LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-04-2015, 07:49 PM   #1
halfpower
Member
 
Registered: Jul 2005
Distribution: Slackware
Posts: 241

Rep: Reputation: 31
Question Robot keeps making suspicious page requests


I have a web page that receives up to, at least, 130 GET requests per day from a robot. It's using different IP addresses. The robot is also sending user agent strings typical of a legit web surfer. The page is static, and there seems to be no room for injection attacks. It's also not enough traffic for a DOS attack. Any idea what this robot might be doing?
 
Old 06-05-2015, 03:41 AM   #2
ugjka
Member
 
Registered: May 2015
Location: Latvia
Distribution: Arch, Centos
Posts: 368
Blog Entries: 5

Rep: Reputation: 264Reputation: 264Reputation: 264
Quote:
Originally Posted by halfpower View Post
I have a web page that receives up to, at least, 130 GET requests per day from a robot. It's using different IP addresses. The robot is also sending user agent strings typical of a legit web surfer. The page is static, and there seems to be no room for injection attacks. It's also not enough traffic for a DOS attack. Any idea what this robot might be doing?
It could be Scraping, Trying to register to spam, Trying to exploit security holes.

I'm running a forum and 99% of robots try to register to spam the board.
 
Old 06-05-2015, 08:37 AM   #3
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
How can you identify it's a robot? If you can do that then you should be able to write a fail2ban recipe to ban the IP address when you see the suspicious activity.

More worrying are robots making POST requests as they are the ones that are usually trying to automagically register.
 
Old 06-05-2015, 10:48 AM   #4
joec@home
Member
 
Registered: Sep 2009
Location: Galveston Tx
Posts: 291

Rep: Reputation: 70
Have you checked the whois of the IP address of the bot to ensure it is not a legitimate web crawler from a search engine such as Google?
 
Old 06-05-2015, 11:33 AM   #5
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
Check referer log to see if there is a link to your site.
 
Old 06-08-2015, 01:32 PM   #6
halfpower
Member
 
Registered: Jul 2005
Distribution: Slackware
Posts: 241

Original Poster
Rep: Reputation: 31
All of the IP addresses point back to the same web hosting company. The access logs contain no referrer. I would think if it were a legit web crawler, then it would properly identify itself rather than masquerading with different user-agent strings. It is not yet too threatening, but it is strange. Requests are spaced, on average, 15 minutes apart. In some cases, my access logs have shown two practically simultaneous page requests from two slightly different IP addresses.

Last edited by halfpower; 06-08-2015 at 01:36 PM.
 
Old 06-08-2015, 02:27 PM   #7
joec@home
Member
 
Registered: Sep 2009
Location: Galveston Tx
Posts: 291

Rep: Reputation: 70
You might want to send a report to the abuse department of that web hosting company, they might have been infected with a botnet. No need to make accusations, just give a sample of the logs you are seeing and explain the traffic looks suspicious, let them handle it from there.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Suspicious requests in haproxy log. Need to block. Help? jc_oo12 Linux - Security 2 04-14-2011 08:10 AM
Apache2, how to restrict number of page requests from any ip to 1000 TefoZi Linux - Newbie 3 09-03-2007 01:47 PM
Allow page requests from a given server txtoolman Linux - Software 5 06-21-2006 08:55 PM
Why is Firefox sending DNS requests when no page is loaded ? carcassonne Linux - Networking 5 04-23-2006 04:39 PM
forward all dns requests to one page Moszer Linux - Networking 4 05-25-2004 01:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration