Forum Moderators: open

Message Too Old, No Replies

Unknown Crawler

193.95.83.130

         

chris_f

10:29 am on May 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



We suspected a denial of service attack at first but someone from the IP Address 193.95.83.130 hit our site for two and half days (about 400 - 600 kbps).

It seemed to do a good crawl of the site. Can anyone identify it? It declares itself as Mozilla/2.0+(compatible;+MSIE+4.0;+Windows+98).

I'll provide more info like DNS and Whois shortly. I remember looking at it yesterday and it was unclear.

chris_f

10:33 am on May 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It seems to be hosted by startosphere.com. Click here to see [193.95.83.130].

chris_f

10:37 am on May 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Can anyone whois on the IP Address.

Lisa, I'd be most grateful.

PsychoTekk

10:56 am on May 14, 2002 (gmt 0)

10+ Year Member



193.95.83.130 - whois.RIPE.net
---------------
% This is the RIPE Whois server.
% The objects are in RPSL format.
% Please visit [ripe.net...] for more information.
% Rights restricted by copyright.
% See [ripe.net...]

inetnum: 193.95.83.0 - 193.95.83.255
netname: AE-83
descr: A.E network 2 Tunis, Tunisia
country: TN
admin-c: KG1364-RIPE
tech-c: KS903-RIPE
rev-srv: ns.ati.tn
status: ASSIGNED PA
mnt-by: RIPE-NCC-NONE-MNT
changed: saadaoui@ati.tn 20000510
source: RIPE

route: 193.95.0.0/17
descr: Agence Tunisienne Internet
descr: RIPE LIR for ISP's and Networks in Tunisia -tn.ati-
origin: AS2609
mnt-by: EUNET-TN
changed: equipe-reseaux@ati.tn 20020213
source: RIPE

person: Khedija Ghariani
address: 13 rue Jugurtha Mutuelle-ville
address: 1002 Tunis - Tunisia
phone: +216 1 846 100
fax-no: +216 1 846 600
e-mail: kghariani@ati.tn
nic-hdl: KG1364-RIPE
changed: saadaoui@ati.tn 19990611
source: RIPE

person: Kamel Saadaoui
address: A.T.I
address: 13 rue Jugurtha
address: Mutuelle-ville 1002
address: Tunis, Tunisia
phone: +216 1 846 100
fax-no: +216 1 846 600
e-mail: saadaoui@ati.tn
nic-hdl: KS903-RIPE
changed: saadaoui@ati.tn 20000509
source: RIPE

chris_f

10:59 am on May 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



We saw they were Tunisian as well. Any ideas what they are up to? Or who they are?

PsychoTekk

11:28 am on May 14, 2002 (gmt 0)

10+ Year Member



ATI (Agence Tunisienne d'Internet) [ati.tn...]
two networks: 193.95.82.* and 193.95.83.*
an ISP, no own SE? (rely on google)
i suspect the useragent is fake
maybe just someone playing around with some homemade bot?

chris_f

12:13 pm on May 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks PsychoTekk

Lisa

6:57 pm on May 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I took a look at my private IP table. No gTLD domains use that IP address. In fact no gTLDs are in that Class-C network.

PsychoTekk has already given you the owner of the IP, you can see they are in Tunisia.

Hope that helps

chris_f

8:07 am on May 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks for trying Lisa.