Forum Moderators: open

Message Too Old, No Replies

Anyone recognise this?

         

davelms

8:38 pm on Jul 29, 2003 (gmt 0)

10+ Year Member



211.157.103.38 - - [28/Jul/2003:20:24:56 +0100] "GET / HTTP/1.1" 200 19484 "http:// www.thurow-service.de/01000029001.asp" "Mozilla/4.0 (compatible; MSIE 5.00; Windows 98" mydomain.co.uk

I admit I'm a newbie here, but I've been a slient reader for many months. I'm intriuged by the unusual formation (ie no closing ")", the additional 0 in MSIE 5.00 which I've never seen before - but this could be normal - and the fact that the referrer has been fixed as "http: //www.thurow-service.de/01000029001.asp" through all its accesses. Oh, by the way, this IP/UA took most of my uk-based site yesterday. It's timing was sometimes slow and almost "human"-like at times, at others quite fast, but it acted like a spider: downloading pages in a strange order (like it was working through a list of URLs it was gradually building itself), no images were taken and it couldn't cope with URLs containg a "?" so such links were followed but with no passed variables.

Anyone experienced this one before?

Sinner_G

7:40 pm on Jul 30, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Looks like a referrer hijack. A WHOIS of the IP 211.157.103.38 makes it look like it is a chinese one.