Forum Moderators: open

Message Too Old, No Replies

Bork Edition

Not the Swedish chef

         

caribguy

9:55 am on Mar 29, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I think this might be useful for people who are being borked out of their content. I know it might be considered to be a faux pas to name nad shame specific ip addresses, but considering Panda the copypasta below may be useful for preserving unique content...

www.example.com 76.22.184.141 - - [27/Mar/2011:01:02:19 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bo
rk-edition [en]"
www.example.com 68.93.137.121 - - [27/Mar/2011:01:03:14 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 24.197.185.44 - - [27/Mar/2011:01:03:34 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 24.197.185.44 - - [27/Mar/2011:01:03:36 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.80.49.127 - - [27/Mar/2011:01:03:42 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 24.130.95.20 - - [27/Mar/2011:01:04:08 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 46.50.168.142 - - [27/Mar/2011:01:04:09 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 46.50.168.142 - - [27/Mar/2011:01:04:19 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.57.151.5 - - [27/Mar/2011:01:04:24 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.80.49.127 - - [27/Mar/2011:01:04:53 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 67.185.26.36 - - [27/Mar/2011:01:05:00 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 67.185.26.36 - - [27/Mar/2011:01:05:02 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.79.147.126 - - [27/Mar/2011:01:05:13 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.79.147.126 - - [27/Mar/2011:01:05:14 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 67.185.26.36 - - [27/Mar/2011:01:05:16 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 67.185.26.36 - - [27/Mar/2011:01:05:18 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.216.157.115 - - [27/Mar/2011:01:05:27 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.216.157.115 - - [27/Mar/2011:01:05:31 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 108.56.77.15 - - [27/Mar/2011:01:05:32 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 108.56.77.15 - - [27/Mar/2011:01:05:33 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 70.188.48.18 - - [27/Mar/2011:01:05:34 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 70.188.48.18 - - [27/Mar/2011:01:05:35 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.81.72.92 - - [27/Mar/2011:01:05:38 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.81.72.92 - - [27/Mar/2011:01:05:40 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 69.124.150.164 - - [27/Mar/2011:01:05:46 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 69.124.150.164 - - [27/Mar/2011:01:05:48 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 46.50.168.142 - - [27/Mar/2011:01:05:48 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 46.50.168.142 - - [27/Mar/2011:01:05:56 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.80.49.127 - - [27/Mar/2011:01:06:02 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.80.49.127 - - [27/Mar/2011:01:06:06 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 208.87.243.233 - - [27/Mar/2011:01:06:08 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 208.87.243.233 - - [27/Mar/2011:01:06:09 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.193.218.249 - - [27/Mar/2011:01:06:38 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.193.218.249 - - [27/Mar/2011:01:06:39 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.38.201.157 - - [27/Mar/2011:01:06:40 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 68.38.201.157 - - [27/Mar/2011:01:06:41 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 99.88.162.170 - - [27/Mar/2011:01:06:44 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 67.185.26.36 - - [27/Mar/2011:01:07:04 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 75.70.196.66 - - [27/Mar/2011:01:07:09 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 46.50.168.142 - - [27/Mar/2011:01:07:18 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.80.49.127 - - [27/Mar/2011:01:07:26 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
www.example.com 173.80.49.127 - - [27/Mar/2011:01:07:32 -0500] "GET / HTTP/1.0" 403 274 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
forum.example.com 173.80.49.127 - - [27/Mar/2011:01:07:40 -0500] "GET / HTTP/1.0" 403 276 "http://forum.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
forum.example.com 173.80.49.127 - - [27/Mar/2011:01:07:49 -0500] "GET / HTTP/1.0" 403 276 "http://forum.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"

dstiles

9:35 pm on Mar 29, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I have long blocked the sub-string...

MSIE 5.5; Windows NT 4.0) Opera 7.0

... which is broken anyway.

All but one of the IPs you list are dynamic (broadband). Since more than half are comcast you could block all comcast ranges! :)

I have three or four of the exact IPs you list in my security "trap" log, logged in the past few days. From the evidence all of those are compromised (ie virus'd) IPs. Not a lot you can do other than block by UA.