Forum Moderators: open
Fake BingBot
User-agent: *
Disallow: /wp- Status200
Request/wp-login.php
Hostmysite.com
Referer-
RemoteIP50.57.148.171
Time2013-03-17T13:29:50+0000
UserAgentMozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
Query?redirect_to=http%3A%2F%mysite.com%2Fwp-admin%2F&reauth=1
MethodGET
Status302
Request/wp-admin/index.php
Hostmysite.com
Referer-
RemoteIP50.57.148.171
Time2013-03-17T13:29:44+0000
UserAgentMozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)
Query
MethodGET
[edited by: incrediBILL at 3:14 am (utc) on Mar 19, 2013]
[edit reason] unlinked URL [/edit]
especially when Bing and NOT coming from a legitimate MS IP offering valid DNS
Should be blocked by default? What does that mean? It is good practice to add them to the DENY table?
I generally avoid blocking an entire range because of one rogue IP. Singlehop, for example, is not a bad neighborhood. And Rackspace definitely isn't.
This varies from server to server. If there is a list of IPs that should be blocked on every server please post a link to it.
What if you block a data center then an important search engine starts coming from an IP in that data center?
[edited by: Ocean10000 at 2:02 pm (utc) on Apr 3, 2013]
[edit reason] Removed flame [/edit]
[edited by: Ocean10000 at 3:07 pm (utc) on Apr 3, 2013]
[edit reason] Removed Flame [/edit]
Some people advise trying to stop bad robots by testing User Agent strings.
#=========
Others show more diversity:
Same IP address, all within 90 seconds:
66.249.73.112 = DoCoMo/2.0 N905i(c100;TB;W24H16) (compatible; Googlebot-Mobile/2.1;+http://www.google.com/bot.html)
66.249.73.112 = SAMSUNG-SGH-E250/1.0 Profile/MIDP-2.0 Configuration/CLDC-1.1 UP.Browser/6.2.3.3.c.1.101 (GUI) MMP/2.0
66.249.73.112 = Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
Same IP address, six minutes apart:
50.30.34.47 = SEOstats 2.1.0 [github.com...]
50.30.34.47 = wscheck.com/1.0.0 (+http://wscheck.com/)
50.30.34.47 = bot.wsowner.com/1.0.0 (+http://wsowner.com/)
#=========
I surely wont blanket block anything but certain countries.
[edited by: Ocean10000 at 3:20 pm (utc) on Apr 3, 2013]
[edit reason] Removed quote [/edit]
[edited by: wilderness at 1:20 am (utc) on Apr 3, 2013]
...scumbots mutate the UAs within seconds of receiving a 403.
Gaia, all these spoofed Biongbots are coming from hosting companies that should be blocked by default
My dedicated firewall is full with individual ips.
I wonder if there is any real solution available for this problem. I just don't want scrapers to hit my server.