Forum Moderators: open
31.13.115.ddd - - [31/Aug/2019:03:16:50 -0700] "GET /?fbclid=IwAR1Fa4MWFMOwEryMprDMwEg68EW9Uyj-fS7wFVr5I_DVut1mW4Be0yVNU_E HTTP/1.1" 403 1860 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"
31.13.115.ddd - - [31/Aug/2019:03:16:51 -0700] "GET /boilerplate/errorstyles.css HTTP/1.1" 301 613 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"
31.13.115.ddd - - [31/Aug/2019:03:16:55 -0700] "GET /piwik/piwik.js HTTP/1.1" 403 1860 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"
31.13.115.ddd - - [31/Aug/2019:03:16:55 -0700] "GET /favicon.ico HTTP/1.1" 301 581 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b" 31.13.115.ddd - - [31/Aug/2019:03:16:54 -0700] "GET /boilerplate/errorstyles.css HTTP/1.1" 200 4226 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b"
31.13.115.ddd - - [31/Aug/2019:03:16:56 -0700] "GET /favicon.ico HTTP/1.1" 200 639 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/534+ (KHTML, like Gecko) BingPreview/1.0b" How is that possible?After spending some time comparing logs and headers for this and another common FB range, I would conclude that they are renting out 31.13.115 and possibly other areas ... except that during the same time period I continue to see externalhit requests from the identical IPs. In addition to the ones that caught my attention here, there have been a handful of blocked (out of sight, out of mind) robots.