Forum Moderators: open

Message Too Old, No Replies

GozaikBot

         

keyplyr

9:28 pm on Aug 28, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Seems to be a SE for monster.com headhunter service, now including social media:

"GET /robots.txt HTTP/1.0" 200 3739 "-" "GozaikBot (www.gozaik.com;webmaster@gozaik.com;www.gozaik.com/gozaikbot.html)"
"GET /images/example.jpg HTTP/1.1" 304 211 "-" "Googlebot-Image/1.0"

Host: AWS
75.101.128.0 - 75.101.255.255
75.101.128.0/17

What they want with my images is a mystery.

keyplyr

11:10 pm on Aug 28, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Allowable time to edit post has past.

Forgot to say that the "Googlebot-Image/1.0" UA is spoofed. This hit also came from the same IP a millisecond later.

lucy24

2:50 am on Aug 29, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



the "Googlebot-Image/1.0" UA is spoofed

And that's all we need to know, isn't it? Sending a blatantly fake UA is a guaranteed way to draw closer attention to yourself ... and that attention is not likely to be favorable.

The 304 is a bit worrying, because it implies they've been there before. That is, it means "not modified since ..." something, and I really doubt your server interprets the "something" as "the last time the real imagebot, from a completely different IP, visited".

keyplyr

3:41 am on Aug 29, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Your correct. This is from a new client's site & I'm in the midst of installing a comprehensive defense stratagem (I get paid more when stuff sounds high-tech.)


- - -

From a few minutes ago:"

"GET / HTTP/1.1" 403 1525 "-" "-"

Same IP address, but now that they've been blocked a few times, they've gone stealth. Also notice they hit the robots.txt with the 1.0 protocol but use 1.1 for other web documents. I think a lot of agents do that but I don't understand why.

lucy24

6:35 am on Aug 29, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



now that they've been blocked a few times, they've gone stealth

If they think that not sending a User-Agent header will increase their chances of getting through, you are probably not dealing with a robotic mastermind.

keyplyr

8:49 am on Aug 29, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month




Maybe they should search monster.com for someone better?