Forum Moderators: open
they again hit me on port 80, they get 301 re-direction codes but they're not following themWere they requesting files they had previously got at https, or new material they’d never seen before?
192.178.6.abc - - [16/Jan/2025:18:39:24 -0800] "GET /robots.txt HTTP/1.1" 200 4136 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
192.178.6.abc - - [16/Jan/2025:18:39:24 -0800] "GET / HTTP/1.1" 403 3009 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
(The 403 is because I block anything claiming to be googlebot that isn't from 66.249.etcetera.) But mark the sequel: 34.116.39.abc - - [17/Jan/2025:02:10:47 -0800] "HEAD / HTTP/1.1" 403 282 "http://example.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 AppEngine-Google; (+http://code.google.com/appengine; appid: s~virustotalcloud)"
3.131.151.abc - - [17/Jan/2025:02:10:47 -0800] "GET / HTTP/1.1" 403 2965 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.51"
3.145.101.abc - - [17/Jan/2025:02:10:47 -0800] "GET / HTTP/1.1" 403 2965 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.51"
192.178.6.abc - - [17/Jan/2025:02:10:47 -0800] "GET / HTTP/1.1" 403 3009 "-" "GoogleOther"
34.116.39.abc - - [17/Jan/2025:02:10:48 -0800] "GET / HTTP/1.1" 403 3009 "http://example.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 AppEngine-Google; (+http://code.google.com/appengine; appid: s~virustotalcloud)"
GoogleOther? wtf? I include the surrounding lines because this is a low-traffic site, so it's very unlikely to see two wholly unrelated requests within the same second. Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GoogleOther) Chrome/122.0.6261.94 Safari/537.36from assorted IPs in the 66.249.64-70 range. All blocked due to header deficits.