Forum Moderators: open

Message Too Old, No Replies

very suspicious

         

stn24

9:06 pm on Mar 24, 2001 (gmt 0)



Just got hit by:
IP : 206.47.244.56
UA : Mozilla/4.5 [en] (Win98; I)
FROM / VIA : Hunter Steel
The creepy part is that it hit 2 of my cloaked pages in 1 second and nothing else. These pages receive either bot traffic or referer traffic. The referer variables are empty. The IP resolves to : ch6smc.bellglobal.com. Makes me a little paranoid especially since I'm in the middle of FAST crawl.

littleman

5:07 am on Mar 26, 2001 (gmt 0)



I could tell you with 99% certainty that these guys aren't a Fast shadow bot. I did a log scan and pulled these out from the same class C from hits today.
The requests came in for pages that are not in Fast's db and have never been submitted to them. The first three are requests for pages only in Inktomi's
db and the last one was hitting a page that sits only in excite. From what I could tell they are spidering the SEs.

Name: ch7smc.bellglobal.com - Address: 206.47.244.57 Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)
Name: ch4smc.bellglobal.com - Address: 206.47.244.60 Mozilla/4.74 [en]C-SYMPA (Win98; U)
Name: ch2blm.bellglobal.com - Address: 206.47.244.93 Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
Name: ch2blm.bellglobal.com - Address: 206.47.244.93 Mozilla/4.0 (compatible; MSIE 5.0; Windows 98) - Sun Mar 25 09:52:32 2001

BTW they are out of Canada:

Bell Sygma (BELLGLOBAL-DOM)
160 Elgin St. Flr. 12
Ottawa, Ontario K1G 3J4
CA

Looks like these are the same guys:
[BELLNEXXIA.COM...]
[BELLNEXXIA.COM...]
The best use of flash I've seen in a while

These are also them:
WorldLinx Telecommunications, Inc.
160 Elgin Street, Floor 12
Ottawa, Ontario K2P 2C4
CA

<ADDED>
As big as these guys are they aren't very on top of it! I just tested 206.47.244.57, it's a proxy! Looks like someone is piggybacking off their system.

stn24

6:36 am on Mar 26, 2001 (gmt 0)



Thanks Littleman appreciate your input. It makes little more sense now. I first thought that FAST was using ip's from Bell, I've seen them using ip's from TELUS (another phone company) but they had their typical user agent. Thanks.