Forum Moderators: open

Message Too Old, No Replies

Where am I?

         

lucy24

10:23 pm on Dec 6, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Where's that “And the winner is...” thread when I need it?

69.163.200.125 - - [06/Dec/2015:06:12:05 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)" 
69.163.200.125 - - [06/Dec/2015:06:12:09 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
69.163.200.125 - - [06/Dec/2015:06:12:11 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
69.163.200.125 - - [06/Dec/2015:06:12:15 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
69.163.200.125 - - [06/Dec/2015:06:12:19 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
69.163.200.125 - - [06/Dec/2015:06:12:23 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
69.163.200.125 - - [06/Dec/2015:06:12:27 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
69.163.200.125 - - [06/Dec/2015:06:12:31 -0800] "GET /where_am_I? HTTP/1.1" 404 2262 "I'm lost eh?" "SuperBot/3.1 (Win32)"
Nothing new about the IP-- the generally inoffensive DreamHost-- or for that matter the UA with its conveniently blockable "Bot" element. But those are literal spaces and question marks in the request and referer.*

Is there a prize for Truth In Referring?


* I looked it up. Among other things it’s a song by Bob Marley, whom I never particularly thought of as Canadian.

keyplyr

7:54 pm on Dec 8, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



they're lost eh?

blend27

12:01 am on Dec 11, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Redirect them to [di.fm...]

keyplyr

4:14 am on Dec 11, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Redirect them to [di.fm...]
I don't know if that was an attempt at humor or not, but IMO it is unethical and simply bad webmastering to redirect traffic to remote destinations not owned by you. How would you like it if some site redirected toxic traffic or malicious agents to your site?

lucy24

5:43 am on Dec 11, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I once knew someone who ran a tiny little server out of her garage. One hotlink, and her bandwidth for the month would be used up. She dealt with it by pointing hotlinks to an array of horrible lunatic-fringe sites-- the kind where the hotlinker would lose no time getting rid of their link, whereas a polite request and/or a simple 403 might be ignored for days on end if not forever. (Even a bare-bones 403 uses some resources.) The "victim" sites never cared, because if you're on the lunatic fringe you don't care what brings people to your site, as long as they get brung.

I have no idea how she converted an image request into a fully displayed page-- iframe? I don't think they existed yet-- I just know that it worked as intended.

Just sayin ;)

keyplyr

5:53 am on Dec 11, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I'm say'n it is an ethics issue. It is wrong to do this.

Besides, it's doubtful the FCC would see the justification.

blend27

4:27 pm on Dec 12, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



@keyplyr,
Of-course it was with humor in mind :)

@Lucy24

a bit OT but,

My favorite, still is, is for image hotlinkers on MFA(and such sites) is to create and image that is 1px wide and 6000px tall(or 6000x1 ). At 1px/inch resolution and in a .GIF format it should be no more than a whooping 128 bite heavy.

With our ol' friend .HTACCESS:
Depending on offending site`s layout/css
- if tall is selected then everything past the reference to image is 6000px deep.
- if wide is selected then everything to the right(yes! all the ads in the right column) are 6000px to the right - KABOOM.

Why?

A few years back My relative asked me if there is something could be done about the hot-linked images when bunch of UN-educated Yoyos started hotlinking to images from their Forum site and trash talking about it in a Foreign language. No more that they knew that we also spoken that Language, plus fluent in several programming langs.

Before I did anything I wrote an email to a Forum Mod and my requests were ignored. So I put the block in place, and wrote to the same Mod again a week later. He/She wrote a little piece of script that converted "mame of our domain" on the fly into something else when someone tried hotlinking.

No More!

tangor

4:32 pm on Dec 12, 2015 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Clever bots give me a chuckle from time to time. Mostly right before I nuke them.

lucy24

12:08 am on Feb 1, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



69.163.200.125 - - [28/Jan/2016:22:51:53 -0800] "GET /images/ HTTP/1.1" 403 3450 "nowhere" "Mozilla/5.0 (Linux; Android 5.1; LG-H811 Build/LMY47D) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.83 Mobile Safari/537.36" 
69.163.200.125 - - [28/Jan/2016:22:53:20 -0800] "GET /images/ HTTP/1.1" 403 3450 "nowhere" ".36 (KHTML, like Gecko) Chrome/47.0.2526.83 Mobile Sa ,"
69.163.200.125 - - [28/Jan/2016:22:54:12 -0800] "GET /images/ HTTP/1.1" 403 3450 "{referer spam}" "sausagefest"
69.163.200.125 - - [28/Jan/2016:22:55:20 -0800] "GET / HTTP/1.1" 200 5583 "{referer spam}" "sausagefest"
69.163.200.125 - - [28/Jan/2016:22:56:35 -0800] "GET / HTTP/1.1" 200 5583 "{referer spam}" "sausagefest"
:: sigh ::

Guess it's time to block the range. Cursory log check tells me I've had a fair number of visits from the neighborhood, but generally they were blocked on UA / referer / request grounds so I didn't have to pay attention.

:: further detour to raw logs to investigate UA pattern ::

Goodness, what an astounding number of legitimate agents using the bare name ^\w+$. Even the narrower [a-z]+ isn't wholly objectionable. On the other hand, referers in the form \w+ are rare but it will do no harm to block them.

keyplyr

1:41 am on Feb 2, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I see no reason to allow this server farm access (I don't.) It doesn't need port 80 for cross-talk.

lucy24

3:25 am on Feb 2, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



In my book, server farms are innocent until proven guilty. If they host nothing but inoffensive robots, they're welcome to do their stuff. Matter of fact, I think it's the first range from this particular host that I've even had occasion to look up, let alone block-- and they're one of the bigger hosts.

keyplyr

3:30 am on Feb 2, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Depends on what you stand to loose I guess.