| Author |
Message |
sharlein Member Emeritus

Joined: Nov 19, 2002 Posts: 322 Location: On the Road
|
Posted:
Thu Jun 03, 2004 6:49 am |
|
I received my first hit with Sentinel(tm). It was an Inktomi crawler and the reason given was SCRIPT. Can someone tell me exactly one happened? Thank you, Steve |
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Thu Jun 03, 2004 6:58 am |
|
Without revealing your path info, post the email you received. |
|
|
|
 |
sharlein Member Emeritus

Joined: Nov 19, 2002 Posts: 322 Location: On the Road
|
Posted:
Thu Jun 03, 2004 7:10 am |
|
It was sent to Rebecca, I will post it as soon as she forwards it. Thank you. |
|
|
|
 |
sharlein Member Emeritus

Joined: Nov 19, 2002 Posts: 322 Location: On the Road
|
Posted:
Thu Jun 03, 2004 1:20 pm |
|
Here is the email: | Quote: |
----- Original Message -----
Sent: Thursday, June 03, 2004 12:47 AM
Subject: Abuse Blocked on xxxxx
>
> Date & Time: 2004-06-03 02:47:28
> Blocked IP: 66.196.90.7
> User ID: Anonymous (1)
> Reason: Abuse - SCRIPT
> --------------------
> User Agent: Mozilla/5.0 (compatible; Yahoo! Slurp;
> Query String:
ndex&l_op=ratelink&lid=6&ttitle=GRC_(Steve_Gibson_Research_Corporation)
> Forwarded For: none
> Client IP: none
> Remote Address: 66.196.90.7
> Remote Port: 54792
> Request Method: GET
> --------------------
> Who-Is for IP
> 66.196.90.7
>
>
>
>
> OrgName: Inktomi Corporation
> OrgID: INKT
> Address: 4100 East Third Avenue
> City: Foster City
> StateProv: CA
> PostalCode: 94404
> Country: US
>
> NetRange: 66.196.64.0 - 66.196.127.255
> CIDR: 66.196.64.0/18
> NetName: INKTOMI-BLK-3
> NetHandle: NET-66-196-64-0-1
> Parent: NET-66-0-0-0-0
> NetType: Direct Allocation
> NameServer: NS1.YAHOO.COM
> NameServer: NS2.YAHOO.COM
> NameServer: NS3.YAHOO.COM
> NameServer: NS4.YAHOO.COM
> NameServer: NS5.YAHOO.COM
> Comment: This netblock contains Web Crawlers. Please
> Comment: contact for questions or concerns.
> RegDate: 2001-10-30
> Updated: 2003-09-26
>
> AbuseHandle: ZI107-ARIN
> AbuseName: Inktomi Corporation
> AbusePhone: +1-650-653-2800
> AbuseEmail:
>
> TechHandle: ZI35-ARIN
> TechName: Inktomi Corporation
> TechPhone: +1-650-653-2800
> TechEmail:
>
> OrgTechHandle: ZI35-ARIN
> OrgTechName: Inktomi Corporation
> OrgTechPhone: +1-650-653-2800
> OrgTechEmail:
>
>
>
|
|
|
|
|
 |
Raven Site Admin/Owner

Joined: Aug 27, 2002 Posts: 16987 Location: Kansas
|
Posted:
Thu Jun 03, 2004 1:47 pm |
|
It's the () in the url. Just for curiosity, try that same url but filter out this part | Code: | | &ttitle=GRC_(Steve_Gibson_Research_Corporation) |
|
|
|
|
 |
sharlein Member Emeritus

Joined: Nov 19, 2002 Posts: 322 Location: On the Road
|
Posted:
Thu Jun 03, 2004 4:16 pm |
|
The link works with or without the (). I removed them. Should I consider this a false positive and remove the ban? |
|
|
|
 |
BobMarion Former Admin in Good Standing

Joined: Oct 30, 2002 Posts: 1043 Location: RedNeck Land (known as Kentucky)
|
Posted:
Thu Jun 03, 2004 4:24 pm |
|
This is a false positive In the "Script" blocker there is a regex check that has the ( and ) in it. This is also in the native nuke script checkers. We are looking for a way to prevent it from triggering the blocker but at the same it would then trigger the native script protection. |
|
|
|
 |
sharlein Member Emeritus

Joined: Nov 19, 2002 Posts: 322 Location: On the Road
|
Posted:
Thu Jun 03, 2004 4:30 pm |
|
Thank you, Bob. I will remove the block. |
|
|
|
 |
|
|
|
|