Forum Moderators: open
203.199.84.66 - - [01/Nov/2003:14:08:59 +0100] "GET / HTTP/1.0" 200 2118 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:09:19 +0100] "GET /start.html HTTP/1.0" 200 621 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:09:32 +0100] "GET /starte.html HTTP/1.0" 200 625 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:09:59 +0100] "GET /robots.txt HTTP/1.0" 200 1029 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:11:17 +0100] "GET /robots.txt HTTP/1.0" 200 1029 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:11:39 +0100] "GET /robots.txt HTTP/1.0" 200 1029 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:11:56 +0100] "GET /robots.txt HTTP/1.0" 200 1029 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:12:09 +0100] "GET /robots.txt HTTP/1.0" 200 1029 www.-.net "-" "infomine.ucr.edu" "-"
203.199.84.66 - - [01/Nov/2003:14:12:26 +0100] "GET /robots.txt HTTP/1.0" 200 1029 www.-.net "-" "infomine.ucr.edu" "-" Because there is plenty of information on legit infomine crawlers that all have different UA strings than this one that just visited my site I ask the community if anyone had similar things and/or knows if this one is legitimiate. IP is somewhere in india on a leased line.
Personally, I don't have any tolerance right now for bots from India or China since most of my hit and run attackers have been from those two countries.
Conclusion: I'm not sure what is going on at the other site, but it is not us doing the crawling (in this instance, at least). Any blocks on the IOP range about do not affect us.
Unfortunately they got not everything right in their response, thought that
infomine.ucr.edu was there referer, but it is the UA.
First I thought: OK, someone is playing with the referer.
But it behaved like a bot and came every 24h.
Strangely it stopped at 31/Oct/2003
01/Nov/2003 directory.mozilla.org (DMOZ) crawled us again.
Coincidence?