Forum Moderators: open

Message Too Old, No Replies

AVG-8 User-Agents revisited

Scamming using an AVG signature

         

dstiles

12:23 am on Jan 9, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm seeing what's almost certainly hacking attempts with a UA and general header info identical with one of the old AVG-8 signatures.

Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)

So far it's been between 10 and 40 hits about 1-10 seconds apart (the lower quantity and longer variation may be due to already canned IPs being blocked elsewhere and not logged here). There appeared to be a build-up over a few days in groups of four hits on two IPs.

Typically the hits are from half a dozen IPs approx in rotation but often coming two successive hits per IP. Some are coming through proxies with no FWD but with a VIA of (so far)...

1.1 announce.cztorrent.net
1.1 counter.auti.hr
1.1 MFWIFW00, 1.1 MFWIFW00
1.1 PNS
1.1 VAG-VGS-ISA1
1.1 www.lsi.die.upm.es
1.1 www.rocketdispatch.com

Sources vary between (probably compromised) web servers and broadband. A proportion of the hits were from web servers on University IP ranges.

Hits so far have been on forms and guestbook pages plus home page. I THINK the forms/guestbooks are not in SEs but they are commonly hit by bad bots.

My reason for believing it's hackers is because it's highly unlikely I'd get a spate of 10-40 hits within seconds from a true AVG from places as distant as Germany, Sweden and USA. So far I haven't seen any acompanying SQL Injection code on these hits.

I'm reluctant to auto-kill the offending IPs because I'm still getting a few "genuine" AVG prefetches.

incrediBILL

7:22 am on Jan 9, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



There's a bunch of SV1 spoofing out there, it's being used by scrapers with rotating UA's and all sorts of nonsense. At this point, any SV1 traffic should be handed a small placebo page and ignored because the genius that created the AVG link scanner opened the door for unlimited spoofing.

The only valid response is unlimited placebo or unlimited blocking at this point.

It's war...

dstiles

9:55 pm on Jan 9, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I've got permanent reporting on SV1 hits anyway but these, exactly mirroring AVG, got a terse rejection message.

Samizdata

12:30 am on Jan 10, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



It's war...

Much as I enjoy a war on bots and respect the vast experience of the regulars here, a quick trawl through my logs shows that the user-agent in question (which we know can be perfectly valid) is used by some obviously human visitors - and in my case, at least, they outnumber suspected and obvious ne'er-do-wells by a considerable margin.

So, while I do not doubt reports of a plague elsewhere, I am in no position to construct defences based on the user-agent alone - and if other filters are tripped it gets intercepted anyway.

How do you folks allow the genuine human visitors through?

...

GaryK

4:26 am on Jan 11, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



How do you folks allow the genuine human visitors through?

They get the standard, prove you're a human form page. If they pass my tests they get through. Otherwise they get my standard, I don't give a damn attitude. After a week of offensively abusive behavior on one of my sites I decided it was time to stop feeling bad about not letting so-called people through.

Samizdata

5:20 am on Jan 11, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Thanks Gary.

I seem to be lucky in that the plague hasn't hit any of my sites yet.

I am certain that the overwheming majority of visitors I get with that user-agent are genuine.

No doubt my time will come.

...