Forum Moderators: open
My server is now handing out a "I think you're a bot" page when any requests come in that match that exact UA.Your server’s judgement is probably right. The last human I find with this exact UA is from early October; since then it’s been nothing but robots. Some requesting pages alone, some images alone, and a striking red flag with
POST /test.hello?%ADd+cgi.force_redirect%3d0+%ADd+cgi.redirect_status_env+%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://inputI don’t have enough pdfs to make anything statistically meaningful, but it is worth noting that the robots get either pages or images, never anything else. @lucy24, are you seeing these also from Windstream IP's, and also a HEAD then GET?No, I think there's more than one botrunner using this UA. (fwiw: At any given time, I have around half a dozen UAs flagged-and-blocked as “botnet_agent”--outdated but not absurdly antiquated humanoids--and then after some months they stop.) Conversely, on rare occasions I do see the HEAD+GET sequence--which is enough to mark a robot, because what human browser uses HEAD?--but not from this specific UA.
In my logs I see a small amount of GET's (usually from googlebot, maybe also bing) where the bytes transfered was zero and the code is 304.Yup. Those are static files when the request was