ForumPostersUnion.com


   

Go Back   Forum Posters Union > Search Engine Intelligence & Research > Spiders, Crawlers and web robots
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Spiders, Crawlers and web robots Intelligence on search engine spider bots and identification, bad bots from spam botnets, content scrapers, tools to identify web robots, blocking malicious bots.

Reply
 
Thread Tools
  #1  
Old 12-11-2010, 10:01 AM
Lee G Lee G is offline
Super Member
 
Join Date: Dec 2010
Location: Catral, Costa Blanca
Posts: 69
PaperLiBot/2.1

Another amazon bot found

PaperLiBot/2.1

If you want to make it easier to kill and run a vb forum
Add the following code to your spiders file includes > xml > spiders_vbulletin

Code

PHP Code:
        <spider ident="PaperLiBot/2.1">
        <
name>PaperLiBot</name>
    </
spider
NetRange 184.72.0.0 - 184.73.255.255
CIDR 184.72.0.0/15

Name AMAZON-EC2-7
Handle NET-184-72-0-0-1
Parent NET184 (NET-184-0-0-0-0)
Net Type Direct Assignment
Origin AS
Nameservers PDNS3.ULTRADNS.ORG
PDNS2.ULTRADNS.NET
PDNS1.ULTRADNS.NET
Organization Amazon.com, Inc. (AMAZO-4)
Registration Date 2010-01-26
Last Updated 2010-05-28
Comments The activity you have detected originates from a
dynamic hosting environment.
For fastest response, please submit abuse reports at
http://aws-portal.amazon.com/gp/aws/...actus/AWSAbuse
For more information regarding EC2 see:
http://ec2.amazonaws.com/
All reports MUST include:
* src IP
* dest IP (your IP)
* dest port
* Accurate date/timestamp and timezone of activity
* Intensity/frequency (short log extracts)
* Your contact details (phone and email)
Without these we will be unable to identify
the correct owner of the IP address at that
point in time.

RESTful Link http://whois.arin.net/rest/net/NET-184-72-0-0-1
Reply With Quote
  #2  
Old 12-11-2010, 10:16 AM
AnthonyCea's Avatar
AnthonyCea AnthonyCea is offline
Publisher
 
Join Date: Feb 2006
Posts: 31,664
What do you mean by

Quote:
kill and run a vb forum
You mean kill this particular spider ?
Reply With Quote
  #3  
Old 12-11-2010, 10:37 AM
Lee G Lee G is offline
Super Member
 
Join Date: Dec 2010
Location: Catral, Costa Blanca
Posts: 69
Depends how good you are at running forums
Teach me to be up until 3am, followed by a full day, redoing my htaccess and monitoring traffic , The beer tonight will be well earned

Seems my forum is open season for idiots at the moment
I say idiots, some can be spotted a mile away by adding their user agents to the spider list

Artabus and deepnet explorer for open proxies
Wordpress for content thieves

You can see what I mean by looking at my forum, link in my profile
Reply With Quote
  #4  
Old 12-11-2010, 11:02 AM
AnthonyCea's Avatar
AnthonyCea AnthonyCea is offline
Publisher
 
Join Date: Feb 2006
Posts: 31,664
Well my friend, you will constantly be under attack by Xrumer low life's, hackers, RFI bots and so on, this will never end, so welcome to the life of forum administration.

PS: A lot of webmasters and forum admin's don't even care, that is how they get by, they just let scum attack them constantly.
Reply With Quote
  #5  
Old 12-11-2010, 11:10 AM
Lee G Lee G is offline
Super Member
 
Join Date: Dec 2010
Location: Catral, Costa Blanca
Posts: 69
I was hacked with a base 64 code injection back in April
Since then my traffic has never came back to what it was
One of the reasons I had these code jockeys so much.
Until then, I had a good beer token maker, plus all software and server costs covered.

I have been a regular user of these forums for a while.
So its only fair to repay all your hard work here
Reply With Quote
  #6  
Old 12-11-2010, 11:51 AM
AnthonyCea's Avatar
AnthonyCea AnthonyCea is offline
Publisher
 
Join Date: Feb 2006
Posts: 31,664
If you have the technical skills to run a sophisticated software firewall you can stop a lot of attacks before they hit the applications running on your server, you will be much better off than banning on the domain level by filtering out malicious IP's this way.

The problem with this is you need to be a great server administrator to understand the complexity of such a firewall, the man that invented the script linked to runs a web hosting data center, so he has a huge advantage over the average forum administrator or webmaster when it comes to stopping spam botnets and hackers.
Reply With Quote
  #7  
Old 10-11-2011, 11:22 PM
AnthonyCea's Avatar
AnthonyCea AnthonyCea is offline
Publisher
 
Join Date: Feb 2006
Posts: 31,664
11:07 PM Guest Viewing Thread
50.19.129.185
Mozilla/5.0 (compatible; PaperLiBot/2.1; http://support.paper.li/entries/2002...at-is-paper-li)


ec2-50-19-129-185.compute-1.amazonaws.com
Reply With Quote
  #8  
Old 12-13-2011, 08:39 PM
AnthonyCea's Avatar
AnthonyCea AnthonyCea is offline
Publisher
 
Join Date: Feb 2006
Posts: 31,664
08:35 PM Guest Viewing Thread
50.19.207.65
Mozilla/5.0 (compatible; PaperLiBot/2.1; http://support.paper.li/entries/2002...at-is-paper-li)


ec2-50-19-207-65.compute-1.amazonaws.com
Reply With Quote
  #9  
Old 06-05-2012, 05:31 AM
Lee G Lee G is offline
Super Member
 
Join Date: Dec 2010
Location: Catral, Costa Blanca
Posts: 69
These guys are now operating out of two ip ranges on the French OVH servers. Looks like they are changing from the Amazon cloud

37.59.18.# ip range and 37.59.16.#

NetRange: 37.0.0.0 - 37.255.255.255
CIDR: 37.0.0.0/8
OriginAS:
NetName: RIPE-37
NetHandle: NET-37-0-0-0-1
Parent:
NetType: Allocated to RIPE NCC
Comment: These addresses have been further assigned to users in
Comment: the RIPE NCC region. Contact information can be found in
Comment: the RIPE database at http://www.ripe.net/whois
RegDate: 2010-11-30
Updated: 2011-01-17
Ref: http://whois.arin.net/rest/net/NET-37-0-0-0-1

OrgName: RIPE Network Coordination Centre
OrgId: RIPE
Address: P.O. Box 10096
City: Amsterdam
StateProv:
PostalCode: 1001EB
Country: NL
RegDate:
Updated: 2011-09-24
Ref: http://whois.arin.net/rest/org/RIPE

ReferralServer: whois://whois.ripe.net:43

OrgTechHandle: RNO29-ARIN
OrgTechName: RIPE NCC Operations
OrgTechPhone: +31 20 535 4444
OrgTechEmail:
OrgTechRef: http://whois.arin.net/rest/poc/RNO29-ARIN

OrgAbuseHandle: RNO29-ARIN
OrgAbuseName: RIPE NCC Operations
OrgAbusePhone: +31 20 535 4444
OrgAbuseEmail:
OrgAbuseRef: http://whois.arin.net/rest/poc/RNO29-ARIN

== Additional Information From whois://whois.ripe.net:43 ==

inetnum: 37.59.0.0 - 37.59.63.255
netname: OVH
descr: OVH SAS
descr: Dedicated servers
descr: http://www.ovh.com
country: FR
admin-c: OK217-RIPE
tech-c: OTC2-RIPE
status: ASSIGNED PA
mnt-by: OVH-MNT
source: RIPE # Filtered

role: OVH Technical Contact
address: OVH SAS
address: 2 rue Kellermann
address: 59100 Roubaix
address: France
admin-c: OK217-RIPE
tech-c: GM84-RIPE
nic-hdl: OTC2-RIPE
abuse-mailbox:
mnt-by: OVH-MNT
source: RIPE # Filtered

person: Octave Klaba
address: OVH SAS
address: 2 rue Kellermann
address: 59100 Roubaix
address: France
phone: +33 9 74 53 13 23
nic-hdl: OK217-RIPE
abuse-mailbox:
mnt-by: OVH-MNT
source: RIPE # Filtered

route: 37.59.0.0/16
descr: OVH ISP
descr: Paris, France
origin: AS16276
mnt-by: OVH-MNT
source: RIPE # Filtered
Reply With Quote
Reply



Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 02:35 PM.


Powered by vBulletin®
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
2006-2011 ForumPostersUnion.com