Forum Moderators: open

Message Too Old, No Replies

BingPreview from Facebook

         

lucy24

5:39 pm on Sep 1, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



For a while now I’ve been seeing human(oid) visits from FB ranges, but this one tops all. The site is HTTPS. Free lookup insists the IP still belongs to Facebook (FB Ireland, which may be relevant).

HTTP:
31.13.115.ddd - - [31/Aug/2019:03:16:50 -0700] "GET /?fbclid=IwAR1Fa4MWFMOwEryMprDMwEg68EW9Uyj-fS7wFVr5I_DVut1mW4Be0yVNU_E HTTP/1.1" 403 1860 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b" 
31.13.115.ddd - - [31/Aug/2019:03:16:51 -0700] "GET /boilerplate/errorstyles.css HTTP/1.1" 301 613 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"
31.13.115.ddd - - [31/Aug/2019:03:16:55 -0700] "GET /piwik/piwik.js HTTP/1.1" 403 1860 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"
31.13.115.ddd - - [31/Aug/2019:03:16:55 -0700] "GET /favicon.ico HTTP/1.1" 301 581 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"

HTTPS (i.e. exactly what you would expect from a human visitor in the same circumstances):
31.13.115.ddd - - [31/Aug/2019:03:16:54 -0700] "GET /boilerplate/errorstyles.css HTTP/1.1" 200 4226 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b" 
31.13.115.ddd - - [31/Aug/2019:03:16:56 -0700] "GET /favicon.ico HTTP/1.1" 200 639 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"

Since piwik was blocked, I don't know if they would have acted on it. There were no immediately preceding human visits (this is a VERY low-traffic site), and no externalhit requests at any time.

File under: wtf?

TorontoBoy

7:09 pm on Sep 1, 2019 (gmt 0)

5+ Year Member Top Contributors Of The Month



What? How is that possible? Is FB teaming up with Bing? Do you have any req header info?

lucy24

8:24 pm on Sep 1, 2019 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



How is that possible?
After spending some time comparing logs and headers for this and another common FB range, I would conclude that they are renting out 31.13.115 and possibly other areas ... except that during the same time period I continue to see externalhit requests from the identical IPs. In addition to the ones that caught my attention here, there have been a handful of blocked (out of sight, out of mind) robots.

I've assumed that the human visits were coming through the facebook app in some way (analogous to all those google mobile ranges, Wireless Transcoder or whatever its official name is) but that wouldn't account for Bing Preview.

Goodness. Facebook aren't running an open proxy are they? There's nothing unusual in the headers, except one that sent an empty Accept: header, which may have been a one-off glitch.

TorontoBoy

8:50 pm on Sep 1, 2019 (gmt 0)

5+ Year Member Top Contributors Of The Month



FB VPN app, supposedly shut down: [theverge.com...] 2019 Feb