Forum Moderators: open

Message Too Old, No Replies

Opera

         

Dijkgraaf

10:47 pm on Sep 22, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



UA: Opera/9.80 (X11; Linux x86_64; U; en) Presto/2.6.34 Version/10.50

IP: 213.236.208.nn
rDNS: pat-tdc.opera.com

robots.txt: No

Behaviour: Loves to fetch hotlinked images. When actually visiting a page it will also fetch the JavaScript and Images for that page as well as the favicon.ico. So does a good job of pretending to be a browser. What gives it away is that the images are always status 200 rather than 304 (so no caching).

Project Honeypot

Geographic Location [Norway] Norway (Oslo)
Spider First Seen approximately 3 years, 1 month, 4 weeks ago
Spider Last Seen within 1 year, 3 months, 2 weeks
Spider Sightings 9 visit(s)
User-Agents seen with 3 user-agent(s)
Threat Rating 9
First Received From approximately 3 years, 8 months, 1 week ago
Last Received From within 1 year, 6 months, 2 weeks
Number Received 5 email(s) sent from this IP

User Agent Strings
Opera/9.10 (Windows NT 5.1; U; en)
Opera/9.70 (X11; Linux i686; U; en) Presto/2.2.0
Opera/9.70 (X11; Linux i686; U; en) Presto/2.3.0

Brett_Tabke

12:31 am on Sep 23, 2010 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



ya, it is a proxy server called 'opera tubo' and 'opera mini'. There are real humans being served real pages from that 'spider.

Dijkgraaf

2:13 am on Sep 23, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks Brett