Web robots are visiting sites to hack, spam, email harvest and to scrap your website contect for profit.
This blog is an atempt to keep track of them and to help webmasters by listing the abuse in google.
Mar 8, 2011
182.114.206.25 hn.kd.ny.adsl union injection hacker
I got the same issue today on a site. Hundreds of thousands of the same SQL injection query, only differing by an increasing LIMIT at the end, from IP 115.52.227.189 (also resolves to hn.kd.ny.adsl). Looks like at least an entire /24 resolve to the same host. Read somewhere else that there could be an entire /12 that these requests can originate from. Best to just block 115.52.0.0/12 in its entirity.
1 comment:
I got the same issue today on a site. Hundreds of thousands of the same SQL injection query, only differing by an increasing LIMIT at the end, from IP 115.52.227.189 (also resolves to hn.kd.ny.adsl). Looks like at least an entire /24 resolve to the same host. Read somewhere else that there could be an entire /12 that these requests can originate from. Best to just block 115.52.0.0/12 in its entirity.
Post a Comment