Forum Moderators: DixonJones
All in all there must have been more than 60 different strings, here's just a sample:
Mozilla/4.0 (compatible; MSIE 5.01; Windows 98)
Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0; YComp 5.0.2.6)
Mozilla/4.0 (compatible; MSIE 5.0; AOL 4.0; Windows 98; DigExt)
Mozilla/4.0 (compatible; MSIE 5.0; AOL 7.0; Windows 98; DigExt)
Mozilla/4.0 (compatible; MSIE 5.0; Mac_PowerPC)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 2000) Opera 6.06 [de]
Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt; SP20; pbc4.0.0.0; YComp 5.0.0.0)
Mozilla/4.0 (compatible; MSIE 5.5; AOL 5.0; Windows 98)
Mozilla/4.0 (compatible; MSIE 5.5; AOL 5.0; Windows 98; Win 9x 4.90)
Mozilla/4.0 (compatible; MSIE 5.5; AOL 5.0; Windows 98; surfEU DE M3)
They all seem valid to me so I guess someone took the trouble to collect them and feed them to a robot. BTW, there never is a referrer, so they block that out too.
It already started to mess up our logfile analysis, and if this catches on we might as well forget about it alltogether. So has anybody seen something like this and could give me some advice how to block this out? Any help would be appreciated!
Kind regards
It would seem that at some point in mid sept or so, a bunch of windoze machines got comporomised with a trojan that is doing the log-spamming... sigh, yet another kind of spam to watch out for.
My guess is that, as they are all coming from dial-up connections (aka home computers) then there is a high probability that they trojanned computers. From my logs I can see 2, possibly 3, different attack styles, which suggests 2 or 3 programs. And, maybe some of the programs don't work properly and blank out the referers by mistake?
Either that or you are being DOS'd (rather poorly).
As for what to do about it... I have no idea!
:(