Forum Moderators: open

Message Too Old, No Replies

knowledge/0.5

Anyone heard of bot called "knowledge/0.5"?

         

LeBain

6:26 pm on Oct 3, 2001 (gmt 0)



Anyone heard of "knowledge/0.5"? Rapid fire bot from IP 64.38.194.224 grabbed my robots.txt and 3.2MB of pages in two minutes from 10/02/2001 8:48 to 8:50!

littleman

7:45 pm on Oct 3, 2001 (gmt 0)



The bot has hit one of my servers from the same IP. If you request that IP you'll get a password protected site, here is the header info:
401 Authorization Required
Connection: close
Date: Wed, 03 Oct 2001 19:04:03 GMT
Server: Apache/1.3.14 - PHP4.02 - Iprotect 1.6 CWIE (Unix) PHP/4.0.3pl1
WWW-Authenticate: Basic realm="RESTRICTED"
Content-Type: text/html; charset=iso-8859-1
Client-Date: Wed, 03 Oct 2001 19:02:51 GMT
Client-Peer: 64.38.194.224:80
Title: 401 Authorization Required
X-Pad: avoid browser bug

A quick port scan shows that the server has MySQL.

Anyway, the bot is posting HTTP_FROM with an email contact at cwie.net (jacobp@cwie.net), which looks to be a small isp. I'd shoot them an email if you are curious. You probably want to ban them. There is a good chance they are template steeling, there is a lot of adult sites on that class C.

LeBain

9:00 pm on Oct 3, 2001 (gmt 0)



Thanks for the info! I added the following lines to my .htaccess file:

order allow,deny
allow from all
deny from 64.38.194.224

littleman

9:10 pm on Oct 3, 2001 (gmt 0)



Your welcome. By the way, welcome to wmw.