Is this a legit Googlebot or a Spoof?

Discussion in 'Security' started by amanamission, Sep 25, 2007.

  1. #1
    I have been getting an awful lot of ill-mannered spambot type IPs and I'm getting tried of banning them. This one looks fishy, but the IP resolves to Mountain View.

    ff-in-f84.google.com 66.249.85.84

    WTF?

    Anybody know FOR SURE wheteher this is a legit bot or something ugly?
     
    amanamission, Sep 25, 2007 IP
  2. Roido

    Roido Active Member

    Messages:
    273
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    60
    #2
    Roido, Sep 26, 2007 IP
  3. amanamission

    amanamission Notable Member

    Messages:
    1,936
    Likes Received:
    138
    Best Answers:
    0
    Trophy Points:
    210
    #3
    I guess I'm glad I didn't block it...I wonder what it's for? Not a typical Googlebot.
    There's no way that that DNS info could be faked, I guess?
     
    amanamission, Sep 26, 2007 IP
  4. Ladadadada

    Ladadadada Peon

    Messages:
    382
    Likes Received:
    36
    Best Answers:
    0
    Trophy Points:
    0
    #4
    The UserAgent will usually tell you plenty about whichever GoogleBot you have. Also, plugging the UserAgent into Google's search engine will find you more information than you could possibly want to know about it :)
     
    Ladadadada, Oct 5, 2007 IP
  5. amanamission

    amanamission Notable Member

    Messages:
    1,936
    Likes Received:
    138
    Best Answers:
    0
    Trophy Points:
    210
    #5
    I did that and didn't find anything conclusive, which is why I thought it was odd...only about 400 listings, all from server logs. Usually I look to see if someone else banned the IP.
     
    amanamission, Oct 5, 2007 IP
  6. redolive

    redolive Peon

    Messages:
    1
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Somone is running a keyword lookup of your site with Googles keyword generator tool. This bot is used by google to scan you site for keywords for use in an adwords campaign. Try it out yourself by entering your web address and then watch your logs, visit the adwords keyword generator tool https://adwords.google.com/select/KeywordToolExternal

    Typically it is competitors who are trying to get ideas for keywords by using your site as a guide.
     
    redolive, Oct 24, 2008 IP
  7. jayshah

    jayshah Peon

    Messages:
    1,126
    Likes Received:
    68
    Best Answers:
    1
    Trophy Points:
    0
    #7
    This (reverse) DNS ...
    66.249.85.84 resolves to ff-in-f84.google.com
    Code (markup):
    ... can easily be faked. But, this can't:
    
    OrgName:    Google Inc. 
    OrgID:      GOGL
    Address:    1600 Amphitheatre Parkway
    City:       Mountain View
    StateProv:  CA
    PostalCode: 94043
    Country:    US
    
    NetRange:   66.249.64.0 - 66.249.95.255 
    CIDR:       66.249.64.0/19 
    NetName:    GOOGLE
    NetHandle:  NET-66-249-64-0-1
    Parent:     NET-66-0-0-0-0
    NetType:    Direct Allocation
    Code (markup):
    Jay
     
    jayshah, Oct 25, 2008 IP
  8. awesometbn

    awesometbn Peon

    Messages:
    268
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #8
    Hello amanamission,
    You may already know about these resources, but you can investigate anything suspicious you see in your server logs with arin.net, dnsstuff.com, and domaintools.com. There are plenty of other things you can do, for example from the command line with nslookup and whois.
     
    awesometbn, Oct 26, 2008 IP