Forum Moderators: open

Message Too Old, No Replies

Zeus ThemeSite Viewer

Multiple Stat Log Entries for Mod-Rewrite

         

DrLou

2:13 pm on Jul 29, 2002 (gmt 0)



Hello,

I'm a newbie poster but have been following the threads here for quite a while- lots of valuable information and a great learning experience. I want to thank everyone for their valuable input and experience.

Now I have finally run into a question that I could use some help with. I have edited my .htaccess file using Mod_Rewrite to exclude spambots, etc. The Rewrite Rule includes a redirection to a unique html page (http://www.mvssolutions.com/spam.html) for listed Rewrite Conditions.

I just noticed in my site stat logs that User Agent "Zeus ThemeSite Viewer Webster Pro V2.9 Win32" recently attempted to view my site. Zeus is one of the Rewrite Conditions in my .htaccess file (see below).

What appeared in my stat logs was about 16 entries for this request- which included a redirect (Error 302 217 bytes).

My question is: Is this what should happen?

Is this the correct outcome based on my .htaccess Mod-Rewrite entry?

Since this is the first time I have been visited by a potential spambot I didn't know what to expect. I was a bit surprised that the Error 302 was returned and also what was returned was only 217 bytes of information- I thought the data size would be about 3,000 bytes which is the size of my "spam.html" redirect page.

I'm also surprised that there were about 16 requests for this information.

As an aside, I recently tested the .htaccess file and my Mod-Rewrite entry using [wannabrowser.com...] (WannaBrowser) and got similar results- that is multiple stat log entries of the same nature.

Sorry about the lengthy posting- but wanted to ensure all of the appropriate info is conveyed.

Thanks in advance for whatever help you can provide.

Dr. Lou

Pertinent info is given below.

The initial stat log entry was the following:

pool-151-203-70-230.bos.east.verizon.net - - [29/Jul/2002:04:53:37 -0700] "GET / HTTP/1.0" 302 217 "http://www.GCMSservice.com" "Zeus ThemeSite Viewer Webster Pro V2.9 Win32"

Followed by 15 "requests/entries" of the following:

pool-151-203-70-230.bos.east.verizon.net - - [29/Jul/2002:04:53:37 -0700] "GET /spam.html HTTP/1.0" 302 217 "http://www.mvssolutions.com" "Zeus ThemeSite Viewer Webster Pro V2.9 Win32"

My Mod_Rewrite info is as follows (I actually cut and pasted this from a thread in this forum- with some minor additions/entries. I forgot who wrote it initially but Thanks!):

RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} ^BlackWidow [OR]
RewriteCond %{HTTP_USER_AGENT} ^Bot\ mailto:craftbot@yahoo.com [OR]
RewriteCond %{HTTP_USER_AGENT} ^CherryPicker [OR]
RewriteCond %{HTTP_USER_AGENT} ^ChinaClaw [OR]
RewriteCond %{HTTP_USER_AGENT} ^DISCo [OR]
RewriteCond %{HTTP_USER_AGENT} ^Download\ Demon [OR]
RewriteCond %{HTTP_USER_AGENT} ^eCatch [OR]
RewriteCond %{HTTP_USER_AGENT} ^EirGrabber [OR]
RewriteCond %{HTTP_USER_AGENT} ^EmailCollector [OR]
RewriteCond %{HTTP_USER_AGENT} ^EmailSiphon [OR]
RewriteCond %{HTTP_USER_AGENT} ^EmailWolf [OR]
RewriteCond %{HTTP_USER_AGENT} ^Express\ WebPictures [OR]
RewriteCond %{HTTP_USER_AGENT} ^ExtractorPro [OR]
RewriteCond %{HTTP_USER_AGENT} ^EyeNetIE [OR]
RewriteCond %{HTTP_USER_AGENT} ^FlashGet [OR]
RewriteCond %{HTTP_USER_AGENT} ^GetRight [OR]
RewriteCond %{HTTP_USER_AGENT} ^Go!Zilla [OR]
RewriteCond %{HTTP_USER_AGENT} ^Go-Ahead-Got-It [OR]
RewriteCond %{HTTP_USER_AGENT} ^GrabNet [OR]
RewriteCond %{HTTP_USER_AGENT} ^Grafula [OR]
RewriteCond %{HTTP_USER_AGENT} ^HMView [OR]
RewriteCond %{HTTP_USER_AGENT} ^HTTrack [OR]
RewriteCond %{HTTP_USER_AGENT} ^Image\ Stripper [OR]
RewriteCond %{HTTP_USER_AGENT} ^Image\ Sucker [OR]
RewriteCond %{HTTP_USER_AGENT} ^InterGET [OR]
RewriteCond %{HTTP_USER_AGENT} ^Internet\ Ninja [OR]
RewriteCond %{HTTP_USER_AGENT} ^JetCar [OR]
RewriteCond %{HTTP_USER_AGENT} ^JOC\ Web\ Spider [OR]
RewriteCond %{HTTP_USER_AGENT} ^larbin [OR]
RewriteCond %{HTTP_USER_AGENT} ^LeechFTP [OR]
RewriteCond %{HTTP_USER_AGENT} ^Mass\ Downloader [OR]
RewriteCond %{HTTP_USER_AGENT} ^MIDown\ tool [OR]
RewriteCond %{HTTP_USER_AGENT} ^Mister\ PiX [OR]
RewriteCond %{HTTP_USER_AGENT} ^Navroad [OR]
RewriteCond %{HTTP_USER_AGENT} ^NearSite [OR]
RewriteCond %{HTTP_USER_AGENT} ^NetAnts [OR]
RewriteCond %{HTTP_USER_AGENT} ^NetSpider [OR]
RewriteCond %{HTTP_USER_AGENT} ^Net\ Vampire [OR]
RewriteCond %{HTTP_USER_AGENT} ^NetZIP [OR]
RewriteCond %{HTTP_USER_AGENT} ^NICErsPRO [OR]
RewriteCond %{HTTP_USER_AGENT} ^Octopus [OR]
RewriteCond %{HTTP_USER_AGENT} ^Offline\ Explorer [OR]
RewriteCond %{HTTP_USER_AGENT} ^Offline\ Navigator [OR]
RewriteCond %{HTTP_USER_AGENT} ^PageGrabber [OR]
RewriteCond %{HTTP_USER_AGENT} ^Papa\ Foto [OR]
RewriteCond %{HTTP_USER_AGENT} ^pcBrowser [OR]
RewriteCond %{HTTP_USER_AGENT} ^RealDownload [OR]
RewriteCond %{HTTP_USER_AGENT} ^ReGet [OR]
RewriteCond %{HTTP_USER_AGENT} ^Siphon [OR]
RewriteCond %{HTTP_USER_AGENT} ^SiteSnagger [OR]
RewriteCond %{HTTP_USER_AGENT} ^SmartDownload [OR]
RewriteCond %{HTTP_USER_AGENT} ^SuperBot [OR]
RewriteCond %{HTTP_USER_AGENT} ^SuperHTTP [OR]
RewriteCond %{HTTP_USER_AGENT} ^Surfbot [OR]
RewriteCond %{HTTP_USER_AGENT} ^tAkeOut [OR]
RewriteCond %{HTTP_USER_AGENT} ^Teleport\ Pro [OR]
RewriteCond %{HTTP_USER_AGENT} ^Teleport*28 [OR]
RewriteCond %{HTTP_USER_AGENT} ^VoidEYE [OR]
RewriteCond %{HTTP_USER_AGENT} ^Web\ Image\ Collector [OR]
RewriteCond %{HTTP_USER_AGENT} ^Web\ Sucker [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebAuto [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebCopier [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebFetch [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebReaper [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebSauger [OR]
RewriteCond %{HTTP_USER_AGENT} ^Website\ eXtractor [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebStripper [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebWhacker [OR]
RewriteCond %{HTTP_USER_AGENT} ^WebZIP [OR]
RewriteCond %{HTTP_USER_AGENT} ^Wget [OR]
RewriteCond %{HTTP_USER_AGENT} ^Widow [OR]
RewriteCond %{HTTP_USER_AGENT} ^Xaldon\ WebSpider [OR]
RewriteCond %{HTTP_USER_AGENT} ^Zeus
RewriteRule ^.*$ [mvssolutions.com...] [L,R]

bobriggs

2:28 pm on Jul 29, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Not all that familiar with the product, but I did find this on the cyber-robotics site:

The ThemeSite Viewer will navigate through web sites just like your default browser. When a ThemeSite is being viewed in the ThemeSite Viewer, you can explore it by clicking on links just as you were surfing the web with your normal browser.

Looks like someone was using it to browse and was trying to reload the page...Just a guess. Any other hits from that same IP with a different UA?

jdMorgan

8:33 pm on Jul 29, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



DrLou,

Welcome to WebmasterWorld!

If you really want to get them to go away, I'd recommend changing your RewriteRule to:

RewriteRule .* - [F,L]

This returns a server code of 403-Forbidden and does not redirect unless you have a custom error
document defined for 403 errors.

You can define a custom 403 error document by adding

ErrorDocument 403 /spam.html

somewhere ahead of the rewrite stuff, but it's not necessary or even necessarily a good idea. If
you are getting hits from lots of spambots for lots of pages, why waste your server bandwidth? -
The bad-bots generally won't follow the redirect anyway.

Generally, the smarter bad-bots and e-mail harvesters will take the hint and abandon your site,
either immediately or after they have had a chance to digest your bitter 403 medicine.

Hope this helps,
Jim