Identification
Its full user-agent string, exactly as it arrives at the gate:
There is no operator to verify against. This name is what software calls itself when nobody gave it one. Read Unknown's documentation.
How to block URL-echo scanner
URL-echo scanner does not read robots.txt, so a polite sign is wasted on it. Refuse it at your web server or firewall instead. User agents are easy to fake, so pair this with rate limiting.
# robots.txt will not stop URL-echo scanner. Block it at the server.
# nginx
if ($http_user_agent ~* "^(https?://|/)") {
return 403;
}The same thing on Apache:
# Apache (.htaccess)
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} ^(https?://|/) [NC]
RewriteRule .* - [F,L]Observed behaviour
Most active around 11:00. Office hours, like a professional.
Requested 0 disallowed pages out of 27 requests. Never read robots.txt.
Has never followed the hidden link to /trap/. Either well trained or very lucky.
Where it comes from
Scripts and scanners run from wherever their owners rent a server. These are the networks behind the visits on file:
No network data for these visits yet. The zoo looks networks up in a local database, which may still be downloading.
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Keeper's field notes
Questions site owners ask
Does URL-echo scanner respect robots.txt?
We can't say yet. It has not fetched robots.txt here, and it has not touched a disallowed page either.
Will blocking URL-echo scanner hurt my search rankings?
No. Nothing respectable will miss it.
How often does URL-echo scanner visit?
Here, about 4 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.