Another hitbot network uncovered

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • PowerCum
    CjOverkill
    • Apr 2003
    • 1328

    #1

    Another hitbot network uncovered

    During the routine beta test and scrubing of bot traffic we found that there is a large bot network running on cloud server providers. That specific bot network traffic seems to emulate browser behavior considerably good to fool most of the anticheat protections. It's traffic is being traded around and also sold to and from some traffic brokers without their knowledge.

    For the next major CjOverkill version there is planned an automatic update of this list, but for now you should just ban these IP ranges.
    Just click on your IP Filter into your cjadmin and add these ranges to make sure you are not being cheated by that hitbot network.

    All these IP ranges belong to hosting companies, so there is absolutely no chance that you will filter human traffic even if you wanted to.

    23.20.0.0 - 23.23.255.255
    50.16.0.0 - 50.19.255.255
    54.242.0.0 - 54.243.255.255
    54.247.0.0 - 54.247.255.255
    54.248.0.0 - 54.249.255.255
    54.251.0.0 - 54.251.255.255
    54.252.0.0 - 54.252.255.255
    67.202.0.0 - 67.202.63.255
    72.44.32.0 - 72.44.63.255
    75.101.128.0 - 75.101.255.255
    107.20.0.0 - 107.23.255.255
    174.129.0.0 - 174.129.255.255
    184.72.0.0 - 184.73.255.255
    204.236.128.0 - 204.236.255.255
    216.182.224.0 - 216.182.239.255

    During the next days there will be more updates to this list while we are mapping all the hosting providers giving server support to this hitbot network.

    For more information feel free to hit ICEFIRE on ICQ 171216535

    The updated list will be hosted on http://www.cjoverkill.com/banthins.html
    CjOverkill Traffic Trading Script
    Free, secure and fast traffic trading script. Get your copy now
  • JFK
    FUBAR the ORIGINATOR
    • Jan 2002
    • 67373

    #2
    Thanks for the post

    FUBAR Webmasters - The FUBAR Times - FUBAR Webmasters Mobile - FUBARTV.XXX
    For promo opps contact jfk at fubarwebmasters dot com

    Comment

    • woj
      <&(©¿©)&>
      • Jul 2002
      • 47882

      #3
      how many ips do they have?
      Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
      Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
      Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager

      Comment

      • KillerK
        Confirmed User
        • May 2008
        • 3406

        #4
        Is this a feature you "borrowed" from Choker?

        Comment

        • fatfoo
          ICQ:649699063
          • Mar 2003
          • 27763

          #5
          Congratulations with uncovering the hitbot traffic network. This specific hitbot traffic can fool most of the anticheat protections - that is not good. These kinds of things happen often with traded traffic. These kinds of things could happen with bought traffic from traffic brokers. Good luck with filtering human traffic.
          Send me an email: [email protected]

          Comment

          • redwhiteandblue
            Bollocks
            • Jun 2007
            • 2793

            #6
            You've missed a few:

            50.17.0.0 - 50.17.255.255
            50.19.0.0 - 50.19.255.255
            107.21.0.0 - 107.21.255.255
            107.22.0.0 - 107.22.255.255
            184.73.0.0 - 184.73.255.255

            I think they're all Amazon AWS, but didn't check them all.
            Interserver unmanaged AMD Ryzen servers from $73.00

            Comment

            • candyflip
              Carpe Visio
              • Jul 2002
              • 43069

              #7
              Originally posted by KillerK
              Is this a feature you "borrowed" from Choker?
              CJOverkill has been in constant development since it's inception. Choker hasn't updated TTT in 5, almost 6 years.

              Spend you some brain.
              Email Me

              Comment

              • PowerCum
                CjOverkill
                • Apr 2003
                • 1328

                #8
                Originally posted by redwhiteandblue
                You've missed a few:

                50.17.0.0 - 50.17.255.255
                50.19.0.0 - 50.19.255.255
                107.21.0.0 - 107.21.255.255
                107.22.0.0 - 107.22.255.255
                184.73.0.0 - 184.73.255.255

                I think they're all Amazon AWS, but didn't check them all.
                Yes, they use mainly amazon AWS for now, but there are also some minor providers. As you may see the minor ranges you have pointed are already included in my list. Some of the ranges include several class B.
                CjOverkill Traffic Trading Script
                Free, secure and fast traffic trading script. Get your copy now

                Comment

                • redwhiteandblue
                  Bollocks
                  • Jun 2007
                  • 2793

                  #9
                  Originally posted by PowerCum
                  Yes, they use mainly amazon AWS for now, but there are also some minor providers. As you may see the minor ranges you have pointed are already included in my list. Some of the ranges include several class B.
                  Ah yes. It is late, I am tired.
                  Interserver unmanaged AMD Ryzen servers from $73.00

                  Comment

                  • V_RocKs
                    Damn Right I Kiss Ass!
                    • Nov 2003
                    • 32449

                    #10
                    Free money!

                    Comment

                    Working...