I was looking through my raw access logs this morning and noticed a lot of entries similar to this one all from the same IP address.
205.252.49.146 - - [30/Dec/2004:05:22:42 -0700] “HEAD /refer/index.php?start=50&glimpse=1 HTTP/1.1″ 404 - “http://bdsm.net-pic.com” “Mozilla/5.0″
The only difference in the entries is the URL, some are for poker and others are for porn sites. What exactly is this clown trying to do? My guess would be some kind of referrer spoofing but I don’t have any referrer information displayed on my website.
Needless to say I have banned the IP address.