Gig Avenue

Found Gig Avenue by tracing 404 errors.Gig Avenue Site Pic

They have a sweet web page, & by sweet I mean 110 % shady. Their entire homepage including all text? One big image. Bonus points for the purely table-based layout. Super bonus points for the social media links in the site footer that don’t actually link anywhere.

Hope their “technology cost optimization” product is lightyears ahead of their 20-year old website but not holding my breath.

Back to their bot — they don’t use a bot-specific UserAgent string. Guess what they use?

"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"

Evil or what. They are masquerading as Firefox 29, which makes it harder to ban their bot. Terrible internet manners.

The 404 errors are because Gig Avenue doesn’t manage uppercase characters in our paths correctly, most of the time. Here’s a 30-second snapshot from our access log (filtered to show just Gig Avenue requests):

208.78.85.247 - - [28/Jan/2015:08:59:25 -0800] "GET /carcomplaints.com/kia/optima/2013/steering/steering.shtml HTTP/1.1" 404 4159 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:26 -0800] "GET /carcomplaints.com/Subaru/Legacy/2015/ HTTP/1.1" 200 8510 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:26 -0800] "GET /carcomplaints.com/ram/2500/2012/windows_windshield/ HTTP/1.1" 404 4149 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:30 -0800] "GET /carcomplaints.com/Jeep/Compass/2007/ HTTP/1.1" 200 8876 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:34 -0800] "GET /carcomplaints.com/ford/expedition/1999/engine/blown_head_gasket.shtml HTTP/1.1" 404 4185 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:34 -0800] "GET /carcomplaints.com/hyundai/elantra/2009/safety/ HTTP/1.1" 404 4151 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:40 -0800] "GET /carcomplaints.com/volkswagen/jetta/2008/recalls/ HTTP/1.1" 404 4152 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:42 -0800] "GET /carcomplaints.com/ford/explorer/2005/body_paint/paint_is_peeling_off.shtml HTTP/1.1" 404 4193 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:42 -0800] "GET /carcomplaints.com/Toyota/Corolla/2003/transmission/transmission_failure.shtml HTTP/1.1" 200 20864 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:45 -0800] "GET /carcomplaints.com/Hyundai/ HTTP/1.1" 200 7487 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:46 -0800] "GET /carcomplaints.com/gmc/terrain/2012/accessories-interior/ HTTP/1.1" 404 4050 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"
208.78.85.247 - - [28/Jan/2015:08:59:48 -0800] "GET /carcomplaints.com/ford/expedition/1999/windows_windshield/window_wont_go_down.shtml HTTP/1.1" 404 4197 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20120101 Firefox/29.0"

How to ban Gig Avenue

Since they’re hiding requests as Firefox, you can’t use UserAgents. Think they comply with robots.txt? You’re funny. I went with .htaccess & a RewriteRule:

RewriteEngine On
RewriteCond %{REMOTE_ADDR} ^(208\.78\.85|208\.66\.97|208\.66\.100)
RewriteRule !^robots\.txt - [F]

This looks for IPs matching 208.78.85.* & 208.66.100.* which was the range I saw. They get a bare-bones 403 Forbidden error back for everything except robots.txt, in case they start playing nice someday.

For help with RewriteCond ban types, see the RewriteRule help page.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>