Forum Moderators: open

Message Too Old, No Replies

MS impersonating FB

         

keyplyr

9:21 pm on Jan 5, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



40.87.57.66 - - [05/Jan/2017:01:20:42 -0800] "GET /example.html HTTP/1.1" 403 4860 "-" "facebookexternalhit/1.1"
40.87.57.66 - - [05/Jan/2017:01:20:42 -0800] "GET /example.html HTTP/1.1" 403 1853 "-" "facebookexternalhit/1.1"
Shame on them

This is not Azure or MS Cloud, this is...
Microsoft Corporation
40.74.0.0 - 40.125.127.255

robzilla

10:34 pm on Jan 5, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I think that is actually an Azure IP address.

lucy24

10:46 pm on Jan 5, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



This is hardly the first time that someone has shown up from a MS range without a recognized MS UA.

This one rang a bell for other reasons, because of course it isn't the ordinary facebook UA
facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
(alternating, for reasons best known to themselves, with /1.0, sometimes even on the same visit). If it showed up just once or twice I'd assume the shorter version was a glitch in the request, but there are too many of them. Counting on fingers says the shorter version is around 1/60 of all (legitimate) requests. And apparently an unknown number of illegitimate ones.

Are they really requesting pages-and-nothing-else (now that's fishy), or was that an artifact of post editing and exemplifying?

keyplyr

11:28 pm on Jan 5, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I think that is actually an Azure IP address.
If it is, then it is not registered as Azure.

keyplyr

4:28 am on Jan 6, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Here's an attempt from AWS...
35.161.92.22 - - [05/Jan/2017:14:54:30 -0800] "GET /example.html HTTP/1.1" 403 4985 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)

robzilla

7:44 am on Jan 6, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I often use MaxMind's GeoIP demo for a quick lookup, and find it pretty reliable. They indicate the IP belongs to Microsoft Corporation (ISP), but that the organization is "Microsoft Azure".

keyplyr

8:39 am on Jan 6, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Thanks robzilla

Sometime there's discrepancies between look-up services. It would make sense it's a perp on Azure.