Forum Moderators: DixonJones

Message Too Old, No Replies

Multiple user agents from same IP all at once

Nearly crashed my dedicated server

         

GaryK

5:55 am on Jun 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The following user agents, all from the same IP Address, hit every site and every page on my server at the exact same time on May 31. It accessed numerous pages per second. Not that it really matters but none of the user agents read or respected robots.txt. The IP Address belongs to an individual in Germany. Technically it wasn't a DOS attack but it may as well have been!

Has anyone ever seen anything like this before?

Do any of the user agents look familiar?

I've got a database of ±40,000 unique user agents and I've never seen any of these user agents until today. The ones that seem to be prematurely truncated were like that in the log files.

Thanks.

Mozilla/5.0 (Windows; U; Windows NT 5.1; de-DE; rv:1.6) Gecko
Mozilla/5.0 (X11; U; Linux i686; rv:1.7.3) Gecko/20041104 Firefox
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; DT; AVPersonal
Mozilla/5.0 (Windows; U; Windows NT 5.1; de-AT; rv:1.8a4) Gec
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; T-Online I
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; freenet
Mozilla/5.0 (Windows; U; Windows NT 5.0; de-DE; rv:1.6) Gecko
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; QXW0339r;
Mozilla/5.0 (Windows; U; Win 9x 4.90; de-DE; rv:1.7) Gecko
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.2) Gecko
Mozilla/5.0 (Windows; U; Windows NT 5.0; de-DE; rv:1.4) Gecko
Mozilla/5.0 (X11; U; Linux i686; de-AT; rv:1.0.2)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; QXW03419; FunW
Mozilla/5.0 (Windows; U; Windows NT 5.1; de-AT; rv:1.6) Gecko

keyplyr

8:56 am on Jun 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Has anyone ever seen anything like this before?

Not as blatant as that. I hope you've banned the IP.

GaryK

3:02 pm on Jun 5, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks for your reply keyplyr.

The range of IP Addresses assigned to this individual was very small so I banned the entire range.

It was suggested privately that this may in fact have been a DOS attack from someone who was mad at me for being labeled a site ripper in the browscap.ini file I distribute. The only problem is while I've seen that same IP Address as long ago as 2000 I haven't added any of the user agents it used to my file since they all were incomplete and the activity was clearly that of a human not a bot.

I'll be contacting my IP Attorney on Monday to see if there's anything reasonable she and I can do about this.

blend27

3:50 pm on Jun 7, 2005 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I have something like this in the logs

Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; DigExt)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; N_o_k_i_a)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; compaq)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)

Usualy 15 hits a day from the same exact IP with 1 second interval, goes for the home page only.

Blocked.