Forum Moderators: open

Message Too Old, No Replies

sna-0.0.1 mikeelliott@hotmail.com (nee mikemuzio@msn.com)

Spider as Snoopy Spammer

         

Pfui

11:48 pm on Jul 3, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



A great example of spamming by spidering/data mining -- and it's/he's been at it for YEARS.

-----
UA: sna-0.0.1 mikeelliott@hotmail.com
(0.0.1? Oh, please.)
HOST: mgir.mginvestorrelations.com

LOG:

mgir.mginvestorrelations.com
sna-0.0.1 mikeelliott@hotmail.com
07/03 00:17:53 /robots.txt 403 -
07/03 00:57:15 / 403 -
07/03 01:04:30 /dir1/file1.html 403 -
07/03 01:05:45 /dir2/file2.html 403 -

mgir2.mginvestorrelations.com
sna-0.0.1 mikeelliott@hotmail.com
07/02 12:46:10 /robots.txt 403 -
07/02 12:48:21 /dir1/file1.html 403 -
07/02 12:50:32 /dir2/file2.html 403 -
07/02 13:15:24 /robots.txt 403 -
07/02 13:17:13 / 403 -

mgir.mginvestorrelations.com
sna-0.0.1 (mikeelliott@hotmail.com)
07/01 18:14:10 /robots.txt 200 -

NOTES:

Initially asks for robots.txt, but already 'knew' URLs. When fed robots.txt, it backed off.

Note multiple subdomains.

"mginvestorrelations"? Thanks but I don't need your stuff and you don't need my stuff.

sna-0.0.1
[webmasterworld.com...]

Variations on a theme, two entries from the incomparable psychedelix.com's lists [psychedelix.com] --

sna-0.0.1 (mikemuzio@msn.com) [psychedelix.com]
Snoopy PHP-client

sna-0.0.1 mikeelliott@hotmail.com [psychedelix.com]
Snoopy PHP-client

Pfui

1:13 am on Jul 13, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



P.S.

1.) aplus.cryptic.net
sna-0.0.1 (mikeelliott@hotmail.com)

Courtesy of DNS Stuff for "cryptic.net" a.k.a.

(surprise, surprise)

MG Investor Relations. - Financial Communications and Investor Relations Services --

IP address: 208.109.17.147
Reverse DNS: ip-208-109-17-147.ip.secureserver.net
Reverse DNS authenticity: [Verified]

.
2.) web4.helpinghost.com
sna-0.0.1 (mikeelliott@hotmail.com)

Courtesy of Domain Tools for "helpinghost.com" --

Server Type: Micro$oft-IIS/5.0 (<- well that's one way to obfuscate)

And from DNS Stuff --

IP address: 216.40.247.127
Reverse DNS: ev1s-216-40-247-127.ev1servers.net.
Reverse DNS authenticity: [Could be forged: hostname ev1s-216-40-247-127.ev1servers.net. does not exist]

.
3.) Here's a 2004 WW thread about this bot harvesting e-mail addresses...

[webmasterworld.com...]

...includes a link to Project Honey Pot's info [projecthoneypot.org] for it, too.

[edited by: Pfui at 1:17 am (utc) on July 13, 2006]