Forum Moderators: DixonJones
The event takes only a total of 42 Seconds and changes UA Strings 15 times - once for each URL spammed.
69.225.183.** - - [09/Nov/2004:05:26:48 -0800] "GET / HTTP/1.1" 200 20402 "www.wwcompo+ites.com" "Opera/7.21 (Windows 98; U) [en]" 69.225.183.** - - [09/Nov/2004:05:26:54 -0800] "GET /Icon.ico HTTP/1.1" 200 1078 "www.findtut+rials.com" "JoeDog/1.00 [en] (X11; I; Siege 2.59)" 69.225.183.** - - [09/Nov/2004:05:26:55 -0800] "GET /Traptrap HTTP/1.1" 200 175 "www.tot+via.com" "Lynx/2.7.1 libwww-FM/2.14"
69.225.183.** - - [09/Nov/2004:05:27:00 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.tot+via.com" "Lynx/2.7.1 libwww-FM/2.14"69.225.183.** - - [09/Nov/2004:05:27:01 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.esit+blast.com" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; YComp 5.0.0.0)"
69.225.183.** - - [09/Nov/2004:05:27:01 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.esit+blast.com" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; YComp 5.0.0.0)"
69.225.183.** - - [09/Nov/2004:05:27:01 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.esit+blast.com" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; YComp 5.0.0.0)"69.225.183.** - - [09/Nov/2004:05:27:03 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.searc+-engines-guide.com" "Konqueror/3.1; (Konqueror/3.1; i686 Linux;;datecode)"
69.225.183.** - - [09/Nov/2004:05:27:03 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.searc+-engines-guide.com" "Konqueror/3.1; (Konqueror/3.1; i686 Linux;;datecode)"
69.225.183.** - - [09/Nov/2004:05:27:04 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.searc+-engines-guide.com" "Konqueror/3.1; (Konqueror/3.1; i686 Linux;;datecode)"69.225.183.** - - [09/Nov/2004:05:27:05 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.l+ok.com" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.5)Gecko Epiphany/1.0.6"
69.225.183.** - - [09/Nov/2004:05:27:05 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.l+ok.com" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.5)Gecko Epiphany/1.0.6"
69.225.183.** - - [09/Nov/2004:05:27:06 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.l+ok.com" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.5)Gecko Epiphany/1.0.6"69.225.183.** - - [09/Nov/2004:05:27:06 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.b+oble.com" "Mozilla/3.01 (compatible)"
69.225.183.** - - [09/Nov/2004:05:27:12 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.b+oble.com" "Mozilla/3.01 (compatible)"69.225.183.** - - [09/Nov/2004:05:27:12 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.ebr+ndz.com" "Konqueror/3.0;(Konqueror/3.0; i686 Linux;;datecode)" 69.225.183.** - - [09/Nov/2004:05:27:18 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.stan+ord.edu" "MSIE (MSIE 6.0; Windows XP) Opera 7.11 [en]" 69.225.183.** - - [09/Nov/2004:05:27:18 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.quick+egister.net" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.6)Gecko"
69.225.183.** - - [09/Nov/2004:05:27:20 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.quick+egister.net" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.6)Gecko"69.225.183.** - - [09/Nov/2004:05:27:23 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.infoh+way.com" "Mozilla/4.0 (compatible)" 69.225.183.** - - [09/Nov/2004:05:27:24 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.makem+top.co.uk" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.4)Gecko Netscape/7.1" 69.225.183.** - - [09/Nov/2004:05:27:26 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.pedag+net.com" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)" 69.225.183.** - - [09/Nov/2004:05:27:26 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.seor+nk.com" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.7)Gecko"
69.225.183.** - - [09/Nov/2004:05:27:31 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.seor+nk.com" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.7)Gecko"69.225.183.** - - [09/Nov/2004:05:27:31 -0800] "GET /Blahblah.html HTTP/1.1" 403 480 "www.avatarse+rch.com" "Mozilla/5.0 (X11; U; Linux; i686; en-US; rv:1.0.2)Gecko"
While I am fully aware of the significance of Log Spamming [google.com], what I'd like to know is exactly HOW events like these are carried out?
Are we talking an application, or program?
What's the methodology used here?
Do these hits / impressions have some measurement driven income attached to them? My thinking is along the "Click my banner ad" lines we have all read before.
Thanks.
Could be a number of ways ... HTTP isn't the most secure protocol, so take any programming language from Perl to VB that can write HTTP requests and headers and you could build something to spam logfiles pretty easily.
Why rotate the User-Agent every few requests? Probably to make it much harder for you to identify them and/or automatically ban them by relying purely on user-agent. I guess randomising the UAs would also balance out the impact on any UA traffic reports so that there wasn't just one massive spike on the reports.
- Tony
<snip>
[edited by: WebGuerrilla at 7:12 am (utc) on Nov. 11, 2004]
[edit reason] TOS #25 [/edit]
As it turns out, I have one of those sites listed. It will be removed shortly.
Sorry to the one whose site that is, but hey...log spamming is something I'm very much against and each time I find a referrer that is actually a url drop and I have that site listed, that site will go away...post haste.