Forum Moderators: DixonJones

Message Too Old, No Replies

Strange log behavior

Problem IP with repeating tasks

         

thinkeric

6:57 pm on Jan 12, 2006 (gmt 0)

10+ Year Member



I'm a webmaster of a site that has been having some weird behavior the last two months, noticed when checking stats on awstats. I'm not a newbie when it comes to analyzing log files, but I'm not an expert either. Need a little assistance with this one:

I have a single IP that makes requests for the same three pages on my client's site (a museum), once an hour and always in the same order. Log file entry as follows:

207.250.30.3 - - [12/Jan/2006:05:21:54 -0600] "GET /zoo_info/ HTTP/1.1" 200 7465 "-" "Mozilla/4.0 (compatible;)" 
207.250.30.3 - - [12/Jan/2006:05:23:07 -0600] "GET /store.php HTTP/1.1" 200 3946 "-" "Mozilla/4.0 (compatible;)"
207.250.30.3 - - [12/Jan/2006:05:23:15 -0600] "GET /attractions/ HTTP/1.1" 200 6271 "-" "Mozilla/4.0 (compatible;)"

As you can see, no referrer and no system information. IP resolves to "207-250-30-3.gen.twtelecom.net" (looks like a Time Warner cable connection) and comes from within the United States. No other suspicious behavior that I can see in my log files, and it makes no request for any other graphics/css on these pages.

My best guesses:

1. Someone could have the page loading as their start page, but that wouldn't explain the other follow-up requests. And I am guessing that no graphics/css are made as these have already been cached on the terminal in question.

2. Some kind of attack/spam issue, but the hits aren't even close to crippling the server. But it is hurting my efforts to track the success of my client's site.

I'm out of ideas on this one... any ideas, or any way to track down the machine(s) in question? Thanks in advance.

[edited by: tedster at 4:45 am (utc) on Jan. 13, 2006]
[edit reason] disable graphic smile faces [/edit]

Stefan

2:48 am on Jan 13, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Could they have an auto-refresh of those pages set in their browser that they forgot about? The once every hour suggests something automatic, but I have no idea what.

Some kind of attack/spam issue

The world's most feeble DOS attempt, but at least they're punctual :-)

ADDED: And pardon my manners - welcome to Webmasterworld.

thinkeric

3:17 am on Jan 13, 2006 (gmt 0)

10+ Year Member



Thanks for the welcome. Yeah, I have no friggin idea. I'm not sure I want to go to a drastic measure such as banning the IP, as it really isn't causing that many problems. Aside from messing with my stats.

I'll keep the detective hat handy... thanks for the reply.

jtara

8:44 am on Jan 13, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



(delete) All this time I thought twtelecom was Taiwan Telecom. Time Warner cable? OK, mea culpa. Still could have something to do with pandas, though...

thinkeric

4:56 pm on Jan 13, 2006 (gmt 0)

10+ Year Member



All this time I thought twtelecom was Taiwan Telecom. Time Warner cable? OK, mea culpa.

I assumed overseas as well. I decided to try twtelecom.net in my browser, and it went to Time Warner Telecom. So it does appear to be an ISP.

Still could have something to do with pandas, though...

LOL. If you saw "zoo_info" in the log, I must clarify. It's actually a "zoo" for airplanes (it's an aviation museum in Kalamazoo, Michigan... hence the name.)

Heh, maybe that's the problem... the surfer keeps refreshing to see if I add the pandas...

Staffa

9:15 pm on Jan 13, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



That IP number is from a range attributed to an aviation company in Indiana.

Would that make sense to you?

Pfui

1:08 am on Jan 17, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



We never figured out who was doing what in this [webmasterworld.com] thread, but relentless, apparently automated hits from ".gen.twtelecom.net" addresses are all too well known to many of us.