Forum Moderators: open

Message Too Old, No Replies

vanoppen.biz

         

keyplyr

1:39 am on Dec 27, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
rDNS: ns1.spectrumnet.us
WHOIS: vanoppen.biz 174.127.128.0/19
robots.txt: no

3 IP tag team crawled from D rage. Mostly direct requests for HTML pages (no images) but also sitemap.xml, a couple JS and a few disallowed files which drew my attention.

Pfui

6:28 pm on Dec 27, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



174.127.132.1*
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)

robots.txt? NO

After that hit bot traps along with many first and second level-deep files on 12-03, I did a bit of Googling. Spectrum Networks/Vanoppen.biz (John van Oppen)/etc., a Mercer Island, WA-based ISP, has a less than stellar reputation:

1.) See data specific to the IP that hit me here [projecthoneypot.org]. Check out the comments below the long list of "IPs in the Neighborhood."

2.) Search results show the ISP has history of hosting malware site(s).

3.) Search results show the ISP has history of hosting scraper(s) and/or scraped site(s)/site theft:
- Search for: Vanoppen.biz Green Tree
- Scroll down to: The Zombie Botnet DNS Data

4.) Search results show the ISP owner/admin has sigged himself as providing "Internet hosting and security services". (That last part? Not so much, apparently.)

5.) Head's up, too, re:
- 76.191.64.0 - 76.191.127.255 (76.191.64.0/18)
- 208.76.152.0 - 208.76.155.255 (208.76.152.0/22)

Lain_se

2:52 pm on Feb 10, 2010 (gmt 0)

10+ Year Member



I know this thread is a bit old, but I would like to add that this Vanoppen.biz web host was made more than a dozen attempts to gain unauthorized access to my servers and in a few cases the attack could of almost been considered a denial of service.

They NEVER replied to any of my requests to explain the actions or for abuse complaints. So I have denied every CIDR range I could find on them and to date no more attacks have occurred. If anyone wants to update your htaccess to block this scum here is what I have.

deny from 76.191.64.0/18 "vanoppen.biz Hacker"
deny from 174.127.128.0/19 "vanoppen.biz Hacker"