|
Posted by JPR on February 24, 2007, 9:39 am
Please log in for more thread options
we are seeing some wierd hits originating from microsoft ip addresses and
using strange live.com referers, such as "upskirt" and "boobs". no, these
terms are not present on any of our pages. we aren't 12, and we aren't
running pr0n sites. :)
originating ip addresses are: 131.107.0.95 and 131.107.0.96. these are
within one of microft's assignments:
CIDR: 131.107.0.0/16
NetName: MICROSOFT
(this ip range is NOT the same range that originates the "regular" msn/live
crawler activity.)
and their respective host names resolve to tide525.microsoft.com and
tide526.microsoft.com. in no instance has either requested a robots.txt
file.
we've seen this on two different domains (so far)... relevent portions of
their server logs (referer and user agent):
"http://search.live.com/result.aspx?q=upskirt&mrt=en-us&FORM=LVSP"
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; WOW64; SV1; .NET CLR
2.0.50727)"
"http://search.live.com/result.aspx?q=boobs&mrt=en-us&FORM=LVSP"
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; WOW64; SV1)"
"http://search.live.com/result.aspx?q=fluoxetine&mrt=en-us&FORM=LVSP"
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; WOW64; SV1; .NET CLR
2.0.50727)"
"http://search.live.com/result.aspx?q=fluoxetine&mrt=en-us&FORM=LVSP"
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; WOW64; SV1; .NET CLR
2.0.50727)"
anyone have a clue what this stuff is?!?! are these just a stupid attempt
at referer spamming on microsoft's part?
|