Forum Moderators: open
IP: 38.105.244.nnn -> hailoo.com
"Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.8.1.16) Gecko/20080702 Iceweasel/2.0.0.16 (Debian-2.0.0.16-0etch1)"
If you didn't know, Iceweasel is the name of Firefox on Debian because Debian doesn't use the Mozilla build of Firefox which causes licensing issues, more legal nonsense than I have ever read in one sitting but truth is stranger than fiction:
[en.wikipedia.org...]
Anyway, back to the source of this IP...
Whois on the IP says:
network:Org-Name:Hailoo LLC
Searching for Hailoo LLC turns up this parked domain:
Domain Name: HAILOO.US
Registrant Organization: Hailoo Search Inc.
Registrant Email: <snip> @hailoo.com
So it all appears to be related yet nothing to see anywhere.
Hailoo, is anyone there?
Record expires on 13-Oct-2009.
Record created on 13-Oct-2005.
Registrant:
Hailoo, Dwan
Hailoo Search Inc.
(address in East Setauket, NY)
US
Whois gives the IP block 48/29 for hailoo but a different (Newark) address.
Sounds like a (badly behaved?) SE using mozilla?
Just found a bit in a job advert:
"(developing) sophisticated search technology for a large, Middle Eastern user-base..." (Linux-based)
IP: 38.105.244.nnn -> hailoo.comFTR: IP(hailoo.com)-3 = 38.105.244.nn -> hailoo.com
Her search engine is in stealth mode (since 2005) or her servers are (again) under foreign control (hailoo+one+of+my+computers+is+sending+out+spam).
.com, .net, .org, .biz, .info, .de, .dk, .ru, .ir, … many domains for "a small hi-tech Internet start-up company based in New York", operating in stealth mode.
a large, Middle Eastern user-baseRussia is not in the Middle East.
It's not unusual for an SE type of company to register domains world-wide.
I don't dispute that the server(s) may be hijacked or otherwise under the control of spammers. A lot of botnets are controlled through and utilise US servers and this may be the case here, especially if the site has been taken down - although in that case it's odd there is no "hijack" site replacing it.
Same user agent came from PSI's 38.99.65.nn got denied
Then tried from Level3 8.20.84.nn and also was denied.
That IP is showing Apache 2 Test Page powered by CentOS
Slightly different agent then tried and got denied from an Egypt DSL IP and Austria 212.31.90.nn
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.6) Gecko/2009020409 Iceweasel/3.0.6 (Debian-3.0.6-1)
Chatter on forums includes forum owners reporting a signed in member called 'Hailoo' going through all posts fast (crawling) and one of them confirming it is a new search engine.
I'd say the name Hailoo is a fake front for a bot owner running several boxes to populate a database for another project under a different name.
Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.18) Gecko/20081030 Iceweasel/2.0.0.18 (Debian-2.0.0.18-0etch1)Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.6) Gecko/2009020409 Iceweasel/3.0.6 (Debian-3.0.6-1)
Forgive my ignorance, but aren't these user agents for an obscure but legitimate browser?
Re-read my first post, I linked out to all the information about it.
Right, but how did Hobbs know to deny the user agent from the Egyptian and Austrian residential IP when it could have been a real browser?
Iceweasel is a Debian build of Firefox, which isn't obscure at all, just the wacky alias.
I should've used a better word than "obscure". How about "rare". I was implying that only a tiny minority of people use Linux for personal PCs, so it's an uncommon user agent but can be still a legitimate user.
[edited by: Umbra at 1:59 am (utc) on April 4, 2009]