Welcome to WebmasterWorld Guest from 54.196.238.210

Forum Moderators: Ocean10000 & incrediBILL

Message Too Old, No Replies

Rampant of Redmond

Shivering my Timbers

     

Angonasec

1:51 am on Jan 8, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Be warned, it's cold in WA:

It hit one popular page dozens of times, non-stop, peaking at 12 hits +per second+

No robots.txt, no favicon, no js, nor images, just this frenziedly packing today's access log;


65.52.246.161 - - [07/Jan/2014] "GET /example.htm HTTP/1.1" 200 10522 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0)"

Appears to be genuine MS:
Microsoft Hosting
65.52.0.0 - 65.55.255.255 65.52.0.0/14

We're currently directing it to the rubber-room.

keyplyr

3:45 am on Jan 10, 2014 (gmt 0)

WebmasterWorld Senior Member keyplyr is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month





That covert M$ UA has been active for years. I safely block it.

Angonasec

5:06 am on Jan 10, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



KeyP: Thanks, first time it's had a fit on our site. Do you block it on UA or IP range? The UA posted above appears to be legit except for the 64bit WOW64; missing...

lucy24

6:15 am on Jan 10, 2014 (gmt 0)

WebmasterWorld Senior Member lucy24 is a WebmasterWorld Top Contributor of All Time Top Contributors Of The Month



Page only? No supporting files? css and js always, midi and piwik.php if it can get them; images only from 199.30.

Not the ordinary plainclothes bingbot, then.

Angonasec

7:02 am on Jan 10, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hence the new thread :)

keyplyr

8:16 am on Jan 10, 2014 (gmt 0)

WebmasterWorld Senior Member keyplyr is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month



I do it with a couple filters: if it has that UA *and* comes from that IP *and* asks for... You get the picture.

Angonasec

12:52 pm on Jan 10, 2014 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Yes, there's a few legitimate bing/msn bots using that IP range/CIDR, but "usually" with a kosher UA, so I'm just directing the specific convulsing IP to a dark-green room.
 

Featured Threads

Hot Threads This Week

Hot Threads This Month