Acunetix WVS 8 Released Candidate Now Available!
releases

Acunetix Web Vulnerability Scanner Product Releases

docs & FAQs

Acunetix technical documentation and FAQ

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars, Events and Training around the world

web security zone

Everything you need to know about Web Security

Home » articles

Statistics from the top 1,000,000 websites – part II

Submitted by on March 4, 2010 – 4:38 pm3 Comments

This is the second part of an older article we posted, where we present some statistics from the top 1,000,000 sites on the internet.  We are using the Alexa database as source for our statistics.  In the first part of this article, we presented the Top Web Servers, Apache version distribution, Microsoft IIS version distribution, Unix vs Windows and so on. In this second part we will include more statistics such as top mail server providers, top dns server providers, top AS names, country distribution and more.

Top MX Servers

To start off with, I wanted to see where people are receiving their mail. Therefore, for each domain we queried the MX servers and calculated which servers are the most popular. The results are shown bellow:

MX (mail server)CountPercentage
*.google.com5743738.57%
*.secureserver.net (Go Daddy)2915519.58%
*.mail.dreamhost.com60894.09%
*.kundenserver.de60554.07%
*.emailsrvr.com54483.66%
*.1and1.com53233.57%
*.messagelabs.com44542.99%
*.qq.com41562.79%
mail.automattic.com41072.76%
*.mail.yahoo.com38522.59%
*.ispgateway.de35602.39%
*.ovh.net35602.39%
*.masterhost.ru27491.85%
*.rzone.de23771.60%
*.schlund.de21971.48%
*.1and1.co.uk19941.34%
*.sitebuildit.com17721.19%
*.frontbridge.com16751.12%
*.servage.net15641.05%
*.mx-server.net13770.92%

As you can see from the table above, most of the people are entrusting their mails to Google. Gmail for your domain (Google Apps for your domain) is very popular because it works well and it’s free for small companies. On the second place is *.secureserver.net. These are the MX servers from Go Daddy. On the third place is DreamHost.

Top DNS Servers

Next, we’ve calculated the NS (name server) distribution. Same procedure, for each domain we’ve queried the NS servers and calculated which servers are the most popular.

NS serverCountPercentage
*.domaincontrol.com (Go Daddy)4081721.64%
*.google.com1965210.42%
*.xinnetdns.com128406.81%
*.xinnet.cn128356.81%
*.dreamhost.com117686.24%
*.name-services.com98185.21%
*.bluehost.com94725.02%
*.ovh.net87624.65%
*.rackspace.com81554.32%
*.mediatemple.net67023.55%
*.1and1.com60063.18%
*.dnsmadeeasy.com53962.86%
*.hostmonster.com53912.86%
*.yahoo.com48492.57%
*.technorail.com48352.56%
*.wordpress.com46852.48%
*.dns.com.cn45362.41%
*.ultradns.net42032.23%
*.namespace4you.de40062.12%
*.kasserver.com38602.05%

domaincontrol.com is the NS server for Go Daddy. On the second place are the Google name servers. These are the Blogspot blogs (there are a lot of them). Third and forth place belongs to xinnetdns: some popular Chinese web hosting provider.

Top AS Names

An autonomous system (AS) is a collection of connected Internet Protocol (IP) routing prefixes under the control of one or more network operators. Next table will display the top AS Names (based on their AS numbers).

AS NameCountPercent
THEPLANET-AS - ThePlanet.com Internet Services, Inc.5831117.42%
GOOGLE - Google Inc.3775711.28%
CHINANET-BACKBONE No.31,Jin-rong Street282268.43%
PAH-INC - GoDaddy.com, Inc.238067.11%
SOFTLAYER - SoftLayer Technologies Inc.217996.51%
ONEANDONE-AS 1&1 Internet AG191275.71%
OVH OVH175155.23%
BLUEHOST-AS - Bluehost Inc.154734.62%
PEER1 - Peer 1 Network Inc.136664.08%
RMH-14 - Rackspace.com, Ltd.122153.65%
DREAMHOST-AS - New Dream Network, LLC115863.46%
LAYER3-ASN - Layered Technologies, Inc.115113.44%
HETZNER-AS Hetzner Online AG RZ105793.16%
LAYER3-ASN-2 - Layered Technologies, Inc.105253.14%
LIQUID-WEB-INC - Liquid Web, Inc.83522.49%
MEDIATEMPLE - Media Temple, Inc.77392.31%
LEASEWEB LEASEWEB AS70062.09%
GNAXNET-AS - Global Net Access, LLC67472.02%
CHINANET-SH-AP China Telecom (Group)65601.96%
AKAMAI-ASN1 Akamai Technologies European AS62841.88%

The table from above lists the top IP providers from our top 1,000,000 websites as listed by Alexa. THEPLANET leads the way, followed by Google and a Chinese provider.

Registrars distribution

The next table is about IP registrars. There are 5 registrars on the internet:

  • arin – American Registry for Internet Numbers
  • ripencc – Réseaux IP Européens Network Coordination Centre
  • apnic – Asia-Pacific Network Information Centre
  • lacnic – Latin American and Caribbean Internet Addresses Registry
  • afrinic – The Registry of Internet Number Resources for Africa
RegistrarCountPercent
arin50398451.68%
ripencc31874132.69%
apnic13749314.10%
lacnic122901.26%
afrinic26210.27%

Country distribution

We’ve also calculated the country distribution. We’ve resolved each domain to its corresponding IP address and then determined the country for that ip address. Finally, we’ve counted the most popular countries.

CountryCountPercentage
United States49799353.73%
Germany815188.80%
China633646.84%
Japan423844.57%
United Kingdom408144.40%
Russian Federation355833.84%
France298933.23%
Netherlands262182.83%
Canada216952.34%
Italy160131.73%
Spain119921.29%
Turkey87400.94%
Europe77200.83%
Poland73460.79%
Brazil68360.74%
Australia65440.71%
Czech Republic60700.65%
Sweden57460.62%
Ukraine54650.59%
Thailand48450.52%

No surprises here: United States, Germany and China are taking the top spots.

While navigating all those websites we’ve received some funny responses from web servers. I’ve listed some of them below.

Weird headers

These are various headers that contain invalid characters. Most of them are error messages (usually PHP and MySQL errors). Some of them include some kind of information disclosure (even source code disclosure in one case).

Header NameHeader Value
file 'cmysqlsharecharsets?.conf' not found (Errcode: 2)
php noticeUndefined variable: rssrtl in D:domainsmeansearch.comwwwrootmodulesmod_slick_rsstmpldefault.php on line 46
php noticeUndefined index: error in D:domainsmeansearch.comwwwrootmodulesmod_slick_rsstmpldefault.php on line 29
php warningPHP Startup: Unable to load dynamic library '/usr/local/php5/lib/php/php_pdo_mysql.dll' - /usr/local/php5/lib/php/php_pdo_mysql.dll: cannot open shared object file: No such file or directory in Unknown on line 0
php warningPHP Startup: Unable to load dynamic library './php_gd.so' - Cannot open "./php_gd.so" in Unknown on line 0
php warningUnknown(): Unable to load dynamic library '/usr/local/php4/lib/php/php_xslt.dll' - /usr/local/php4/lib/php/php_xslt.dll: cannot open shared object file: No such file or directory in Unknown on line 0
character set '#18' is not a compiled character set and is not specified in the 'cmysqlsharecharsetsIndex' file
gen true for "http//www.philadelphia-reflections.com" r (n 0 s 0 v 0 l 0 oa 0 ob 0 oc 0 od 0 oe 0 of 0 og 0 oh 0 c 0)
e</div>xpiresMon, 26 Jul 1997 05:00:00 GMT
php fatal errorCall to a member function count() on a non-object in /virtual/valueset/project/dropshipping/apps/valueset/modules/amazon/templates/indexSuccess.php on line 123
php header for pdf filesheader("Cache-Control: must-revalidate, post-check=0, pre-check=0");
<?php include_once("analyticstracking.php"); ?>
<!-- -->dateFri, 11 Dec 2009 21:07:37 GMT
<!-- warningIS_SALVE : esl5 at auction.pl line 1020. -->, IS_SALVE : esl5 at auction.pl line 1054. -->
are you hacker this server ? baby !^ Aaron ^
super isp13939.NET
php scriptphp
wordpress-datenbankfehler unknown collation'utf8_general-ci' für die Abfrage SET NAMES 'utf8' COLLATE 'utf8_general-ci' in require, require_once, require_once, require_once, require_wp_db, require_once

Funny Server headers

And finally, some administrators are using various humorous values for the Server header. I’ve listed some of them below:

Server
God is Love
Homer/1.
House Plans
Http With Associates
I'm a server
IIS 9.2 Alpha
IIS/7.(Unix) mod_ssl/2.8.3OpenSSL/.9.8e
IIS_8._pre_alpha
Its a Server
Just a Web Server
Just Apache
make my day
null
openyourmind
Pizza/4cheese
reboot!
the 4in 4.25 seconds
*** unknown ***
BlackHole/1.
David's little web server powered by Smalltalk
Go Away
HolyServer/9 (YeahBaby)
O_o
Paranoid
;-)
Apache ;-)
Stoned Webserver 1.
Apachern
Server secured
Ski The Best... Booth Creek Resorts

3 Comments »

Leave a comment!

Add your comment below, or trackback from your own site. You can also subscribe to these comments via RSS.

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.