Forum Moderators: open

Message Too Old, No Replies

HipChat

         

lucy24

5:09 pm on Mar 21, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Anyone know what this is?

192.188.252.abc - - [21/Mar/2017:07:54:49 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "https://www.google.com/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36" 
192.188.252.abc - - [21/Mar/2017:07:54:57 -0700] "GET /favicon.ico HTTP/1.1" 200 662 "http://example.com/dir/subdir/blowups/filename.jpg" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36"

192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.7.0 Chrome/49.0.2623.111 Safari/537.36"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_3) AppleWebKit/602.4.8 (KHTML, like Gecko) HipChat/732 (modern)"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.110 Safari/537.36"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.7.0 Chrome/49.0.2623.111 Safari/537.36"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) HipChat/732 (modern)"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.7.0 Chrome/49.0.2623.111 Safari/537.36"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.7.0 Chrome/49.0.2623.111 Safari/537.36"
192.188.252.abc - - [21/Mar/2017:07:55:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.7.0 Chrome/49.0.2623.111 Safari/537.36"
192.188.252.abc - - [21/Mar/2017:07:57:04 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat"
192.188.252.abc - - [21/Mar/2017:08:05:39 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_3) AppleWebKit/602.4.8 (KHTML, like Gecko) HipChat/732 (modern)"
192.188.252.abc - - [21/Mar/2017:08:07:16 -0700] "GET /dir/subdir/blowups/filename.jpg HTTP/1.1" 200 45389 "-" "HipChat Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) QtWebEngine/5.7.0 Chrome/49.0.2623.111 Safari/537.36"
IP belongs to The Urban Institute, which leaves me none the wiser. I would have guessed some kind of message-board utility--craftily bypassing hotlink protection by not sending a referer--except that the initial human visit was from the same IP.

?

keyplyr

11:10 pm on Mar 21, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



HipChat
Team chat that's actually built for business
Persistent, searchable, and loaded with goodies: group chat, video chat, screen sharing, and the security your IT team craves.
source: hipchat.com

Could be HipChat sharing your page (screensharing) with another HipChat user - or - could be this app attribute is always present in the UA string (if installed) and the visit was a normal browser user from work - or - they could be doing really bad stuff!

lucy24

12:29 am on Mar 22, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



could be this app attribute is always present in the UA string

It's the sheer number of different UAs that confuzzled me. I count four in this short excerpt, including a lone "HipChat" and-that's-all, apart from the original human.

Maybe a workplace that's got it installed on all their computers (but not the initial human's laptop), also explaining the consistent IP?

:: shrug ::

keyplyr

1:03 am on Mar 22, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I was thinking the screensharing might account for that.

Scenario: office worker discovers your assets. Wants to share with coworkers. Launches HipChat and shares your page.They all check it using the app.

If you consider the features mentioned in the app description above, it makes sense.