Strange Log Activity

Discussion in 'Site & Server Administration' started by nevetS, Sep 2, 2005.

  1. #1
    Somebody is creating some strange log activity and I'm having trouble figuring out why.
    
    216.40.34.229 www.bkweddings.com - [01/Sep/2005:23:25:47 -0700] "HEAD /wedding-s
    ongs/index.xml HTTP/1.1" 200 - "-" "-" "-"
    [php]
    
    I'm seeing groups of 6 HEAD requests followed by 2 GET requests for the same file - all with the same timestamp except for the second GET request which occurs one second later.
    
    It's hapenning very frequently - and intermittently.  It'll happen every 6 or so minutes for a period, then it will hold off for a few hours, then it comes back again.
    
    It's happening on several files - but all of them are rss feeds.  I don't want to ban an aggregator like syndic8 or feedster, and HEAD requests are pretty light anyways, but this level of activity is strangley high and all coming from the same IP.  It doesn't identify itself as a spider and magpie type aggregators usually identify themselves.  Why take 6 HEAD requests anyways?  It just doesn't make sense.
    
    The IP resolves to TUCOWS.COM, but they do virtual hosting so it could be anyone.
    PHP:

     
    nevetS, Sep 2, 2005 IP
  2. woodside

    woodside Peon

    Messages:
    182
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #2
    How did you determine the ip resolves to tuwcows.com? I see this:

    host 216.40.34.229
    229.34.40.216.in-addr.arpa domain name pointer fc-e1.feedcache.net.
     
    woodside, Sep 2, 2005 IP
  3. nevetS

    nevetS Evolving Dragon

    Messages:
    2,544
    Likes Received:
    211
    Best Answers:
    0
    Trophy Points:
    135
    #3
    d'oh! Lack of sleep. I did a whois lookup on the IP rather than a reverse dns lookup.

    I decided to ban the IP since their activity doesn't make any sense, they don't have a web site, and they visit way too frequently for a bot.
     
    nevetS, Sep 2, 2005 IP
  4. woodside

    woodside Peon

    Messages:
    182
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    0
    #4
    It happens to the best of us. :)
     
    woodside, Sep 2, 2005 IP