What? I was trying to access my bank’s web page but
instead of the page I was presented with this message. Is the web site down? Nope, doesn’t seem to be. It pings with no problem. I’m firing up the Firefox, and voila – the
web page appears before my eyes. Is
something wrong with the IE? Did I
unknowingly install a rogue browser extension, spyware or adware? The fact that it’s a bank’s site made me
suspicious.
Or is it
just IE8? I’m trying compatibility mode
– nope, the same result. Trying IE8 from
another machine. Works like a charm! This is starting to look very troubling. OK, it’s time for serious investigation.
Perhaps
Autoruns can tell me what’s going on?
It’s a Sysinternals tool. I’m
looking through IE BHO’s, Winsock providers, other stuff that’s in there. Nothing stands out. Everything looks normal.
Perhaps
it’s the anti-virus? Or Vmware network
services? Shutting everything down. Still nothing.
OK, let’s
take a look at what happens at the network level. Launching the Wireshark. Capturing some network packets and what am I
seeing? IE8 sends a DNS query for the
bank’s site. The query resolves OK. Then it establishes the connection: SYN,
SYN+ACK, ACK – so far so good. Then it
sends HTTP GET. And the very next packet
it receives from the site is RST. No
wonder it can’t display the web page!
The site just drops the connection.