Excessively long useragent

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Excessively long useragent

L0 Member

I don't think the following bot useragent is acceptable:

 

Expanse, a Palo Alto Networks company, searches across the global IPv4 space multiple times per day to identify customers' presences on the Internet. If you would like to be excluded from our scans, please send IP addresses/domains to: scaninfo@paloaltonetworks.com


It is excessively long, and reads more like an advert. A legit organisation should not be doing this IMO

Site admins should need to opt-in, as is good practice for accepting cookies for example, not opt-out.

Does the Palo bot abide by robots.txt or similar mechanism?

2 REPLIES 2

Community Team Member

Hi @chaeron ,

 

This was discussed before here:

https://live.paloaltonetworks.com/t5/general-topics/high-loads-by-scanner/td-p/503445

 

As suggested, in order to be removed contact the email from the access log and request to remove your IP address from the scans.

 

Kind regards,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L0 Member

Thank you for your response.
Although I understand site owners can request that the Palo bot does not scan their ip address(es), this sets a precedent, site owners should not be expected to "opt out" via email from bots sent from legitimate companies - that would be a full-time job 🙂
At a minimum, the robots.txt file should be respected.
...non-legit organisations would ignore the request, and possibly spam harder ( how does a site owner know Palo is legit, again, researching this would be part of the full-time job )
I think my main point is that the site logs get populated with overly-long "useragents" that read like advertisements, something a malicious actor might do, but not a legitimate organisation.
Looking at the multitude of useragents, malicious and legit, Palo bot stands out as not really being a useragent at all.
Although not a scientific test, a sample of 10,000 useragents gives me an average string length of 78, Palo bot is 269 characters in length.
imo legitimate companies should "play nicely" and follow convention.

  • 1445 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!