AlexJ Posted December 12, 2021 Posted December 12, 2021 I am not sure what this crawl bot is trying to do.. but looking for some info:
Randy Calvert Posted December 12, 2021 Posted December 12, 2021 There was a bot out of Sweden that appeared to be attempting to Pentest my site a few weeks ago. My firewall blocked a TON of attempted SQL injections, cross site scripting, and other malicious requests. I would block the IP because whatever they’re doing they should NOT be triggering all of those errors. So it’s most likely not a “good” bot. AlexJ 1
AlexJ Posted December 12, 2021 Author Posted December 12, 2021 I was thinking same to block their subnet: 193.235.141.0/24
Randy Calvert Posted December 12, 2021 Posted December 12, 2021 That would be a good course of action if you don’t have a lot of legitimate traffic from that country. Over 95% of my legitimate traffic is from the US so it’s safe for me to do that. Only you would know what your traffic is like. 🙂
Solution Marc Posted December 13, 2021 Solution Posted December 13, 2021 Make sure you site is up to date, and indeed I would advise you block that IP. Something is clearly intentionally trying to hammer your server with requests
Daniel F Posted December 13, 2021 Posted December 13, 2021 What is the URL where the errors get logged? Are they all logged from the same URL?
Recommended Posts