Welcome to WebmasterWorld Guest from 220.127.116.11 , register , free tools , login , search , pro membership , help , library , announcements , recent posts , open posts Become a Pro Member
Anyone else seeing UA Mozilla 28.0 On Bell or HP IP (I think) not2easy
18.104.22.168 - - [06/Jul/2014:11:25:46 -0500] "GET / HTTP/1.1" 200 13808 "-" "Mozilla 28.0" has visited a few times this month always that same IP which shows: 22.214.171.124 - 126.96.36.199 188.8.131.52/14, 184.108.40.206/11 Alcatel-Lucent tech contact: somebody-at-hp.com It does the things a human would do but what the heck is it? So far it hits only the home page there.
Could it be an app? dstiles
I have a lot of rubbish on 135.245.48.nn and 135.245.168.nn that I wasn't aware of (13 in total, the former this month, the latter March). Time to look at blocking, I think. I have the range 220.127.116.11 - 18.104.22.168 listed as Lucent but only those /24s are troublesome so far. not2easy
I think I will follow your lead, dstiles. I don't care for disguises on visitors, even when they are smiley faced. Thanks! @aristotle - Yes, I had that thought, I looked at every resource I know of to try to find out what it is, but the Mozilla 28.0 name is only showing up in reference to the Firefox 28 browser, no appps. Pfui
Ten hits to PHP honeypots in eight months using the same fake "Mozilla 28.0" UA -- [ ...] -- equals a blockworthy IP, imho. projecthoneypot.org