Unkown bot visits every hour!

Discussion in 'Site & Server Administration' started by helleborine, Nov 29, 2006.

  1. #1
    What MUST be a bot, a rogue bot, has been hitting my forum once per hour, TO THE SECOND:

    85.25.129.25 - - [29/Nov/2006:16:19:16 -0600] "GET / HTTP/1.0" 200 13032 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.6) Gecko/20060728 Firefox/1.5.0.6"

    85.25.129.25 - - [29/Nov/2006:15:19:16 -0600]
    85.25.129.25 - - [29/Nov/2006:14:19:16 -0600]
    85.25.129.25 - - [29/Nov/2006:13:19:16 -0600]

    See... It comes every hour... to the SECOND. Only checks one page.

    What is this thing up to???
     
    helleborine, Nov 29, 2006 IP
  2. britishguy

    britishguy Prominent Member

    Messages:
    7,949
    Likes Received:
    892
    Best Answers:
    0
    Trophy Points:
    360
    #2
    This is the info

    (Asked whois.ripe.net:43 about 85.25.129.25)

    inetnum: 85.25.129.0 - 85.25.148.255
    descr: SERVER4YOU Dedicated Server Hosting
    descr: http://www.server4you.de
    netname: SERVER4YOU-1
    country: DE
    org: ORG-BSBS1-RIPE
    admin-c: OD376-RIPE
    tech-c: IT1309-RIPE
    rev-srv: ns1.plusserver.de
    rev-srv: ns2.plusserver.de
    status: ASSIGNED PA
    remarks: Abuse-Contact:

    mnt-by: INTERGENIA-MNT
    source: RIPE Filtered
    organisation: ORG-BSBS1-RIPE
    org-name: B S B - Service GmbH
    org-type: NON-REGISTRY
    descr: Internet-Hoster
    remarks: BSB Service GmbH is part of intergenia AG
    address: Daimlerstr.9-11
    address: 50354 Huerth
    address: Germany
    phone: 49 2233 612-0
    fax-no: 49 2233 612-144
    admin-c: OD376-RIPE
    tech-c: IT1309-RIPE
    mnt-ref: INTERGENIA-MNT
    mnt-by: INTERGENIA-MNT
    source: RIPE Filtered
    role: Intergenia Technik
    address: intergenia AG
    address: Daimlerstr. 9-11
    address: 50354 Huerth
    phone: 49 2233 612
    fax-no: 49 2233 612 144
    remarks: trouble: Information Contact

    remarks: trouble: Abuse Contact

    remarks: trouble: for more information http://www.plusserver.de
    admin-c: JO630-RIPE
    admin-c: SW8783-RIPE
    tech-c: JO630-RIPE
    tech-c: SW8783-RIPE
    nic-hdl: IT1309-RIPE
    mnt-by: INTERGENIA-MNT
    source: RIPE Filtered
    abuse-mailbox:

    person: Oliver Drifthaus
    address: Daimlerstr. 9-11
    address: 50354 Huerth
    address: Germany
    phone: 49 2233 612-0
    fax-no: 49 2233 612-144
    nic-hdl: OD376-RIPE
    mnt-by: INTERGENIA-MNT
    source: RIPE Filtered
    route: 85.25.128.0/17
    descr: intergenia AG
    origin: AS13237
    mnt-by: INTERGENIA-MNT
    source: RIPE Filtered
     
    britishguy, Nov 29, 2006 IP
  3. helleborine

    helleborine Well-Known Member

    Messages:
    915
    Likes Received:
    70
    Best Answers:
    0
    Trophy Points:
    120
    #3
    Yes, I checked the whois. I also googled the IP. Nothing suspicious turned up. I think that might be a new one, that's why I posted about it, so that if others notice it, they will know what it's about.
     
    helleborine, Nov 29, 2006 IP
  4. gigapromoters

    gigapromoters Peon

    Messages:
    309
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Might be a customized scrapper or something...

    What type of page its requesting though ?
     
    gigapromoters, Nov 29, 2006 IP
  5. helleborine

    helleborine Well-Known Member

    Messages:
    915
    Likes Received:
    70
    Best Answers:
    0
    Trophy Points:
    120
    #5
    85.25.129.25 - - [29/Nov/2006:16:19:16 -0600] "GET / HTTP/1.0" 200 13032 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.6) Gecko/20060728 Firefox/1.5.0.6"

    The index page, I should guess from the logs. It never goes any deeper.

    Every hour... very weird.
     
    helleborine, Nov 29, 2006 IP
  6. gigapromoters

    gigapromoters Peon

    Messages:
    309
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    0
    #6
    What type of site do you have ?

    There are a lot of scraper sites on internet who are hungry about the content from anywhere. So, you dont need to worry until and unless it becomes a big bandwidth eater.
     
    gigapromoters, Nov 30, 2006 IP
  7. helleborine

    helleborine Well-Known Member

    Messages:
    915
    Likes Received:
    70
    Best Answers:
    0
    Trophy Points:
    120
    #7
    It's a forum. But it doesn't scrape content, it only looks at the first page.

    "GET / HTTP/1.0"

    And there are no other hits, not even for images on the page.
     
    helleborine, Nov 30, 2006 IP
  8. theblight

    theblight Peon

    Messages:
    246
    Likes Received:
    9
    Best Answers:
    0
    Trophy Points:
    0
    #8
    maybe its uptime check of your site...do you have one?
     
    theblight, Dec 1, 2006 IP
    helleborine likes this.
  9. helleborine

    helleborine Well-Known Member

    Messages:
    915
    Likes Received:
    70
    Best Answers:
    0
    Trophy Points:
    120
    #9
    I certainly don't... but my host might! That's the most likely explanation. Thanks!
     
    helleborine, Dec 1, 2006 IP