Java 1.6.0_10 b25 installer: suspicious connection attempts?

2 replies [Last post]
Joined: 2007-01-26

Hello Sun Java installer buildmeisters,

I just tried installing Java 1.6.0_10 b25 offline install distro, and ZoneAlarm alerted about some connection attempts that the installer was trying to make. I supposed that this being the offline installer, these connection attempts were perhaps malicious or sneaky, so I blocked them. The installation was able to complete without problems. Perhaps it's someone's debug code that was left on in the distro, but I wanted to call your attention to it.

Before any dialogs came up, the installer was attempting to connect to two different IP addresses that I did not recognize. One was a DNS call, and that might not be a big deal or might be expected. The other was an HTTP call, and that one looked suspicious.

Here are the addresses that Zoney caught your installer trying to hit: : DNS : HTTP

I think those addresses are hard coded into the installer, at least the HTTP one is, because I ran the installer many times and kept seeing it hit that same IP address.

I took the liberty of running some traceroutes on those addresses, neither address resolved to any name, but the traceroutes went far enough for me to raise an eyebrow or three.

Tracing route to over a maximum of 30 hops

4 17 ms 17 ms 15 ms []
5 16 ms 15 ms 15 ms []
6 16 ms 17 ms 17 ms
7 33 ms 22 ms 21 ms
8 178 ms 35 ms 88 ms
9 52 ms 50 ms 51 ms
10 50 ms 51 ms 51 ms
11 51 ms 49 ms 51 ms

Tracing route to over a maximum of 30 hops

6 27 ms 17 ms 18 ms []
7 20 ms 18 ms 17 ms []
8 33 ms 33 ms 33 ms []
9 34 ms 33 ms 33 ms []
10 33 ms 33 ms 33 ms []
11 35 ms 35 ms 35 ms []
12 35 ms 35 ms 35 ms []
13 * * * Request timed out.
14 * * * Request timed out.

Ok, so, hits to someplace in Google and maybe someone's home/office PC in San Francisco? Seems very very fishy. Uncool! I declare possible shenanigans, even for a beta test since this is Java and not Corel Draw or something made by Microsoft! ;)

Sun, please tell us there's nothing to see here and tell us what these connections are for.

Dave Woldrich

Joined: 2008-04-05

Use a sniffer and see what it is trying to access, and what it is sending (GET or POST data).

Joined: 2004-05-04

That was an attempt to access The first access to DNS was probably to look up I know the online installer needs to go there to download cabs, etc. I wouldn't be so quick to attribute an evil motive to the developers, because that's a legitimate address. If you're worried about it, get the source code and study it. You can do that here.