PDA

View Full Version : LiteFinder Network Crawler


IncrediBILL
06-12-2007, 21:46/09:46PM
I just ranted about this one and it bears repeating here as well.

The user agent is:
"Mozilla/5.0 (compatible; LiteFinder/1.0; +http://www.litefinder.net/about.html)"

IMO it appears to be a ruse just to get people to use their big affiliate link site pretending to be a search engine (http://www.litefinder.net/), which has nothing to do with search whatsoever because anything you search just dumps 10 random affiliate links totally unrelated to the topic.

On their "about" page they refuse to tell you their bot's IPs as being "against the company policy" so here are the IPs I've seen them crawl from so you know what to block:

208.101.44.3 -> mybluewine.net.
209.160.65.42 -> hopone.net.
209.62.109.178 -> ev1s-209-62-109-178.ev1servers.net.
216.40.220.34 -> ev1s-216-40-220-34.ev1servers.net.
216.40.222.50 -> ev1s-216-40-222-50.ev1servers.net.
216.40.222.66 -> ev1s-216-40-222-66.ev1servers.net.
216.40.222.82 -> ev1s-216-40-222-82.ev1servers.net.
216.40.222.98 -> ev1s-216-40-222-98.ev1servers.net.
67.19.114.226 -> w103.networkharmony.com.
67.19.250.26 -> 1a.fa.1343.static.theplanet.com.
70.85.113.242 -> f2.71.5546.static.theplanet.com.
74.53.243.226 -> e2.f3.354a.static.theplanet.com.
74.53.243.242 -> f2.f3.354a.static.theplanet.com.
74.53.244.18 -> 12.f4.354a.static.theplanet.com.
74.53.249.34 -> 22.f9.354a.static.theplanet.com.
74.86.209.74 -> templatestill.com.
74.86.249.98 -> westhoste.net.
75.125.18.178 -> ev1s-75-125-18-178.ev1servers.net.
75.125.47.162 -> ev1s-75-125-47-162.ev1servers.net.
75.125.52.146 -> ev1s-75-125-52-146.ev1servers.net.
84.19.176.208 -> ns.km22118.keymachine.de.
87.118.118.111 -> ns.km31417.keymachine.de.
87.118.98.57 -> ns.km22427.keymachine.de.
87.118.98.62 -> ns.km22426.keymachine.de.

The best method to stop most of these types of bots in the first place is to simply block all of ev1servers.net. theplanet.com, and keymachine.de's ranges of IPs and then a whole bunch more.

How do you find these ranges of IPs?

On ARIN.NET like this:

http://ws.arin.net/whois/?queryinput=theplanet.com
http://ws.arin.net/whois/?queryinput=Everyones+Internet

That should get you off to a good start!

Aga
18-12-2007, 09:13/09:13AM
Hallo,

"litefinder.net" is a harvester. He collects email addresses from web sites.


On 06th November 2007 he visited [link removed]our web page from 74.86.209.74. We showed him an email address generated only for him. On 11th December we received the first spam for this email address.



He visited us on 12th November from 216.40.222.82. First spam on 18th December.



On 24th November 70.85.113.242. First spam on 15th December.

Visits without spam:

On 02th December 74.86.209.74.


On 09th December 75.125.47.162.



Regards
Aga

g1smd
18-12-2007, 09:25/09:25AM
Honeypots delivering unique email addresses to unknown bots are so much fun to track.

ihelpyou
18-12-2007, 16:52/04:52PM
Welcome Aga! :hi: