HTML Logo by World Wide Web Consortium (www.w3.org). Click to learn more about our commitment to accessibility and standards.

Moving forward with Composr

ocPortal has been relaunched as Composr CMS, which is now in beta. ocPortal 9 will be superseded by Composr 10.

Head over to compo.sr for our new site, and to our migration roadmap. Existing ocPortal member accounts have been mirrored.


Heads-up about a rouge bot - intelium_bot

Login / Search

 [ Join | More ]
 Add topic 
Posted
Item has a rating of 5 (Liked by BobSLiked by FletchLiked by JeanLiked by sholzy)  
Rating:
#86447 (In Topic #17673)
Avatar

Community saint

For those that are interested, I just got hit by a content scraper bot that totally ignored robots.txt. It targets both your site and the root of your domain, so if you want to IP block it (159.253.145.175) you will need to do so from the root of your domain.

Here are some of entry points it has tried:

   example.com/cms/_top
   example.com/cms/4
   example.com/cms/Usergroups:
   example.com/cms/Members:
   example.com/cms/Forums:
   example.com/cms/Polls:
   example.com/cms/Music:
   example.com/cms/Gallery:
   example.com/cms/Miscellaneous:
   example.com/cms/Blogs:
   example.com/cms/Episodes:
   example.com/cms/site/site_contact
   example.com/cms/site/site_privacy
   example.com/cms/site/3
   example.com/cms/site/0
   example.com/cms/site/1
   example.com/cms/site/g
   example.com/cms/site/4
   example.com/cms/site/Polls:
   example.com/cms/site/Music:
   example.com/cms/site/Gallery:
   example.com/cms/site/Miscellaneous:
   example.com/cms/site/Blogs:
   example.com/cms/site/Episodes:
   example.com/cms/site/Usergroups:
   example.com/cms/site/Members:
   example.com/cms/site/Rules:
   example.com/cms/site/Forums:
   example.com/cms/site/_self
   example.com/cms/site_contact
   example.com/cms/site_privacy
   example.com/cms/3
   example.com/cms/g
   example.com/cms/1
   example.com/cms/0
   example.com/cms/_self
   example.com/Members:
   example.com/Forums:
   example.com/Polls:
   example.com/Usergroups:
   example.com/Gallery:
   example.com/Music:
   example.com/_self
   example.com/Episodes:
   example.com/Miscellaneous:
   example.com/Blogs:

More info about this bot can be found here: http://riskyinternet.com/what-is/crawler/MTI5NzMwMA==/


Last edit: by temp1024

Do you have a Samsung Galaxy S / Galaxy S II ? If so, why not check out my ScreenFree FM Radio .
Back to the top
 
Posted
Rating:
#86450
Avatar

Community saint

Thanks for the report, temp.

I ran the OcCLE antispam_check on the IP and it came up clean (not listed) but when I checked Project Honey Pot, the IP is reported as a "rule breaker" with a threat rating of 46 first reported 5 months ago and most recently seen in the last week. It's score would have slipped past my anti-spam settings but I wonder why the antispam_check command shows it as unlisted.

Code

XXXXXXXXXXXX.httpbl.org: Unlisted or error
 *.opm.tornevall.org: Unlisted or error
Stop Forum Spam: Responded as unlisted

I've blocked the IP in CloudFlare which should keep it from hitting my site.

Bob

EDIT: Ahh, no suspicious activity in the past three months so it is unreported I guess.
https://www.projecthoneypot.org/ip_159.253.145.175
Back to the top
 
Posted
Rating:
#86451
Avatar

Community saint

BobS said

I wonder why the antispam_check command shows it as unlisted.
Probably because its a minor bot and not wide spread.

Do you have a Samsung Galaxy S / Galaxy S II ? If so, why not check out my ScreenFree FM Radio .
Back to the top
 
Posted
Rating:
#86455
Avatar

Community saint

If you have access to the servers blacklist place it there. Thanks for reporting :)


http://digiflash.nl Photo community  (dutch)
Back to the top
 
Posted
Rating:
#86463
Avatar

Honoured member

thanks for this…i very rarely look at this sort of thing on my site, but funnily enough i did spot it and was wondering what it was.

Thanks Temp
Back to the top
 
1 guests and 0 members have just viewed this: None
Control functions:

Quick reply   Contract

Your name:
Your message: