LGF

more options

  

Advertisement

  

Link address:
Link title:
Description: 
Remaining:

Suspicious Robot Sighting

Tue, Jun 3, 2008 at 9:16:42 am PDT

A web crawler using the IP address 66.165.190.122 has been hitting us like crazy for the past couple of hours, violating the rules in our robots.txt file and crawling through LGF as quickly as possible.

When I checked the access log, I discovered something that makes me a bit suspicious; all of the referring pages for this bot were from “right-wing” sites, and specifically from a limited group of anti-jihad sites including My Pet Jawa, Jihad Watch, and several others. Apparently someone is making an index of those sites for some unknown reason.

I blocked the IP in our htaccess file, and I suggest that if you run a blog you do the same.

78 comments

  • Comments are open and unmoderated, and do not necessarily reflect the views of Little Green Footballs.
  • Obscene, abusive, silly, or annoying remarks may be deleted, but the fact that particular comments remain on the site in no way constitutes an endorsement of their views by Little Green Footballs.
  • Posts that contain phone numbers, street addresses, email addresses or other personal information will also be deleted, as will posts that consist only of a variation on the word, "First!"
  • Comments that advocate violence will be cause for immediate banning with no appeal.
  • REMEMBER: posting comments at LGF is a privilege, not a right. Abuse that privilege, and your account will be blocked.

Hide comments | Jump to bottom

1 Ward Cleaver  6/03/08 9:19:03 am reply quote

Bad robot! Naughty robot!

(pours water on robot, shorting it out)

2 jcm  6/03/08 9:19:52 am reply quote

Don't trust the shover robot!

3 Ward Cleaver  6/03/08 9:20:09 am reply quote

Grad students at Carnegie-Mellon?

4 Kosh's Shadow  6/03/08 9:20:13 am reply quote

This is owned by "terranap data centers"
Who is terranap data centers? No address or even country given in whois.
Strange for something that calls itself "data centers"

5 vxbush  6/03/08 9:22:01 am reply quote

re: #4 Kosh's Shadow

This is owned by "terranap data centers"
Who is terranap data centers? No address or even country given in whois.
Strange for something that calls itself "data centers"

Maybe these guys?

6 jimzinsocal  6/03/08 9:22:04 am reply quote

Great timing. I have the afternoon off so I can investigate this one
as I look at my server logs. Ill see what SANS has as well and thanks for the ip info.

7 pat  6/03/08 9:22:14 am reply quote

Ms Yano, Welcome back.

8 experiencedtraveller  6/03/08 9:22:41 am reply quote

Dear hostile forces,
Remember we can kick your ass without any computers.
Sincerely,
USA

9 vxbush  6/03/08 9:22:58 am reply quote

re: #5 vxbush

Maybe these guys?

See page 18 of my link to see it listed.

10 stevieray  6/03/08 9:23:14 am reply quote

Dark web?

11 Sharmuta  6/03/08 9:25:19 am reply quote

re: #5 vxbush

Maybe these guys?

Here's their website: Terremark Worldwide, Inc.

12 BuddyG  6/03/08 9:25:31 am reply quote

Domo arigato, Mr. Roboto

13 allah this  6/03/08 9:25:47 am reply quote

Smells like jihadi spider bots. Release the Zionist nanohornets!

14 zmdavid  6/03/08 9:26:02 am reply quote

re: #4 Kosh's Shadow

This is owned by "terranap data centers"
Who is terranap data centers? No address or even country given in whois.
Strange for something that calls itself "data centers"


That's what I get, too.
[Link: tools.whois.net...]

It looks like they're in FL.
[Link: www.prnewswire.com...]

15 jimzinsocal[deleted]  6/03/08 9:26:13 am
16 Creeping Eruption  6/03/08 9:26:44 am reply quote

For the technologically challenged (me), can you please translate.

17 The Other Les  6/03/08 9:27:04 am reply quote

Finally, robotic beings rule the world!

18 vxbush  6/03/08 9:27:31 am reply quote

re: #11 Sharmuta

Here's their website: Terremark Worldwide, Inc.

Right; Note that they say under the link "NAP of the Capital region" that a new datacenter is going online on the east coast this month.

19 buzzsawmonkey  6/03/08 9:28:23 am reply quote

"Terrenap?"

As in "dirt nap?"

As in "death?"

20 BuddyG  6/03/08 9:29:17 am reply quote

re: #16 Creeping Eruption

[Link: en.wikipedia.org...]

21 neverquit  6/03/08 9:29:40 am reply quote

"all your data centers are belong to us"

22 Shug  6/03/08 9:31:48 am reply quote

Right wing robots huh ? .....

Rove, you robotic bastard

23 Creeping Eruption  6/03/08 9:32:13 am reply quote

re: #20 BuddyG

Thanks. So they are not inherently malicious, but can be used for nefarious purposes or just to clog up a website?

24 not neo just conservative  6/03/08 9:32:32 am reply quote

I'm not sure, but I think this is an Internet Cafe just East of Dulles.
[Link: www.ip-adress.com...]

25 Watcher Man  6/03/08 9:34:08 am reply quote

Yup that comes back to the Nap of the Americas in Miami from the looks of it.

That is the major gateway to South America run by Terramark.

26 taxfreekiller  6/03/08 9:34:26 am reply quote

Hi, George,

Your short, ugly and backing a looser, gonna cost you a bundle,
and all's your going to get is he will go back to the crazy church.

Yours true,
taxfreekiller

27 Occasional Reader  6/03/08 9:35:43 am reply quote
Suspicious Robot Sighting

These aren't the 'droids you're looking for.


/SOMEBODY had to say it

28 Ward Cleaver  6/03/08 9:35:43 am reply quote

re: #11 Sharmuta

Here's their website: Terremark Worldwide, Inc.

Terror proof!

Building Features

Specifically designed and built as a carrier-grade Federal data communications and hosting facility offering the ultimate in physical security

10 ft. earth berm surrounding the entire campus with 150 ft. building set backs

Compliant fencing, video monitoring, and electronic passage technology

Roving perimeter security guards and operating building security guards
DoD-trained anti-terrorism personnel on staff

Rapid Response Security Force

Tiered Access Control Protocols compliant and flexible to conform to all levels of established threat conditions

Primary entrance processing point outside the protected berm
Isolated shipping/receiving and freight inspection facility (X-ray, etc.)

No vehicle traffic in the vicinity of data operating buildings

Parking for 250 vehicles in three (3) separate areas allows for segregation and isolation

29 Egfrow  6/03/08 9:35:45 am reply quote

The primary contact for this website is William Williams?

30 BuddyG  6/03/08 9:36:29 am reply quote

re: #23 Creeping Eruption

Like Charles said it's suspicious since all of the referring pages for the
bot were from “right-wing” sites. An agenda driven inventory.

31 Watcher Man  6/03/08 9:36:57 am reply quote

re: #19 buzzsawmonkey

Nope as in NAP where all the backbone providers peer at.

This is top level tier backbone stuff.

32 RedSoxNation  6/03/08 9:37:00 am reply quote

My wife wants to start a blog. Can anyone recommend some websites that will help her through this process? Thanks in advance for any help...

33 song_and_dance_man[deleted]  6/03/08 9:39:44 am
34 Watcher Man  6/03/08 9:40:11 am reply quote

re: #28 Ward Cleaver

Thats the new NAP they are just getting ready to open up in Va near DC not the Miami one the ip goes back to.

35 DoubleU  6/03/08 9:41:07 am reply quote

Charles, That is a "Miami" address, I think a Bell South, and that could be anywhere from Miami North to North of West Palm Beach. When I had Bell South I even picked up an Atlanta IP.

re: #32 RedSoxNation

My wife wants to start a blog. Can anyone recommend some websites that will help her through this process? Thanks in advance for any help...

Yes, check out Little Green Footballs. :)

36 Kosh's Shadow  6/03/08 9:41:58 am reply quote

re: #25 Watcher Man

Yup that comes back to the Nap of the Americas in Miami from the looks of it.

That is the major gateway to South America run by Terramark.

Tell Hugo Chavez to shove off.

37 not neo just conservative  6/03/08 9:42:08 am reply quote

re: #33 song_and_dance_man

Yes, but Who Watches the Watchers?

38 stevieray  6/03/08 9:42:31 am reply quote

re: #25 Watcher Man

Yup that comes back to the Nap of the Americas in Miami from the looks of it.

That is the major gateway to South America run by Terramark.

South America, huh... Chavez doing some digging for his little buddy Ahmadinejad?

39 rusty_armor  6/03/08 9:43:10 am reply quote

re: #33 song_and_dance_man

They're watching you Neo

Follow the white rabbit

40 Watcher Man  6/03/08 9:45:17 am reply quote

There are five Tier-1 network access points in the United States. Only one has been designed and built from the ground up as a carrier-neutral facility offering colocation, managed services and the latest in peering network technology; only one is prepared to serve as the Internet gateway for Latin America; and only one is a premier MiamiNAP Data Center. This is why global carriers, ISPs, other Internet-related businesses, educational institutions, and enterprises have chosen to become customers at the MiamiNAP.

The MiamiNAP is backed by a consortium of over 100 major carriers , ISPs and other telecom companies. It is located in an area of numerous telecommunications carrier facilities, fiber loops, international cable landings and multiple power grids.

The MiamiNAP is the next-generation in carrier-class facility, utilizing the most advanced networking standards in the world. The network architecture of the MiamiNAP boasts at its core, an efficient high-speed parallel cross point switch fabric. This fabric has a capacity of up to 178,000,000 packets per second of throughput. In addition, edge switches provide gigabit speed connectivity to the meshed 128 Gbps core chassis peering fabric.

41 really grumpy big dog Johnson  6/03/08 9:48:31 am reply quote

re: #32 RedSoxNation

My wife wants to start a blog. Can anyone recommend some websites that will help her through this process? Thanks in advance for any help...

Without prior knowledge of the technicalities of running a blog that you personally host, I wouldn't recommend it. A really good solution is a hosted blog website, like blogspot.com. They take care of all that backend stuff for you. And it's free.

42 blutonazi98  6/03/08 9:49:07 am reply quote

TERRENAP DATA CENTERS, INC. TERRENAP-0-19 (NET-66-165-160-0-1)

66.165.160.0 - 66.165.191.255

RAVENWOOD TERRENAP-0-19 (NET-66-165-190-120-1)

66.165.190.120 - 66.165.190.127
this what i get
Ravenwood? what the hell is that? i get nothing from google when i search for both of them together

43 WrathofG-d  6/03/08 9:52:46 am reply quote

Ot: Bad Times To Be A Christian In Gaza
(let's give these people more land and autonomy!)

44 zmdavid  6/03/08 9:53:24 am reply quote

re: #42 blutonazi98

TERRENAP DATA CENTERS, INC. TERRENAP-0-19 (NET-66-165-160-0-1)

66.165.160.0 - 66.165.191.255

RAVENWOOD TERRENAP-0-19 (NET-66-165-190-120-1)

66.165.190.120 - 66.165.190.127
this what i get
Ravenwood? what the hell is that? i get nothing from google when i search for both of them together

I think it has something to do with the Indiana Jones movie.
/

45 Alouette  6/03/08 9:54:37 am reply quote

re: #42 blutonazi98

Ravenwood? what the hell is that?

It's a small side street off Beverly Glen in L. A. Spielberg named a character in the Indiana Jones series after this street.

Some people I know live on this street.

47 not neo just conservative  6/03/08 10:00:05 am reply quote

re: #32 RedSoxNation

My wife uses Xanga. She's been happy with it.

48 experiencedtraveller  6/03/08 10:00:06 am reply quote

re: #43 WrathofG-d

Ot:

49 Egfrow  6/03/08 10:02:35 am reply quote

Having a bot coming from a network like that can be like drinking from a fire hose for the receiving website. This company is not your average network and is probably not cheap to get access to servers or hosting. This is not a budget minded hosting service.

50 RJ_in_Reno  6/03/08 10:13:40 am reply quote

Was not the bad guys in Jericho imployed by a company called Ravenwood?

51 docremulac  6/03/08 10:19:35 am reply quote

I guess you could say the Internet Cold War has already begun. China sure recognizes this and Charles obviously does since he's evidently a prime target. I'm not sure how much time he spends manning the virtual ramparts of this forum but it seems to be part of his daily chores.

I hope the west is ready to go on the offensive if the internet war goes hot. In war, there's no such thing as self defense. Go on the offensive or stay home.

Let me put it this way, take a professional boxer, put him in the ring with some average guy off the street and tell the pro he can only use defensive moves. No punching. Who'll eventually win? It might take a long time, but since the pro's only in defensive mode, the amateur's got nothing but time. If the armature only gets one in ten hits in, eventually the big guy's going down.

52 Carolina Girl  6/03/08 10:30:14 am reply quote

re: #41 really grumpy big dog Johnson

Excellent advice - I found blogspot great for starting out - and one of these days I will actuall go back and do something with my domain name!

53 Lively  6/03/08 10:30:52 am reply quote

Send all your robots to Denver!

54 incanus  6/03/08 10:35:52 am reply quote

Ravenwood is a customer of TerreNAP, insofar as they have IP space assigned from TerreNAP's /19 ... go here, which is a lookup for NET-66-165-190-120-1 which BlutoNazi found. Hint: when you see org or net names in parens, you can do a lookup on that object by prefacing it with a bang (see my lookup link).


CustName: RAVENWOOD
Address: 50 NE 9th St
City: Miami
StateProv: FL
PostalCode: 33132
Country: US
RegDate: 2008-05-15
Updated: 2008-05-15

NetRange: 66.165.190.120 - 66.165.190.127
CIDR: 66.165.190.120/29
OriginAS: AS23148
NetName: TERRENAP-0-19
NetHandle: NET-66-165-190-120-1
Parent: NET-66-165-160-0-1
NetType: Reassigned
Comment:
RegDate: 2008-05-15
Updated: 2008-05-15

I cut out the phone numbers, but this is the org that needs further scrutiny.

55 Just Another Four-letter Word  6/03/08 10:39:05 am reply quote

A /29, eh? Looks like a couple o' servers. Find out who they belong to yet, Charles?

JAFLW

56 Viking6  6/03/08 10:43:57 am reply quote

re: #28 Ward Cleaver

Parking for 250 vehicles in three (3) separate areas allows for segregation and isolation


BHO will certainly not approve of this

57 jokono  6/03/08 11:06:48 am reply quote

Ravenwood... Ha! Did anyone here watch the short-lived TV series Jericho? Ravenwood was a defense contractor (ala Black Water) that ravaged the remaining cities after the US was sustained a nuclear assault.

(Jericho was a great show, and was probably cancelled (IMO) due to the fact that it showed a illustrated a great reason for gun ownership.)

58 jpfletcher  6/03/08 11:09:28 am reply quote

06/03/08 12:08:18 IP block 66.165.190.122
Trying 66.165.190.122 at ARIN
Trying 66.165.190 at ARIN

OrgName: TERRENAP DATA CENTERS, INC.
OrgID: TERREN-2
Address: 50 NE 9th St
Address: 2nd Floor
City: Miami
StateProv: FL
PostalCode: 33132
Country: US

NetRange: 66.165.160.0 - 66.165.191.255
CIDR: 66.165.160.0/19
NetName: TERRENAP-0-19
NetHandle: NET-66-165-160-0-1
Parent: NET-66-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.TERRENAP.NET
NameServer: NS2.TERRENAP.NET
Comment:
RegDate: 2003-10-09
Updated: 2005-03-11

RAbuseHandle: ABUSE676-ARIN
RAbuseName: Abuse
RAbusePhone: +1-305-328-8000
RAbuseEmail: abuse@terremark.com

RTechHandle: BW963-ARIN
RTechName: Williams, Bill
RTechPhone: +1-305-328-8000
RTechEmail: bwilliams@terremark.com

RTechHandle: HOSTM537-ARIN
RTechName: Hostmaster
RTechPhone: +1-305-328-8000
RTechEmail: hostmaster@terremark.com

RTechHandle: SS2510-ARIN
RTechName: Spaller, Steven
RTechPhone: +1-305-328-8000
RTechEmail: sspaller@terremark.com

OrgAbuseHandle: ABUSE676-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-305-328-8000
OrgAbuseEmail: abuse@terremark.com

OrgTechHandle: BW963-ARIN
OrgTechName: Williams, Bill
OrgTechPhone: +1-305-328-8000
OrgTechEmail: bwilliams@terremark.com

OrgTechHandle: HOSTM537-ARIN
OrgTechName: Hostmaster
OrgTechPhone: +1-305-328-8000
OrgTechEmail: hostmaster@terremark.com

OrgTechHandle: SS2510-ARIN
OrgTechName: Spaller, Steven
OrgTechPhone: +1-305-328-8000
OrgTechEmail: sspaller@terremark.com

# ARIN WHOIS database, last updated 2008-06-02 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.

59 looking closely  6/03/08 11:17:05 am reply quote

Goddamn robots!

At least you can get insurance.

60 looking closely  6/03/08 11:19:00 am reply quote

re: #46 cosmo

61 jimzinsocal  6/03/08 11:30:26 am reply quote

Sorry for my posting tel numbers earlier.[arin info].
It could have been taken as an urge and that wasnt my intent.

62 gmsc  6/03/08 11:31:14 am reply quote

I don't know if it will be of any help, but there are some paranoid ramblings about TerraNAP at DailyKos that have some legitimate links.

63 incanus  6/03/08 11:42:02 am reply quote

re: #58 jpfletcher

This is simply the provider's supernet; look more closely (links in this thread already).

64 blutonazi98  6/03/08 11:47:42 am reply quote

re: #54 incanus

nice! i had just done that and was about to brag about my IT net prowess.

"shakes fist at incanus" i could have been somebody! i could have made a name for myself!

65 incanus  6/03/08 12:02:43 pm reply quote

re: #64 blutonazi98

nice! i had just done that and was about to brag about my IT net prowess.

"shakes fist at incanus" i could have been somebody! i could have made a name for myself!

You coulda been a contendah!

66 zerodamage  6/03/08 12:22:08 pm reply quote

I've been researching this for a little while now. Depending on where you look, different information props up. For example, if you check this out at [Link: www.ip-adress.com...] you come up with Herndon, VA. A whois check via my Linux terminal gives me this:
whois 66.165.190.122
TERRENAP DATA CENTERS, INC. TERRENAP-0-19 (NET-66-165-160-0-1)
66.165.160.0 - 66.165.191.255
RAVENWOOD TERRENAP-0-19 (NET-66-165-190-120-1)
66.165.190.120 - 66.165.190.127


Ravenwood? The bad guys from the TV Show "Jericho?" Wierd. Anyway....

Network Solutions pulls up the same thing.
The user of this machine has their entire PORT range shut down. They do not want anyone to know anything about it.

67 zerodamage  6/03/08 12:26:17 pm reply quote

Yeah, the ARIN whois was down for me. Glad someone got it to work and was able to pull more information from there. It's too bad that DNSSTUFF.com has gone commercial and is basically useless. Used to be the best site for this kind of thing.

68 markie  6/03/08 12:27:08 pm reply quote

re: #19 buzzsawmonkey

"Terrenap?"

As in "dirt nap?"

As in "death?"

Knap of the earth?

Under the radar?


not.

69 zerodamage  6/03/08 12:30:54 pm reply quote

Ah, here is some useful information from this site here: [Link: www.aboutus.org...]


Description

Through its advanced expertise and global state-of-the-art facilities, Terremark delivers world-class technology solutions to a wide range of domestic and international businesses. Offering facilities services, managed services, professional services, and managed hosting, in a secure environment that ensures continuity of business, compliance with federally-mandated requirements, and ultimately, peace of mind.

As a leading operator of integrated Internet exchanges and datacenter operations, Terremark provides global managed IT infrastructure solutions for private and public sector customers.

Terremark is headquartered in Miami, Florida with offices and facilities in California, Virginia, Spain, Brazil and other locations around the world.

read more
edit Contact

Terremark Worldwide
miami FL
US 33131
+1.3058563200

70 incanus  6/03/08 12:32:30 pm reply quote

re: #69 zerodamage

Again, TerreNAP is simply the provider; they own the /19. You want to dig into the /29 owned by Ravenwood. See my link above. The /29 has been reassigned, which means TerreNAP has assigned responsibility for this netblock to someone else.

71 abolitionist  6/03/08 12:35:42 pm reply quote

re: #22 Shug

Right wing robots huh ? .....

Rove, you robotic bastard

Uh, no.

...all of the referring pages for this bot were from “right-wing” sites, ...

does not mean what your seem to infer. It means the bot was typically visiting/examining a "right wing" site just prior to visiting LGF, perhaps by following a link from there to LGF.

72 blutonazi98  6/03/08 12:54:08 pm reply quote

terrenap, terremark, ravenwood and NAP of the Americas all turn up address at that address. some are listed on different floors but all turn up in google search for that addressgoogle ravenwood + whois addressgoogle nwhois address alone

73 blutonazi98  6/03/08 1:01:18 pm reply quote

terrenap, terremark, ravenwood and NAP of the Americas all turn up in google searches for that address
google ravenwood + whois address

google for nwhois address alone

please ignore gibberish in post 72

74 zerodamage  6/03/08 1:04:00 pm reply quote

re: #72 blutonazi98

Yeah, I figured that out after my post when I realized I missed some replies. I did not bother to repeat it here. I did do an OS scan on the system though and it returns multiple OS fingerprints (via nmap). The IP looks to be the gateway to a larger network with multiple machines much in the way my work network is configured. It's a possibility that this gateway machine (could be a computer or a network device acting as a firewall) has been compromised by someone who whatever. Hard to say without putting much more research into it. The machine scanning LGF is hiding quite effectively.

75 blutonazi98  6/03/08 1:50:44 pm reply quote

i should have stated that all of those entry's show up in Google searches for the actual street address
50 NE 9th St, miami FL 33132
some have address listed on different floors.


this is what happens when i try to blog/google/type/work at the same terminal

76 blutonazi98  6/03/08 1:52:11 pm reply quote

the building itself seems to be owned by
Ifx Communication Networks Incorporated

but i could be wrong

77 clgood  6/03/08 3:39:23 pm reply quote

re: #32 RedSoxNation

If all she wants is a simple blog, Wordpress is plenty easy. I moved there from blogspot because google is evil.

It's simple (and free) to register. A few clicks later and she's up and running.

78 Thunder Pig  6/04/08 2:38:12 am reply quote

Could it have been possible that the person was just mirroring your website and building an index?

When I was on dial up (before lovely DSL arrived 3 months ago), I would routinely visit Public Terminals and also gain access to the Internet from businesses, cafes, and Universities for the purpose of downloading blogs I liked to read. I still have DVDs of info (including LGF) I slurped from the net to read at home, where the pace of dialup was 28k.

I never followed the robots.txt file info.

I still do that on occasion with the Lefty and Jihadi-type websites who I don't want to have my home IP.

If (and when) the Internet War breaks on our shores with any seriousness, you will know it when certain high-profile bloggers start dying. It's what I would do if I were a planner in the jihadi sleeper movement in the west.

Not everything on the internet is sinister, however, I do carry protection in case I am terribly, terribly wrong or luck into being present during an armed robbery.


This entry has been archived.
Comments are closed.

^ back to top ^

log in
Name:
Pass:

Register (closed) Forgot Your Password? My Account Re-send Confirmation (To log in, cookies must be enabled in your browser!)

► LGF Headlines

► Top 10 Comments

► Bottom Comments

► Recent Comments

► Tools/Info

► LGF Hits

► Slideshows

► Resources

► Never Forget

► Statistics

► Tag Cloud

► Contact

You must have Javascript enabled to use the contact form.
Your email:

Subject:

Message:


Messages may be published in our weblog, unless you request otherwise.
Tech Note:
Using the Contact Form

► News/Opinion

► Blogs

Judging from the large number of shoes.

Vote for LGF!
weblog awards