Forum Moderators: open

Message Too Old, No Replies

Anybody Else Getting Bot Attacked Via MSFT IPs?

20.192.0.0/10, 20.33.0.0/16 and More

         

martinibuster

2:38 pm on Jun 28, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Awoke this morning to Wordfence alerts from multiple sites all getting slammed hard by bots coming in through various Microsoft (presumably Azure) IP addys.

20.192.0.0/10
20.33.0.0/16
20.36.0.0/14
20.34.0.0/15
20.40.0.0/13
20.48.0.0/12
20.64.0.0/10
20.128.0.0/16
20.196.152.2

jmccormac

5:00 pm on Jun 28, 2022 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Have some of those ranges blocked for some time due to iffy activity. Just took a look to see if any non-blocked MSFT ranges showed up and it seems clear. There was a CERT message about Adminer having a vulnerability. It might have been scanning for it.

Regards...jmcc

[edited by: jmccormac at 5:33 pm (utc) on Jun 28, 2022]

martinibuster

5:19 pm on Jun 28, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



I haven't had time to examine the bot or what it was doing. Thanks for the info!

LifeinAsia

5:25 pm on Jun 28, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Have been for some time. They get blocked as they hit.

Haven't flipped the lever to block the entire range yet, but feeling more and more like doing it...

martinibuster

7:58 pm on Jun 28, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Yeah, these ranges don't generate a constant level of bots like other sources so I'm kind of inclined to keep these IPs open for now.

lucy24

4:53 am on Jun 29, 2022 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



:: detour to raw logs before remembering I should see what my htaccess says first ::

SetEnvIf Remote_Addr ^20\. bad_range=$0
That means one or more law-abiding robots must live at this address, or I would have proceeded directly to “Require ip”.

:: riffling through logs ::

Oh, it’s the DDG Favicons-Bot. Overall, the whole /8 shows pretty exactly six times as many 403s as 200s--and a whopping total of three robots.txt requests--which does strongly suggest locking the door was the right idea.