Forum Moderators: open

Message Too Old, No Replies

Odd

         

wilderness

12:47 am on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Anybody seen odd activity from this IP?
Note change of UA.

64.235.157.zzz - - [14/Apr/2011:14:42:01 -0600] "GET / HTTP/1.0" 301 0 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/0.4.154.29 Safari/525.19"

64.235.157.zzz - - [14/Apr/2011:15:31:04 -0600] "GET / HTTP/1.0" 301 595 "-" "Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/534.13 (KHTML, like Gecko) Chrome/9.0.597.107 Safari/534.13"

dstiles

7:44 pm on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Baracuda proxies? You would expect to see different UAs from time to time.

On the other hand it looks as if at least one of the browsers is out of date (don't know much about google chrome, if that's what it is) so could be bot activity through the proxy.

If the UAs are correct it's two different machines: windows and linux.

Or it could be a User-Agent switcher in action.

wilderness

8:46 pm on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



many thanks.

I've denied the entire IP range, this very small site with almost as many new pages added recently as existed previously, does not warrant such antics.

dstiles

9:07 pm on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm always wary of proxies but in this case I allow access unless the UA is really bad. As far as I'm aware baracuda proxies are used through a baracuda firewall so SHOULD be good - unless a virus has taken hold behind the firewall, in which case who knows?

If anyone knows what the correct chrome versions are for windows and linux it would be interesting to follow that line in your log lines but I have to say the windows one looks bad.