Forum Moderators: open

Message Too Old, No Replies

thenewpush.com

Server farm pushes bad/fake UAs

         

Pfui

12:54 am on Aug 30, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Given the array of its subdomains and IPs using the same two UAs, thenewpush.com appears routinely keen on checking others' sites...

RECENTLY:

unsecured.thenewpush.com
libwww-perl/5.812
libwww-perl/5.805

host-72-18-152-8.thenewpush.com
Mozilla/4.0
Same two UAs: [projecthoneypot.org...]

PREVIOUSLY:

mail.thenewpush.com
Mozilla/4.0

mx.thenewpush.com
libwww-perl/5.805

host-72-18-150-13.thenewpush.com
libwww-perl/5.805

host-72-18-150-14.thenewpush.com
libwww-perl/5.805

72.18.143.158
libwww-perl/5.805
Even when IP only, same two UAs: [projecthoneypot.org...]

NOTES:

NO robots.txt ever. Files requested always ONLY favicon.ico and bot traps (directly; oddly). For your convenience:

Range: 72.18.128.0 through 72.18.159.255
CIDR: 72.18.128.0/19

jdMorgan

9:35 pm on Sep 2, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Denied March, 2006:

# Mar 8 08:24:10 2006 The New Push via Data393 & WeHostWebSites.com; multiple scraper UAs
Deny from 64.92.192.0/19 72.18.128.0/19 208.42.224.0/19


Jim