Forum Moderators: open

Message Too Old, No Replies

User Agent: "13"

coming from an Everyones Internet IP

         

Mokita

2:14 pm on Aug 4, 2006 (gmt 0)

10+ Year Member



66.98.158.** - - [04/Aug/2006:12:37:10 +1000] "GET /file.htm HTTP/1.1" 403 174 "-" "13"

Only requested one file. It received a 403 as I have that EI CIDR blocked.

[edited by: volatilegx at 2:18 pm (utc) on Aug. 4, 2006]
[edit reason]
[1][edit reason] obscured IP address [/edit]
[/edit][/1]

incrediBILL

4:45 pm on Aug 5, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



OK, this has been happening a bunch lately and they just use a single number for the user agent.

The IP you referenced is for ev1servers.net, if you have reverse DNS enabled at the Apache level you can just whack anything that says it's ev1servers.net and avoid zapping Everyones Internet net access customers.

Unless someone knows something about ev1servers.net that I don't know, it's probably safe to block this entire range:

66.98.128.0 - 66.98.255.255

incrediBILL

4:56 pm on Aug 5, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



FYI, just checked for activity in that range in my archive file and it's just filthy with bad activity.

Definitely servers:

Jayde - 66.98.160.93 "Jayde Crawler. [jayde.com"...]

The proxy DIT - 66.98.206.97 "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1), DynaWeb [dit-inc.us...]

Entire blocks of IPs crawling as numbers, "0" "1" or blanks "",
or 66.98.176.80 libwww-perl/5.805

It's a bad neightborhood, what more can I say :)

GaryK

6:02 pm on Aug 5, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I'm not sure what to make of this. When I went to ARIN and searched on ev1servers I got several potential matches. Two of them had a contact e-mail address @hurricanehost.com. Whenever I see hurricane as part of a domain name it makes my skin crawl. I wonder if there is any connection to Hurricane Electric?

incrediBILL

5:44 pm on Aug 6, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Doubtful as hurricanehost is a FL company and hurricane electric is a CA company, they're about 20 minutes away from me actually!

GaryK

7:17 pm on Aug 6, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks Bill. Your word is good enough for me!

Romeo

1:08 pm on Aug 7, 2006 (gmt 0)

10+ Year Member



if you have reverse DNS enabled at the Apache level you can just whack anything that says it's xyz.net

Don't trust on the reverse PTR names. They can be set to anything, and many providers of dedicated servers let their customers do.
While there is a recommendantion that a reverse PTR record 'should' forward resolve, there are no formal rules and no enforcement on this.
Yes, most of these reverse names are mostly correct, but some are sometimes not, especially in the shady area of automatic bots doing dubious things -- from scraping to exploiting and attacking weak servers.

Although my webservers log the reverse DNS names, too, this is mainly for entertainment purposes, and all analyses or decisions are done on IP address level only.

Kind regards,
R.