Forum Moderators: open

Message Too Old, No Replies

VERY Strange Visit!

Someone PLEASE help me figure out what this is about.

         

Friday

3:37 pm on Aug 22, 2003 (gmt 0)

10+ Year Member



Awoke this morning to find this entry, multiple hits on a single page from an "Other Agent (Unknown Platform)" with "strange" code added after the URL (not mine, this is a static page). I can't figure out what it means, but it makes me nervous. This is a relatively new site I've taken over SEO duties for. This isn't the complete report, I show 47 visits over a 14 hour period, some very close together. It would appear to be a private spider being run by an individual customer of Bell Canada. Any ideas? Kracker? Worm?

qc.sympatico.ca (65.94.37.8) - Other Agent (Unknown Platform)
21 Aug -- 03:27:51 -- 00:06 -- /
21 Aug -- 03:27:57 -- 00:01 -- /hallway.html
21 Aug -- 03:27:58 -- -- /
21 Aug -- 07:10:43 -- -- /
21 Aug -- 10:16:27 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88UK5H08H523VLQ1&s=23&t=&m=3F44D420&x=01406E6
21 Aug -- 10:16:33 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88UK5H08H523VLQ1&s=23&t=&m=3F44D420&x=01406E6
21 Aug -- 10:17:05 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88EK5H1DGD23UU9U&s=34&t=&m=3F44D44E&x=0187FD8
21 Aug -- 10:17:07 -- 00:43 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88EK5H1DGD23UU9U&s=34&t=&m=3F44D44E&x=0187FD8
21 Aug -- 10:17:50 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88D45H48DT23U6QK&s=105&t=&m=3F44D482&x=01246E
21 Aug -- 10:17:52 -- 00:37 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88D45H48DT23U6QK&s=105&t=&m=3F44D482&x=01246E
21 Aug -- 10:18:29 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88HK5H68H123U51L&s=446&t=&m=3F44D4B0&x=015FDE
21 Aug -- 10:18:31 -- 00:46 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88HK5H68H123U51L&s=446&t=&m=3F44D4B0&x=015FDE
21 Aug -- 10:19:17 -- 00:05 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88JK5H6LGH23UDPQ&s=282&t=&m=3F44D4E0&x=014CBD
21 Aug -- 10:19:22 -- 00:33 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88JK5H6LGH23UDPQ&s=282&t=&m=3F44D4E0&x=014CBD
21 Aug -- 10:19:55 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88SK5H3EF923VE1U&s=126&t=&m=3F44D50D&x=01849D
21 Aug -- 10:19:57 -- 00:43 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88SK5H3EF923VE1U&s=126&t=&m=3F44D50D&x=01849D
21 Aug -- 10:20:40 -- 00:03 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=89345H0MG923VAIA&s=119&t=&m=3F44D53F&x=019B14
21 Aug -- 10:20:43 -- -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=89345H0MG923VAIA&s=119&t=&m=3F44D53F&x=019B14
21 Aug -- 17:50:59 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=89345H0MG923UGD7&s=39&t=&m=3F453EAD&x=0182DAE
21 Aug -- 17:51:01 -- 00:40 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=89345H0MG923UGD7&s=39&t=&m=3F453EAD&x=0182DAE
21 Aug -- 17:51:41 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88VK5H2UFD23UVD4&s=66&t=&m=3F453ED5&x=01E3896
21 Aug -- 17:51:43 -- 01:51 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88VK5H2UFD23UVD4&s=66&t=&m=3F453ED5&x=01E3896
21 Aug -- 17:53:34 -- 00:03 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88VK5H2UFD23VOT4&s=40&t=&m=3F453F01&x=01B70B1
21 Aug -- 17:53:37 -- 01:27 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88VK5H2UFD23VOT4&s=40&t=&m=3F453F01&x=01B70B1
21 Aug -- 17:55:04 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88IK5H7MGD23UT48&s=87&t=&m=3F453FAC&x=01FD19A
21 Aug -- 17:55:06 -- 00:34 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88IK5H7MGD23UT48&s=87&t=&m=3F453FAC&x=01FD19A
21 Aug -- 17:55:40 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=892K5H6EGL23UID3&s=100&t=&m=3F453FD2&x=01E177
21 Aug -- 17:55:42 -- 00:40 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=892K5H6EGL23UID3&s=100&t=&m=3F453FD2&x=01E177
21 Aug -- 17:56:22 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88JK5H6LGH23U5CE&s=140&t=&m=3F454003&x=019BBA
21 Aug -- 17:56:24 -- 00:35 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88JK5H6LGH23U5CE&s=140&t=&m=3F454003&x=019BBA
21 Aug -- 17:56:59 -- 00:02 -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88V45H78G523VFD8&s=358&t=&m=3F45402F&x=015A4F
21 Aug -- 17:57:01 -- -- Code 302 Moved Temporarily = /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88V45H78G523VFD8&s=358&t=&m=3F45402F&x=015A4F

wilderness

11:22 pm on Aug 22, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Your script retrieving the logs or what ever method your using to accumulate your logs in this method are NOT ordinary.
Any comprehension is lost in the process. Even if you've grown used to understanding the entries.

"= /directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02%5ESSHPM%5BL7xpsy%3Fmzljsk6&e=utf8&r=390&d=www-en-us&n=88UK5H08H523VLQ1&s=23&t=&m=3F44D420&x=01406E6"

EX:
All these &amp are the + (plus) signs being used in some user agents. These are somehow being converted to the gibberish you have rather than a "standard" log line.

In order for somebody to assist you?
Please provide a standard log line.

Nearly all the lines are the result of a 302 redirected request for a file that is no longer existent.
To stop this visitor? Just remove the redirect for this page.

Bell Canada BELLNEXXIA-10 (NET-65-92-0-0-1)
65.92.0.0 - 65.95.255.255
Bell Nexxia (Prod) NEXXIA0130-CA (NET-65-94-0-0-1)
65.94.0.0 - 65.94.255.255

You might also do a
deny from 65.94.
It's a small range.

Friday

10:13 am on Aug 23, 2003 (gmt 0)

10+ Year Member



Thanks Wilderness,

That gibberish is from a standard, raw Apache log file. And the page does exist. I don't know what's up with the 302. The visitor is adding the stuff after the URL. It's a statixc p[age. That's what's so weird. I can't figure out why the "visitor" is doing this and what they're up to.

MonkeeSage

10:34 am on Aug 23, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



They are encoded, that's why they look like gibberish, decodeURIComponent() will make them human readable. Here is the output of decodeURIComponent() with that URI passed as the param:

/directory/page_name.html&y=02941270CE3DBF26&i=41&c=4901&q=02^SSHPM[L7xpsy?mzljsk6&e=utf8&r=390&d=www-en-us&n=88UK5H08H523VLQ1&s=23&t=&m=3F44D420&x=01406E6

I have no clue why they would be doing that though, or why they would have encoded the URI. I don't think it can hurt anything though.

Jordan

Friday

11:09 am on Aug 23, 2003 (gmt 0)

10+ Year Member



Maybe just a private spider run amok.