It is the web interface of Kazaa where these headers may occur -- I noticed them in my Proxomitron log while previewing downloaded items in the "Theatre" field.
Since then I've also found them occuring in the search, start, and my kazaa fields.
I can't filter Kazaa's actual traffic over port 1214, but start/my kazaa/theatre report over normal HTTP to a server (resolved to different IP's), so I'm not really sure what is happening, but if I can, I will filter them out. Also, they do not always occur, it would seem Kazaa only reports at certain intervals.
BTW, I have gotten Kazaa to run over HTTP Tunnel, but never noticed anything suspicious going on.
Edited by - Jor on 19 Jul 2002 00:23:26