osCommerce and osCMax shopping cart software forums

Shopping Cart Software

osCommerce with teeth!

 
 

65.54.164.106, A Spider? possible hack attempt?

This is a discussion on 65.54.164.106, A Spider? possible hack attempt? within the osCMax v1.7 Discussion forums, part of the osCMax v1.7 Forums category; Do any of yall know if this is a spider? Ip address 65.54.164.106 I keep seeing this ip in the ...


Go Back   osCommerce and osCMax shopping cart software forums > osCMax v1.7 Forums > osCMax v1.7 Discussion

Register FAQ Members List Calendar Mark Forums Read


Free community membership! Fast easy FREE membership
Closed Thread

 

LinkBack Thread Tools
  #1  
Old 06-14-2004, 09:56 AM
Active Member
 
Join Date: May 2004
Location: worcester ma
Posts: 162
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
fridgemags
Default 65.54.164.106, A Spider? possible hack attempt?

Do any of yall know if this is a spider? Ip address 65.54.164.106

I keep seeing this ip in the whos online tool and it starts multiple sessions and sometimes put like Ten items in the shopping cart and at the same time has like two more sessions started.

I have put a robots.txt file in my root html directory to keep spiders out of certain files and have the setting in admin to kill spider sessions set to true.

This ip keeps coming into my site and starting multiple sessions and adding items to the shopping cart.

I did a whois check and tracked it down to microsoft so thought it would be a msnbot?

Here are the results of my whois:

OrgName: Microsoft Corp
OrgID: MSFT
Address: One Microsoft Way
City: Redmond
StateProv: WA
PostalCode: 98052
Country: US

NetRange: 65.52.0.0 - 65.55.255.255
CIDR: 65.52.0.0/14
NetName: MICROSOFT-1BLK
NetHandle: NET-65-52-0-0-1
Parent: NET-65-0-0-0-0
NetType: Direct Assignment
NameServer: DNS1.CP.MSFT.NET
NameServer: DNS2.CP.MSFT.NET
NameServer: DNS1.TK.MSFT.NET
NameServer: DNS1.DC.MSFT.NET
NameServer: DNS1.SJ.MSFT.NET
Comment:
RegDate: 2001-02-14
Updated: 2002-12-05

TechHandle: ZM23-ARIN
TechName: Microsoft Corporation
TechPhone: +1-425-882-8080
TechEmail: noc@microsoft.com

OrgAbuseHandle: HOTMA-ARIN
OrgAbuseName: Hotmail Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@hotmail.com

OrgAbuseHandle: MSNAB-ARIN
OrgAbuseName: MSN ABUSE
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@msn.com

OrgAbuseHandle: ABUSE231-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-425-882-8080
OrgAbuseEmail: abuse@microsoft.com

OrgNOCHandle: ZM23-ARIN
OrgNOCName: Microsoft Corporation
OrgNOCPhone: +1-425-882-8080
OrgNOCEmail: noc@microsoft.com

OrgTechHandle: MSFTP-ARIN
OrgTechName: MSFT-POC
OrgTechPhone: +1-425-882-8080
OrgTechEmail: iprrms@microsoft.com

# ARIN WHOIS database, last updated 2004-06-13 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.

Any ideas on if this is a spider and if so how do i stop them from starting sessions and adding items to the shopping cart?

Thanx for any info.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
  #2  
Old 06-17-2004, 11:57 AM
CMWM's Avatar
Member
 
Join Date: Mar 2004
Posts: 35
Thanks: 2
Thanked 0 Times in 0 Posts
Rep Power: 0
CMWM
Default

I have the same issue but with a different IP. I would love to see an answer

John
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3  
Old 06-18-2004, 07:39 AM
michael_s's Avatar
osCMax Developer

 
Join Date: Jul 2002
Location: Phoenix, AZ
Posts: 10,990
Thanks: 80
Thanked 345 Times in 324 Posts
Rep Power: 10
michael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond reputemichael_s has a reputation beyond repute
Default

Reverse dns for that ip gives: msnbot64106.search.msn.com

So yes, it is a crawler. If it is generating sessions on your site, you should either block the bot from your site, or better, switch to forcing cookie usage for sessions. This is done in the sessions section of the administration. That will remove all session id's from your url and solve the problem. Of course, you cannot use Force cookies if you are using shared ssl.
__________________
Michael Sasek
osCMax Developer


  • osCMax Templates - Hundreds of premium quality templates designed for osCMax 2. Loyalty discounts up to 30% off!
    Each purchase supports the osCMax project with much needed funds!

  • xShop for osCMax - Windows Based osCMax administration. Improved workflow, security, speed and convenience.

  • osCMax Hosting - From basic hosting to High Availability, Load Balanced arrays, the most experienced osCMax host. Default multi server configuration for exceptional performance!

  • osCMax Template Tutorial - Learn how to make your own custom templates and how to use the powerful features of the osCMax template system.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Sponsored Links
Advertisement
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
Image size hack for product pages brendanl79 osCMax v2 Customization/Mods 10 06-15-2007 02:37 PM
Spider Sessions Studio143 osCMax v1.7 Discussion 1 05-14-2005 02:21 PM
Spider Safe URLs? operadivamommy osCMax v1.7 Discussion 0 09-10-2004 10:04 AM
Need help with a simple product listing hack... Nocturnaloner osCommerce 2.2 Modification Help 2 06-04-2004 10:14 AM


All times are GMT -8. The time now is 03:58 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO
http://www.oscmax.com/forums/
Copyright 2008 osCMax