Forum Moderators: open

Message Too Old, No Replies

Anybody recognise this ip?

Just checking the log's when I found this

         

Glovebox

7:38 pm on Jul 27, 2003 (gmt 0)

10+ Year Member



67.68.232.189 - - [27/Jul/2003:10:37:39 -0500] "GET /robots.txt HTTP/1.1" 200 271 "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"

Whatever this is then proceded to grab every page in my site in under 4 minutes. Any idea's what this is guys?

Adam

AthlonInside

8:20 pm on Jul 27, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



You can always do a reverse DNS check with your coomand prompt. Type

nslookup 67.68.232.189

You will get

Toronto-HSE-ppp3782974.sympatico.ca

AthlonInside

8:21 pm on Jul 27, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Oh, by the way, it is very clear that it is a canada ISP. so the guy who fetch your site is a canadian. Or at least someone in canada. :)

bull

8:34 pm on Jul 27, 2003 (gmt 0)

10+ Year Member



related:

[webmasterworld.com...]

and

http*//mail-abuse.org/dul/sympatico.htm

GeorgeGG

3:28 am on Jul 28, 2003 (gmt 0)

10+ Year Member



I would say Toronto or at least Ontario, but
in that block 67.68.232.###, at least 4 speak French.

GGG

wilderness

3:58 am on Jul 28, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Proxies is a possibility?

This thread ( [webmasterworld.com...] )
About another Canadian range.

bull

5:31 am on Jul 28, 2003 (gmt 0)

10+ Year Member



Proxies is a possibility?

But the rDNS...says it's not proxies

wilderness

12:33 pm on Jul 28, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



But the rDNS...says

Reverse DNS is not something I use.

I believe the below implies proxies:

[dnsstuff.com...]

bull

12:47 pm on Jul 28, 2003 (gmt 0)

10+ Year Member



http://www.dnsstuff.com/tools/whois.ch?ip=67.68.232.189+&server=whois.radb.net

You'd like explain it to me...? Cos my brain seems a way to small for this.

wilderness

1:06 pm on Jul 28, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Nothing to explain Bull.

route: 67.68.0.0/16
descr: Proxy-registered route object

I did see some interesting associations here.
1) Level3
2) Cogeco

GeorgeGG

3:07 pm on Jul 29, 2003 (gmt 0)

10+ Year Member



wilderness
Thanks for the pointer to 'whois.radb.net' and
also the info about cut and paste into the ARIN block
and it returns your inquiry. :)

GGG

wilderness

10:42 pm on Jul 29, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



ARIN block and it returns your inquiry

George,matt and gang ;)

There are many types of searches that may be done at ARIN, (I suspect APNIC and RIPE as well, however I tend to lose my patience in understanding their system and the repeated failures at gathering are discouraging.)

One example at ARIN which use to be the "net" option for determining ALL the users in a subnet.
Some time ago I knew this was possible and could not decipher how. I emailed ARIN and although the reply was slow, it did eventually come.
Some months back ARIN changed their pages and database and the former "net" option was replaced with ">".

I'll provide an example. HOWEVER the example does NOT have any significance. ONLY that it is fresh in my mind.
from an PAC Bell range.
The following (as typed) returns all the subnets below the 67.127. range:
"> 67.127." without parenthenses.

ARIN under the old "NET" use in these inquiries had a limit of 256 lines. Even today at times this 256 rule holds firmly. Other times (like this example) it exceeds. I have no idea what the criteria is.

I've been unable to find a similar application for NET inquiries at either RIPE or APNIC. I'm sure it exists though.

jmccormac

10:55 pm on Jul 29, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I seem to recall that some company out of Toronto was doing a kind of preview snapshot imaging process involving webpages. It may have been the same operation. Apparently they were indexing pages that appeared in search engine results. Considering that about 35000 of the pages on my main site appear in search results, I had to deep six them pretty quickly. On a 128K leased line that costs the best part of $1800 a quarter, I just could not afford the privilege of my site being previewed. :) I can dig up the details from old log files and check if it is the same ISP but the M.O sounds similar.

Regards...jmcc