Forum Moderators: open

Message Too Old, No Replies

Mikrotik HttpProxy

Misconfigured headers /scraper

         

caribguy

8:24 am on May 6, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Have been seeing a few errors from this bot in my app server log lately. Mostly because the HTTP_VIA header is bonkers:
1.1 222.124.178.nn (Mikrotik HttpProxy)


In today's event, an Indonesian douche hides behind New Joysey server farm:


HTTP_ACCEPT'image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*'
CONNECTION_TYPE'Keep-Alive'
HTTP_USER_AGENT'Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; en) Opera 8.50'
HTTP_REFERER'affbb.com'
HTTP_X_FORWARDED_FOR'173.248.141.mm, 222.124.178.nn'
HTTP_VIA'1.1 222.124.178.98 (Mikrotik HttpProxy)'
SERVER_PROTOCOL'HTTP/1.1'
HTTP_X_PROXY_ID'464911999'


Love that UA too, blocked without giving it a second thought.

caribguy

5:46 pm on May 6, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Disregard my above comment on the VIA header, it seems to be correct according to RFC 2068 (14.44). [ietf.org...]

dstiles

10:03 pm on May 6, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Maybe correct but I've blocked Mikrotik proxy completely.

I've seen several scrape attempts using it, all rejected. Most of them came from a US server farm. Yours comes from an Indonesian block, which is almost as bad (I think it's a static DSL block but not sure).