 (resolver1.opendns.com)&lt;/P&gt;
&lt;P&gt;Source Port 55389&lt;/P&gt;
&lt;P&gt;Destination Port 53&lt;/P&gt;
&lt;P&gt;Second picture (where red string we see)&lt;/P&gt;
&lt;P&gt;Right click and chose follow TCp session and we get HTTP format&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GET - URI request&lt;/P&gt;
&lt;P&gt;Host - destination host&lt;/P&gt;
&lt;P&gt;User agent - mac OS browser&lt;/P&gt;
&lt;P&gt;refer&lt;/P&gt;
&lt;P&gt;and so on&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Max&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Jun 2017 12:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177494#M4206</guid>
      <dc:creator>mparp</dc:creator>
      <dc:date>2017-06-07T12:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177495#M4207</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;"&lt;EM&gt;First picture (background)&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;This is the DNS query to OpenDNS.&amp;nbsp; I can see also the DNS response.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;Second picture (where red string we see)&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;Yes, fine, this is the HTTP GET request.&amp;nbsp; I do not see the "Dst Port" on the picture in the background, because it is outside.&amp;nbsp; But I bet this is port 80, not 53.&amp;nbsp; And even if it displayed 53, this is nonsense and would not work.&amp;nbsp; You would not be able to visit &lt;A href="http://choices.truste.com/getadmarker2.png%C2%A0" rel="nofollow noreferrer"&gt;http://choices.truste.com/getadmarker2.png&amp;nbsp;&lt;/A&gt; -&amp;nbsp; It may be a glitch with PCAP, but is not reality.&lt;/P&gt;
&lt;P&gt;Also, resolver1.opendns.com does not and cannot handle HTTP traffic on port 53 (or 80).&lt;BR /&gt;Try it out: &lt;A href="http://resolver1.opendns.com:53/" rel="nofollow noreferrer"&gt;http://resolver1.opendns.com:53/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Back to your question "&lt;EM&gt;What technology, service, feature behind this connection&lt;/EM&gt;":&lt;/P&gt;
&lt;P&gt;The "feature" is a bug in PCAP.&amp;nbsp; Try with another sniffer.&amp;nbsp; &lt;STRONG&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Jun 2017 13:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177495#M4207</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2017-06-07T13:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177496#M4208</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/hc/en-us/profiles/309368103-rotblitz" rel="nofollow noreferrer"&gt;rotblitz&lt;/A&gt;, Looks like I do not understand you.&lt;/P&gt;
&lt;P&gt;Picture 1: Full PCAP&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="support.opendns.com_hc_user_images_dbI_YQYgwmRui-eppax7FQ.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/228498iC0B7966CDD22BEA7/image-size/large?v=v2&amp;amp;px=999" role="button" title="support.opendns.com_hc_user_images_dbI_YQYgwmRui-eppax7FQ.png" alt="support.opendns.com_hc_user_images_dbI_YQYgwmRui-eppax7FQ.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Pic -2 follow TCP stream for Pic -1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="support.opendns.com_hc_user_images_beRJlp-J1vin-WSsnfh69Q.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/228337iE553FCAAD981A659/image-size/large?v=v2&amp;amp;px=999" role="button" title="support.opendns.com_hc_user_images_beRJlp-J1vin-WSsnfh69Q.png" alt="support.opendns.com_hc_user_images_beRJlp-J1vin-WSsnfh69Q.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Picture 3&amp;nbsp;&amp;nbsp;result from follow TCP sream for Pic - 1&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="support.opendns.com_hc_user_images_t5aLvzP6BGuDIQ2EoJYXQA.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/228056i7ECC4CB00351BF1E/image-size/large?v=v2&amp;amp;px=999" role="button" title="support.opendns.com_hc_user_images_t5aLvzP6BGuDIQ2EoJYXQA.png" alt="support.opendns.com_hc_user_images_t5aLvzP6BGuDIQ2EoJYXQA.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is all what I have &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Jun 2017 13:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177496#M4208</guid>
      <dc:creator>mparp</dc:creator>
      <dc:date>2017-06-07T13:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177497#M4209</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;May be BUG, will investigate this &amp;nbsp;&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Jun 2017 14:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177497#M4209</guid>
      <dc:creator>mparp</dc:creator>
      <dc:date>2017-06-07T14:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP GET Request on port 53</title>
      <link>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177498#M4210</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Yes, now it's clearer.&amp;nbsp; Wireshark seems to pick the wrong thing from "Follow -&amp;gt; TCP Stream".&amp;nbsp; This is &lt;STRONG&gt;not&lt;/STRONG&gt; the details from the normal DNS traffic you're showing in the background which is clearly not HTTP, but DNS.&amp;nbsp; Maybe this is also intentional, no idea what they would do with this.&amp;nbsp; At least it was good enough to confuse you.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 07 Jun 2017 16:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/http-get-request-on-port-53/m-p/5177498#M4210</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2017-06-07T16:12:55Z</dc:date>
    </item>
  </channel>
</rss>

