Forum Moderators: open

Message Too Old, No Replies

Iterasi.com, yet another archiving site

         

incrediBILL

9:12 pm on Feb 1, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Their archiving tools claim to be MSIE 7, they have no unique RDNS and operate from Infinity Internet which is mixed usage including residential.

198.145.117.nnn
"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; SLCC1; .NET CLR 2.0.50727)"

OrgName: Infinity Internet, Inc.
NetRange: 198.145.0.0 - 198.145.255.255
CIDR: 198.145.0.0/16

Reverse RDNS for the colo is:
pointer ip78.nnn.colo.iinet.com

So the best I could do to make sure I blocked their IPs without whacking residential was blocking the colo segment of their operation ".colo.iinet.com" using the RDNS response.

wilderness

4:09 am on Feb 5, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



mixed usage including residential.

Bill,
I'm seeing more and more lines in my logs that are attributable to these "mixed usage" providers (not just your example).

As a result, I'm left asking myself some questions?
1) Are residential customers selecting non-traditional
providers for the connection?
2) Is the internet traffic progressing at such a rate that
these new services are appearing?
3) Is Business expanding at such a rate that these
providers are enticing their customers to deplore these
"mixed usage providers"?
4) Is it all just a farce and these "mixed usage providers"
have open ranges which may be utilized as proxies?

I'm sure there are other possibilities I've missed :(

BTW had two requests from this provider today (seven hours apart) and with a different UA and different Class C (.116):

"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"

I'm not as polite as you and denied the Class B.

Don

jmccormac

11:15 pm on Mar 16, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Seeing a scraper botnet one one of my sites today using "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)". The mix of IPs is .br, .ca, some APNIC IPs and a few European ones. It is the same botnet that has been active for a few years now - the IPs may vary but the characteristics seem to remain constant.

Regards...jmcc