Forum Moderators: phranque

Message Too Old, No Replies

172.181.108.196 To Block or Not?

That is the question

         

Angonasec

6:02 am on Jan 31, 2004 (gmt 0)



172.181.108.196

This IP visited 700 pages of our site today in a few minutes.
It did not visit our robots page.
I assummed it was a nasty bot stealing content, and added the IP to my root .htaccess file. But when I checked the IP on one of those IP investiagation sites, it's an aol address, GNN hosting in Virginia, 5 spam complaints.

I'm a novice at intepreting the data these investiagtion sites serve up, so I've unblocked the IP in case it's a legitimate bot associated with aol in some way.

Can you help me to decide if it's nasty or not?
It certainly hogged our server CPU, and behaved badly.
Do you know of a tutorial on interpreting IP info?

Ta!

pendanticist

6:10 am on Jan 31, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



If you'll supply us with the UA string, please?

Angonasec

6:45 am on Jan 31, 2004 (gmt 0)



Sorry I didn't record it.
From memory there was *no* browser information at all, no bot name, or address at all.
I'm pretty sure it's nasty, so I've blocked it again anyhow.

The IP resolves to: acb56cc4.ipt.aol.com which gives a DNS error

AOL wouldn't be that irresponsible would they?
They're just hostig the owner of the bot.

If I'm wrong please speak up kwick!

Ta!

keyplyr

7:58 am on Jan 31, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Yes it belongs to AOL. The trouble with blocking an IP from a proxy portal like AOL, is that hundreds (or thousands) of users may eventually be assigned that address, and thus be denied access.

GeorgeGG

5:07 pm on Jan 31, 2004 (gmt 0)

10+ Year Member



whois -h whois.radb.net 172.181.108.196
route: 172.181.0.0/16
descr: Europe

Most probably United Kingdom.

GGG

TryAgain

8:14 pm on Jan 31, 2004 (gmt 0)

10+ Year Member



As if (spam/hacker/leach/whatever) bots keep using the same IP for ever.

Banning IP's rarely is the solution to any problem imo.

Angonasec

8:36 am on Feb 5, 2004 (gmt 0)



Mmm not the most helpful replies I've received in this forum.

What would YOU decide to do about this IP today based on the info the IP investigation sites serve up?

***Any tips on interpreting it.***

It's all Greek to me.

I've certainly blocked this IP, until I'm shown it's safe.

I block all bots and visitors that behave badly, and spam address fishers, Nigerian scammer etc ... with great success.

It's nice to see them coming month after month bashing their noses against the glass door. I especially enjoy seeing the US NiprMill bots squealched! (They charter special Inktomi bots.)

Your Empire stops at my front door George!

If I'm inadvertantly blocking other people using this proxy IP, I'm not too concerned. Why use a dodgy proxy anyway? Looks nepharious to me ...

Comments?

keyplyr

8:49 am on Feb 5, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month




Mmm not the most helpful replies I've received in this forum.

nevermind then

racer_x

11:12 am on Feb 5, 2004 (gmt 0)

10+ Year Member



That IP address appears to be for an AOL server in Frankfurt, Germany.

pendanticist

3:42 pm on Feb 5, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



>Why use a dodgy proxy anyway?

Perhaps this very popular thread might help you understand a bit more. ;)

[webmasterworld.com...]

Keep in mind that all manner of user visits here. Different philosophies you see. Some use these proxies and some dislike them immensly.

Topics, or discussions about the perils of UCE/SPAM, open relay [google.com] / proxies, merits of bulk-mailing, etc. don't fly as well in some forums, as others.

I have a low threshold for visitors who don't respect my domain and ban them without hesitation. The folks who get the hint and stop coming by, eventually have the ban removed.

I have one visitor whom I banned some weeks back and it is so funny to see how many search queries and proxy do-dads he/she's tried using in order to regain access to my domain. All of them fail and an individual like this one becomes recognized as those holding places of honour in my permanent ban list. :)

"When you ina my house, you acta my way, eh?

You no lika my house? You go find 'nother one, ok?

Yeah. More better you go. No come back. Bye now."

Burma Shave.

Angonasec

6:49 am on Feb 6, 2004 (gmt 0)



*Chuckle* Ta Pedanticist.

I am aware that spammers visit here too.

I was merely looking for tips on interpreting the data poured out by IP investigation sites.

The one I use doesn't give a clue, no glossary, advice etc.

Anyone know a good one that does help novices choose which IPs to ban?

Colin

pendanticist

12:29 am on Feb 11, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



If I understand your questions, you are figuring on finding a site which interprets the (for the lack of a better term) threat level of a given bot/spyder/ripper/harverstor whatever, based on UA strings found in your access_log files?

Is that about right?

Angonasec

12:06 pm on Feb 11, 2004 (gmt 0)



Yes, I've been using openrbl.org and samspade.org where you just feed in the offending IP.