Forum Moderators: open
Does anybody know what this is? Some kind of spammer or something? We have had legitimate traffic from the same UA but a lot of it is definately questionable.
Any ideas?
Make sure you have a good security system set up on your server(s). This is a common UA used by hackers who try to break into web servers. I don't handle server configs much but try to set up something where these users get flagged and an e-mail is sent to you with their activies. Then just ban their IP's as they continue to come in. There could be some older browsers out there that still use this UA so it wouldn't be wise to ban it outright.
Basically I think this is one of the net accelerator types of application, where you surf normally and it's supposed to download links in the backround to speed up your surfing. For the occasions I see this its almost definately not hackers, though your situation may be different.
HTTP_ACCEPT = text/html, */*
HTTP_CACHE_CONTROL = max-stale=0
HTTP_USER_AGENT = Mozilla/3.01 (compatible;)
HTTP_X_FORWARDED_FOR = 132.79.8.10 -> home of the sloppy guy.
REMOTE_ADDR = 198.26.122.12
REMOTE_PORT = 36374
Name: WCS1-CBUS.NIPR.MIL
Anyway, the utility *always* has
HTTP_ACCEPT = text/html, */*
HTTP_CACHE_CONTROL = max-stale=0