Forum Moderators: open

Message Too Old, No Replies

new disguise of rippers?

         

the_nerd

1:44 pm on Dec 10, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hi,

just saw this appear as referer in my logfile:

[google."tld"...]

Hitting very agressively (10 pages per second), always with the same referer string. Is that a new kind of spambot - or just a firefox bug (firefox 2.0)? The keyword combination is on one of my pages, but the request came for dozens of pages that don't have it.

the_nerd

the_nerd

9:13 am on Dec 11, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



any idea?

looked into it, "attack" works like this:

1. read one page that contains "keyword1 keyword2", no referrere info
2. come back after 5 seconds, read same page, but fake google kw referer
3. read 3-5 pages without referer
4. request tons of pages all with identical referer string (fake-google)

I'd just like to know if that is common ripper behaviour, or something that used to be called referer spam, or something new.

nerd.

Matt Probert

9:40 am on Dec 11, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



What's the IP address? Is it a range of IP addresses? There are known nefarious bots operating on IP addresses

69.60.120.n and 64.251.30.n

Matt

the_nerd

11:11 am on Dec 11, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



212.41.120.n (single ip, not sure if tos-compliant to post full ip)

nerd

wilderness

5:39 pm on Dec 11, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



212.41.120.n (single ip, not sure if tos-compliant to post full ip)

212.41.120.0 - 212.41.127.255

The Class C range of 120-127 belongs to the same provider in China, thus making the forum policy for omitting the the Class D range slighly assinine.

gregbo

11:21 pm on Dec 11, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Actually, class D is for IPv4 multicast addresses (224.0.0.0 - 239.255.255.255), not the least significant byte of an IPv4 address.

incrediBILL

12:54 am on Dec 14, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I don't think it's a disguise as some rippers try to do something lame with the referrer so people don't bounce them off the site. Some are more clever and actually use the real referrer while crawling.

When it comes to Asian IPs, if you don't do business in Asia the Great Firewall of China will help you sleep nights.

wilderness

3:37 am on Dec 14, 2006 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



When it comes to Asian IPs, if you don't do business in Asia the Great Firewall of China will help you sleep nights.

Same applies to RIPE