Forum Moderators: open
order allow,deny
deny from 82.80.248.0/21
deny from 82.146.32.0/19
deny from 82.196.0.0/20
etc...
allow from all deny from 82.80.248.0/21,82.146.32.0/19 there is no clear starting place on this
cccomm.com
64.113.160.0/20
64.113.160.0 - 64.113.175.255
Deny from 64.113.160.0/20 It's more a question of actually implementing some of the ip address being listed in pages and pages and pages and pages of ip farms. I'm trying to ask what is the process that you folks use when looking at that data. I hope that makes sense.
Those types of people are usually the most unfriendly and types who know everything and therefore really have no clue what it's like to come in with fresh eyes
I can't quite understand how to get from looking at raw logs for example, to determining which IPs from those threads that I should be focused on.
many many many wp-login.php
I know a while back I came across a htaccess entry that will will block all ips, except for ones I manual enter. I don't know the ins and outs, but Limit Login Attempts, even with the most absurd settings possible, appears to have no appreciable positive results. But in terms of you suggesting of denying all request,
Limit Login Attempts, even with the most absurd settings possible, appears to have no appreciable positive results.it is because you have an expectation that there will not be any requests, but that's not how it works. Unless you see requests with a "200" (OK) server response, it is doing exactly what it is supposed to do: prevent logins.
Are the posts being made in the content farms threads, are all these evil?
Some of the legacy threads are gone now, but basically this particular thread, the Server Farms sub-category of the Search Engine Spider and User Agent Identification Forum, does list all known hosting server farms, clouds servers, data centers & colocation company ranges. AWS is so large and prominent, it got its own thread.
All this has been many years in the making and quite a lengthy read but one that will answer most of your questions. These forums are an archive of information for today's webmaster. Most bots do get mentioned in one of the forum's threads, but as I noted, many older threads are now either gone, or unsearchable after the reorganization of WW.
If you see behavior in your server's access logs that is questionable, look up the IP address. Do the research. Find out what type of company the range is assigned to. Many agents disguise themselves as something they're not. In time you'll become skilled at profiling them.
Most of us agree that agents from any of the above have no reason to access our web sites, thus we list the company and their respective server ranges here. What you do with this information is up to you. What works for one webmaster may not for another. One site's bad agent may be thought of as benign or even beneficial to another. Your site, your choice.
-keyplr responding to questions about: "How do you decide what to list in these threads?", "Is it intended to collect all farms by some criterion? Or are are you just using it to share occasional discoveries?", "How do you distinguish between a human-free farm and a provider who just happens to have a human in it with a virus-infected computer?", "And how do you decide what range to include? D'you just look up the CIDR in domaintools or some equivalent and block that?"