Showing posts with label proxy servers. Show all posts
Showing posts with label proxy servers. Show all posts

Tuesday, May 06, 2008

Klatt's Clunkers 8: Bernard Klatt comes close

Below and to the right is a long exerpt from Bernard Klatt's testimony of Feb. 8, 2007 (Richard Warman & the CHRC v. Marc Lemire, T1073/5405 vol. 9, pp. 1636-8) .

Bernard KlattIn it, Klatt, who had been summoned to testify as a technology expert, is discussing the phenomenon that we had identified in the last post: that is, in the logs of Sept. 5, 2003, the traffic associated with 90sAREover's visit sometimes appears as 66.185.84.204 and sometimes as 66.185.84.200. Indeed, in the three minutes following his notorious racist denunciation of Senator Anne Cools, the IP changes four times.

Klatt is unable to explain the phenomenon.

There are several troubling aspects of this. First, of course, is the fact that he he's not sure what is going on: one expects better of an "expert". Second, it is troubling that the shifting IPs (which is material to the identification that he's making) is a matter that was raised not by Klatt himself, but the Chair of Tribunal. He makes no allusion to it at all in his discussion of the Cools' post in his affidavit (paragraphs 34-41, here). His answer to the chair, however, reveals that this is something that he'd noticed before: "That one is interesting" (line 21 of p. 1636). Not interesting enough, apparently, that he should actually explain it in his testimony.

Most importantly, however, is that is a bit troubling how close Klatt came to the truth. At p. 1636, lines 22-23, for example, he recognizes that 66.185.84.200 might be a web-cache, which he repeats at p. 1638, lines 3-4, as "very likely". The correct answer, as we have seen, is that both these IPs are web-caches and that the shifting from one to the other is part of Rogers' practice of load balancing.  And the idea that he might suppose that 66.185.84.200 (which had a hostname of wc04.mtnk.rnc.net.cable.rogers.com) was a web-cache, but not guess that 66.185.84.204 (with hostname wc09.mtnk.rnc.net.cable.rogers.com) was also one is a bit baffling. He was so close!

One expects better than "close", however, from an expert. We want them to be right. Mistakes in expert testimony can ruin lives. In this case, the erroneous testimony has damaged the reputation of an innocent man and exposed those who have repeated Klatt's errors to financial harm.


Other posts in the Klatt's clunkers series:

Load-balancing in action: did Richard Warman and 90sAREover really have the same IP?

Below and to the right is an excerpt from the Freedomsite's logs, truncated on three sides to make it easier to read. (You can see an untruncated version here on p. 35.)

Richard Warman, 90sAREover, CoolsThe top two entries (both with "POST") are related to the notorious Cools message: the first confirming the spelling of "nigger"; the second submitting the nasty message that is at the center of the present controversy. The bottom-most is the last entry for 90sAREover in the logs (or at least those that have been released).

The point to note is that 90sAREover did not have just one IP during his brief visit to the freedomsite message board, but two: 66.185.84.204 and 66.185.84.200, and in the space of three minutes he switches from one to the other at least four times.

I say "at least" four times here because it is important to remember that we are only seeing a portion of what was going on. These two IPs are both Roger's web-caching proxies -- their host names are (respectively) wc09- and wc04.mtnk.rnc.net.cable.rogers.com, showing the tell-tale wc (which abbreviates web-cache) -- and since they are caches there will have been traffic between them and 90sAREover's computer that is not forwarded to the visited site.

Richard Warman, Cools, 90sAREoverWhat does all this mean? The switching between these two web-caches is another example of load-balancing, a practice by which Rogers shifted traffic among its 42 web-caches to deliver the most efficient service to its subscribers. An attempt to sort out how all of this worked resulted in the string ball to the right (explained here), which traced shifts between proxy-IPs that can be identified in the years 2002-5. Each string in the ball is an example of a load-balancing shift.

This load-balancing provides another wrinkle in argument of identifying 90sAREover. It seems that Rogers' subscribers had what might be called a "home" proxy, which functioned as their default web-cache, and that they would rerouted to a another proxy only when needed, especially (one assumes) at peak hours. But when he made the racist Cools-post, was 90sAREover's "home" proxy 66.185.84.204 and 66.185.84.200 a temporary IP to which he was shifted through load-balancing? Or was his home proxy 66.185.84.200? Or might his "home" have been one of the other web-caches in the series, with the traffic rerouted into 200 and 204?

Saturday, April 12, 2008

What to look for when recruiting an expert witness

This is a bad sign:
    KlattDoesntKnowRogersHilite
(For the context, see here and here.)

Wednesday, April 09, 2008

Load-balancing at Rogers

There is an interesting article in the networking magazine Network Computing of 1999 about Rogers' plans for the next few years. Concerned about the challenges that expected increases in traffic would bring, together with the expectation that e-commerce would become more important (making it all the more important that the traffic got through expeditiously), Rogers developed load-balancing technology to prevent server overload.  Some selected quotes:
    Ten Alteon Networks ACEswitch 180 server switches balance the traffic flows among Rogers' five Web and cache servers, as well as its VPN and firewall servers. The Gigabit Ethernet server switches redirect traffic when one server goes down or gets jammed with HTTP traffic. The switches also route and handle the packet filtering for Rogers' firewalls, and all of Rogers' servers are connected via Gigabit Ethernet.
………
    When a user requests Internet access, the switch directs that request to a proxy server. "It's load-sharing among cache proxies, and if they all aren't available, it then redirects the traffic to the Internet," rather than to the proxy server, Howell says.
This seems to be the explanation for the shifting IPs that we noticed earlier. Those shifts are taking place among various proxy servers.

Monday, April 07, 2008

How many proxies does Rogers have?

As we have seen, wc09.mtnk.rnc.net.cable.rogers.com (=66.185.84.204), which has recently been at the central of controversy, is one of Rogers' web-caching proxy servers. These proxies are named with the prefix wc~ (for 'web caching'), a number, and a geographical reference.

So far, we have seen 14 proxies with the mtnk designation, and 14 with a wlfdle bank. Given the pattern, it only took a moment to identify a third bank of proxies, again 14 in number, this time with the abbreviation ym. This brings the number of identified proxy servers to 42, which are:
    IP hostname IP hostname IP hostname 
    66.185.84.68 wc01.wlfdle.~ 66.185.84.196 wc01.mtnk.~ 66.185.85.68 wc01.ym.~
    66.185.84.69 wc02.wlfdle.~ 66.185.84.197 wc02.mtnk.~ 66.185.85.69 wc02.ym.~
    66.185.84.70 wc03.wlfdle.~ 66.185.84.198 wc03.mtnk.~ 66.185.85.70 wc03.ym.~
    66.185.84.71 wc04.wlfdle.~ 66.185.84.199 wc04.mtnk.~ 66.185.85.71 wc04.ym.~
    66.185.84.72 wc05.wlfdle.~ 66.185.84.200 wc05.mtnk.~ 66.185.85.72 wc05.ym.~
    66.185.84.73 wc06.wlfdle.~ 66.185.84.201 wc06.mtnk.~ 66.185.85.73 wc06.ym.~
    66.185.84.74 wc07.wlfdle.~ 66.185.84.202 wc07.mtnk.~ 66.185.85.74 wc07.ym.~
    66.185.84.75 wc08.wlfdle.~ 66.185.84.203 wc08.mtnk.~ 66.185.85.75 wc08.ym.~
    66.185.84.76 wc09.wlfdle.~ 66.185.84.204 wc09.mtnk.~ 66.185.85.76 wc09.ym.~
    66.185.84.77 wc10.wlfdle.~ 66.185.84.205 wc10.mtnk.~ 66.185.85.77 wc10.ym.~
    66.185.84.78 wc11.wlfdle.~ 66.185.84.206 wc11.mtnk.~ 66.185.85.78 wc11.ym.~
    66.185.84.79 wc12.wlfdle.~ 66.185.84.207 wc12.mtnk.~ 66.185.85.79 wc12.ym.~
    66.185.84.80 wc13.wlfdle.~ 66.185.84.208 wc13.mtnk.~ 66.185.85.80 wc13.ym.~
    66.185.84.81 wc14.wlfdle.~ 66.185.84.209 wc14.mtnk.~ 66.185.85.81 wc14.ym.~

Update.  According to this, mtnk abbreviates "Newkirk"; wlfdle, "Wolfedale"; and ym, "York Mills".

Update 2. Presumably these are located at the Rogers offices at these addresses:
  • 3573 Wolfedale Rd, Mississauga
  • 855 York Mills Rd, North York
  • 244 Newkirk Road, Richmond Hill

proxy servers 9: what Rogers said about their own proxying

We have seen that 66.185.84.204 = wc09.mtnk.rnc.net.cable.rogers.com was functioning as a proxy in 2003 (here and here and here and here and here and here and here).  What does this mean that it was a proxy?

Rogers itself once explained this in its FAQ.  That FAQ has since disappeared, but it was quoted in full on the site of the Residential Broadbant Users Association (here; an archived version from Sept. 2003 can be seen here).  

The Rogers FAQ defines a proxy and describes how it is used:
The proxy is a local HTTP (web) server internal to a regional/main data center, which caches (stores) frequently requested content. It was originally implemented in order to greatly reduce unnecessary network traffic, particularly backbone traffic leading to the @Home Network in the US. When you want to access a website via your proxy, you send a request to your proxy, which then checks to see if any of the related content is stored locally. If it isn't, the proxy will access the remote server and send back the information you originally requested. The new information is then cached on the proxy for a predetermined period of time.
Note that the Rogers FAQ actually tells us that accessing a site through a proxy will send the proxy to the site.  Any logs at the site will capture the proxy's IP.   This is presumably why so much traffic can be identified for these years (see here and here and here) -- because 66.185.84.204 is forwarding numerous users.  Also note that its job is to act as a web cache — indeed, as I conclude here, this is what the "wc" in wc09.mtnk.rnc.net.cable.rogers.com stands for.

proxy servers 8: yet another two underlying IPs

In this log entry from November 8, 2003, we see 66.185.84.204 proxying for 63.138.242.220:
    Sat Nov 8 16:39:15 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/quotes.html|4400:63.138.242.220$|Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
And here (from December, 2003), we see it proxying for 24.102.22.213:
    Wed Dec 24 22:54:27 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/publications.html|11277:24.102.22.213$|Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)

proxy servers 7: still two more underlying IPs

We have seen that in 2003 and 2004, 66.185.84.204 was a Roger proxy server, that forwarded traffic for Rogers customers to a variety of site (see here and here and here). Indeed, we have been able to identify the forwarded IPs of some of these:
Here is another excerpt from a visitor log from June 2003:
    Mon Jun 30 20:11:12 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/|35416:24.192.3.174$|Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; eisa.com)
    Mon Jun 30 20:11:14 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/publications.html|9339:24.192.3.174$|Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; eisa.com)
In this case, 66.185.84.204 is forwarding traffic for 24.192.3.164. And in another log from July of 2003, traffic is forwarded for 24.112.104.245:
    Thu Jul 10 23:52:54 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/log.html|46319:24.112.104.245$|Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
The same IP's traffic was forwarded by the same proxy in August (here):
    Wed Aug 6 23:20:23 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/|36325:24.112.104.245$|Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
    Wed Aug 6 23:21:39 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/publications.html|9722:24.112.104.245$|Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)

Sunday, April 06, 2008

Proxy servers 6: two more underlying IPs

The IP 66.185.84.204 visited many websites in 2003, as evidenced by the many logs in which it can be found (e.g., here for October of that year).  We have already seen (here and here) that this IP was used as a web proxy by Rogers in 2003 -- indeed it is even possible to identify some of the individual IPs that it forwarded traffic for (here).

An interesting visitors log from October 2003 can be seen here.  In it are three interesting entries:
    Thu Oct 9 19:50:52 2003|cpe00c0f0219072-cm.cpe.net.cable.rogers.com|24.157.169.36| http://www.cs.ualberta.ca/~mburo/courses/605.RTS/|834:24.157.169.36$|Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
    Tue Oct 14 15:06:57 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/quotes.html|4202:63.139.207.87$|Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
    Sat Oct 18 07:37:43 2003|wc09.mtnk.rnc.net.cable.rogers.com|66.185.84.204| http://www.cs.ualberta.ca/~mburo/orts/orts.html|243:24.157.32.153$|Mozilla/4.0 (compatible; MSIE 5.15; Mac_PowerPC)
In each of the entries, there are two IPs.  In the first, the two IPs are identical, as is the case when there is no proxying at issue.  (See here.)  In the second and third, our old friend wc09.mtnk.rnc.net.cable.rogers.com = 66.185.84.204 appears, again, as a proxy, now for 63.139.207.87 and 24.157.32.153, respectively.

(That the IP appears as a proxy in October 2003, a month at the center of controversy about the use of this IP in the autumn of 2003 is especially important.)

Proxy servers 5: an underlying IP

To the right is a screencap of a truehits log from Feb. 2, 2003 (on which, see here and here).  This gives the Proxy's IP, name, and software version (first column), that it is set to forward the IP of the computer that it is proxying for (second column), and the number of hits that it forwarded (third column), which in this case was 82 (see the red arrow).  

The truehit logs also report their top visitors, as you can see to the right.  The fourth largest visitor of the day was from a Rogers netblock, and it also 82 hits (see the red arrow).

It seems obvious and inevitable that these two entries are to be taken together, and that the 82 hits that 66.185.84.204 had forwarded came from a single IP, 24.157.249.116.  

Now, this IP is no longer part of a Rogers block (see here, for example).  But a few years ago it seems to have been based in West Toronto.  For reasons that we don't need to go into, "arfer" posted to a broad-band discussion boarded a long list (over three thousand items!) of the Rogers blocks that he could find (see here).  About half-way down his list is this entry:
    Rogers Cable Inc. Hnsn ON-ROG-10-HNSN-7 (NET-24-157-249-0-1) 24.157.249.0 - 24.157.249.255
HNSN, according to this, abbreviates Hanson and is in the western GTA.  (Presumably this is the location of some equipment; perhaps Hanson Road in Mississauga?)

In a nutshell what does this mean?  Not much, except that in February 2003, a computer in Mississauga with the IP 24.157.249.116 visited a site in Thailand; on its way there, however, its traffic was channeled by Rogers through one of its proxy servers, 66.185.84.204.  Both the proxy and the individual IP was logged.

Update.  An out-of-date database of whois-information, here, produces this:
    TARGET: 24.157.249.116
    NAME: ON-ROG-10-3HNSN-1
    NUMBER: 24.157.249.0 - 24.157.249.255
    CITY: TORONTO
    STATE: ONTARIO
    COUNTRY: CA
    LAT: 43.70
    LONG: -79.42
    LAT_LONG_GRAN: City
    LAST_UPDATED: 18-Apr-2001
    NIC: ARIN
    LOOKUP_TYPE: Block Allocation
    RATING:
    DOMAIN_GUESS: rogers.home.net
    STATUS: OK
The block-name is slightly different, but the location is the same.

Saturday, April 05, 2008

proxy servers 4: someone notices their proxy (75)

At least one Rogers customer was surprised to learn that his system was being proxied. In xxx, "intrudah" wrote (here):
    i was playing on some gaming ladders (rainbow 6), and i was banned because it said my ip was used by another account.  i get this on the ip analyser:
      "Your IP (69.198.213.219) appears to be behind a web proxy server (66.185.84.75) and results shown might not be for your system."
    the admins think its because of the proxy.  any thoughts?
The discussion did not develop much from there.  But note that 66.185.84.75 is one of the IPs that we have been tracking, and here it proxies for 69.198.213.219, which at one time was part of a Rogers range (see here and here).  At least in this case, the Rogers customer did not even know he was behind a proxy.

Thursday, April 03, 2008

proxy servers 3: what one looks like in an error log

We have already seen that some of the IPs that we've been tracking are Rogers' proxy servers (see here and, especially, here).  Now that we know what to look for, it's not difficult to find confirmation of this.  One example can be seen Nukecops.com, a help-forum for php-nuke, a web-based news publishing and content-management system.  In May 2004, a user "tuxx" asked for advice and posts his error logs, which I want to quote two chunks of.  First, this (which I have added colour to; "tuxx" had replaced the name of his site with "sitename.com" for privacy):
    9993 admin65 /usr/bin/php UNIQUE_ID=usp-9EIxsZcAAGzF610AAABb HTTP_X_FORWARDED_FOR=24.150.44.231 SERVER_PORT=80 HTTP_HOST=sitename.com DOCUMENT_ROOT=/var/www/html SCRIPT_FILENAME=/var/www/html/index232.php REQUEST_URI=/index232.php SCRIPT_NAME=/index232.php HTTP_VIA=1.0 wc09 (NetCache NetApp/5.5R3) SCRIPT_URI=http://sitename.com/index232.php HTTP_CONNECTION=keep-alive PATH_INFO=/index232.php REMOTE_PORT=63754 PATH=/usr/local/bin:/usr/bin:/bin SCRIPT_URL=/index232.php PWD=/var/www/interpreters SERVER_ADMIN=email@sitename.com REDIRECT_STATUS=200 SITE_CGIROOT=/var/www/cgi-bin HTTP_ACCEPT_LANGUAGE=en PATH_TRANSLATED=/var/www/html/index232.php HTTP_ACCEPT=*/* SITE_HTMLROOT=/var/www/html REMOTE_ADDR=66.185.85.76 SHLVL=1 SERVER_NAME=www.sitename.com SERVER_SOFTWARE=Apache/2.0.48 (Fedora) QUERY_STRING= SITE_ROOT=/ SERVER_ADDR=66.49.180.189 GATEWAY_INTERFACE=CGI/1.1 SERVER_PROTOCOL=HTTP/1.1 REDIRECT_URL=/index232.php REQUEST_METHOD=GET _=/usr/bin/php
Here we see the tell-tale signs of a proxy. The "HTTP_VIA=1.0" shows that a proxy is being used, that it's name is "wc09", and that it using Net Appliances version 5.5R3. The "HTTP_X_FORWARDED_FOR" header shows the IP that the traffic is being fowarded for. And the "REMOTE_ADDR=" header introduced the IP of the proxy, in this case 66.185.85.76 (= wc09.ym.rnc.net.cable.rogers.com).  (For a quick tutorial, see here.)

In his search for help "tuxx" has included several other passages from his error logs including this:
    9787 admin65 /usr/bin/php UNIQUE_ID=uTVIYUIxsZcAAGx8VC4AAABQ HTTP_X_FORWARDED_FOR=24.150.44.231 SERVER_PORT=80 HTTP_HOST=sitename.com DOCUMENT_ROOT=/var/www/html SCRIPT_FILENAME=/var/www/html/index232.php REQUEST_URI=/index232.php SCRIPT_NAME=/index232.php HTTP_VIA=1.0 wc09 (NetCache NetApp/5.5R3) SCRIPT_URI=http://sitename.com/index232.php HTTP_CONNECTION=keep-alive PATH_INFO=/index232.php REMOTE_PORT=5350 PATH=/usr/local/bin:/usr/bin:/bin SCRIPT_URL=/index232.php PWD=/var/www/interpreters SERVER_ADMIN=email@sitename.com REDIRECT_STATUS=200 SITE_CGIROOT=/var/www/cgi-bin HTTP_ACCEPT_LANGUAGE=en PATH_TRANSLATED=/var/www/html/index232.php HTTP_ACCEPT=*/* SITE_HTMLROOT=/var/www/html REMOTE_ADDR=66.185.84.204 SHLVL=1 SERVER_NAME=www.sitename.com SERVER_SOFTWARE=Apache/2.0.48 (Fedora) QUERY_STRING= SITE_ROOT=/ SERVER_ADDR=66.49.180.189 GATEWAY_INTERFACE=CGI/1.1 SERVER_PROTOCOL=HTTP/1.1 REDIRECT_URL=/index232.php REQUEST_METHOD=GET _=/usr/bin/php
Again, we see a proxy at work.  This time it is our old friend 66.185.84.204 = wc09.mtnk.rnc.net.cable.rogers.com, which again is shown to be a proxy.

When was this? The date of tuxx's post is May 18, 2004.  We have already seen here that truehits.net had listed 66.185.84.204 as a proxy in early 2003.  Apparently it was still one in 2004.

Wednesday, April 02, 2008

proxy servers 2: other Rogers proxy servers at truehits.net

We have been trying to discover how a group of Rogers IPs are related to one another.  Our results so far are illustrated by the ball-of-string to the right, where each strand represents a user who's IP can be seen shifting from one IP to another.   We saw in the last post, however, that one of them, 66.185.84.74, was a proxy server.  It is listed as a proxy server in the logs of truehits.net from April 19th, 2003, and December 23rd and 26th, 2004.  And, by a lucky chance, it attracted the attention of John Walker of AutoCad (here), who discussed how such a proxy might affect one's logs.  

This raises the question whether there are other proxies among these IPs, and since we found this Rogers proxy at truehits.net, this is obviously the first place to look.  These other Rogers IPs are listed as proxy servers in its logs on the following dates:This means that about half of the IPs that we have been considering are proxy servers. Adding this to our ball of string, with each confirmed proxy circled (the colour is according to year), produces the graphic at the left.

Tuesday, April 01, 2008

proxy servers 1: 66.185.84.74

I have already pointed out (here) the rather odd logs at John Walker's fourmilab.com, in which three Roger's IPs accounted for so much of the traffic for the site in January, 2004. The size of the traffic apparently attracted the attention of the site owner, who discusses it here. His conclusion? That these are proxy servers.  This is what he writes:
    The hosts with very high hit rates appear to be HTTP proxy servers which are relaying requests from hosts behind them. Here's a dump of a packet from the host at the very top of the heavy hitters report:
      wc07.wlfdle.rnc.net.cable.rogers.com -> vitesse HTTP GET / HTTP/1.1
      0: 0800 20a1 4ca0 0030 1e05 2758 0800 4500 .. .L..0..'X..E.
      16: 00ce e6a2 4000 2c06 28f1 42b9 544a c108 ....@.,.(.B.TJ..
      32: e68a b959 0050 0b64 6c2d 798e e202 8018 ...Y.P.dl-y.....
      48: 4470 c88b 0000 0101 080a 2e4f 0050 594f Dp.........O.PYO
      64: daa9 4745 5420 2f20 4854 5450 2f31 2e31 ..GET / HTTP/1.1
      80: 0d0a 486f 7374 3a20 666f 7572 6d69 6c61 ..Host: fourmila
      96: 622e 6368 0d0a 436f 6e6e 6563 7469 6f6e b.ch..Connection
      112: 3a20 6b65 6570 2d61 6c69 7665 0d0a 5072 : keep-alive..Pr
      128: 6167 6d61 3a20 6e6f 2d63 6163 6865 0d0a agma: no-cache..
      144: 582d 466f 7277 6172 6465 642d 466f 723a X-Forwarded-For:
      160: 2032 342e 3135 332e 3539 2e38 340d 0a56 24.153.59.84..V
      176: 6961 3a20 312e 3020 7763 3037 2028 4e65 ia: 1.0 wc07 (Ne
      192: 7443 6163 6865 204e 6574 4170 702f 352e tCache NetApp/5.
      208: 322e 3152 3144 3929 0d0a 0d0a 2.1R1D9)....
    As you can see, this is a proxy server forwarding a packet for a host with IP address 24.153.59.84, which resolves to CPE00e0184e28fb-CM00803785d6b6.cpe.net.cable.rogers.com, another host in the same domain (albeit a very different IP address: the proxy server is 66.185.84.74). Monitoring packets from the proxy server show it forwarding requests from an assortment of hosts behind it. 
Thus John Walker.  There are two important points for us here: (1) 66.185.84.74 is a proxy-server that was forwarding requests for a number of Rogers' customers, and (2) each of Rogers' customer will have had their own IP.  (In this case the customer is 24.153.59.84.)

There is, however, another point.  To the right is screen-capture of the last line of the packet quoted above.  In it is identified the server software that is doing the proxying (see the red arrow): Netcache by Network Appliances (NetApp).  

This is something that we see elsewhere.  A Thai web-directory, truehits.net, provides a variety of services for its customers, including daily traffic statistics that are available on the web.  One reported statistic is top proxy servers, and the same proxy server discussed by fourmilabs in January 2004 was listed by truehits as one of top proxy-servers to visit sunncity.com on April 19 2003, Dec. 23 2004, and Dec. 26 2004.

The screen cap on the left is from April 19.  It shows, not only is the same server software being used (see red arrow), but the exact same version (5.1.1R1D9), and (since it is set up to "Forward IP") with much the same configuration.  

Now, according to the fourmilabs logs, the forwarding was being done for 24.153.59.84 (a Rogers IP).  In the case of this truehits log, we can again identify the specific IP of the individual user, not merely the proxy.  Note that the proxy had forwarded 63 hits (green arrow).   

Among the top daily visitors (see right) is 24.102.79.243, which is marked here as NETBLK-RNS-EAST.  (To judge from this, RNS abbreviates Rogers Network Services.) And the number of hits is identical to the proxy's.  (It is only to be expected, of course, that an small site in Thailand might only receive one Rogers customer in a daily log.)

The important point for us is that Rogers was using this IP as proxy for all of 2003 and 2004.

One final point.  In most cases the proxy hides the individual IP, and the IP that appears in the logs is that of the  proxy, not that of the individual Rogers customer.  In the case of the fourmilabs logs, of course, Mr. Walker has fished out the individual IP for us.  Normally, however, we don't see the individual data, but we see details about his browser and operating system ("user agents").  Consider these examples from two log entries for the same proxy (66.185.84.74) during the period when this proxy was in use:
  • Tue 29-June-2004 08:07 - wc08.wlfdle.rnc.net.cable.rogers.com [=66.185.84.74, ed.] - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)" - "http://search.yahoo.com/"
  • 66.185.84.74 - - [25/Sep/2004:09:59:00 +0200] "GET /downloads/hovtext/1.0/HovText.exe HTTP/1.1" 200 1136640 "http://hovklan.com/hovtext/index.php/?page=download〈=en" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; FunWebProducts; SV1; .NET CLR 1.1.4322)"
In both cases, the IP is the proxy, and the user agent data (browser, operating system, etc.) is the individual's.