电子邮件点击会导致来自不同 IP 和用户代理的多个请求

电子邮件点击会导致来自不同 IP 和用户代理的多个请求

我经营着一个小型网站,用于跟踪球队的比赛出席情况。电子邮件发送给队员,其中包含 3 个链接,1 个表示参加,1 个表示不参加,1 个表示可能参加。每个用户只需单击电子邮件中的链接即可表明他们是否参加下一场比赛。非常简单。最近发生了一件奇怪的事情,有人告诉我他们点击了“不会参加”,但网站将其记录为“会参加”。我只是将其归咎于用户错误或手指粗,但为了以防万一启用了更详细的日志记录。虽然我没有找到解决上述问题的方法,但我发现了一些更奇怪的事情。我发现一些用户会在几分钟内从不同的 IP 地址甚至有时不同的用户代理向服务器发出对同一资源(相同查询字符串)的多个请求。我觉得这真的很奇怪。以下是一些此类事件的示例:

20211009 093747 - a=48170&k=[TOKEN]&r=y,Player: [Player 2 Name],Attendance: 48170,Game: 1425,Team: 68,Response: y,Error: ,IP: 184.147.117.186,User Agent: Mozilla/5.0 (Linux; Android 11; SAMSUNG SM-G781W) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/15.0 Chrome/90.0.4430.210 Mobile Safari/537.36,Referer
20211009 093753 - a=48170&k=[TOKEN]&r=y,Player: [Player 2 Name],Attendance: 48170,Game: 1425,Team: 68,Response: y,Error: ,IP: 96.63.131.4,User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/29.0.1547.66 Safari/537.36,Referer
20211009 093755 - a=48170&k=[TOKEN]&r=y,Player: [Player 2 Name],Attendance: 48170,Game: 1425,Team: 68,Response: y,Error: ,IP: 198.235.201.68,User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.36,Referer
20211009 094047 - a=48170&k=[TOKEN]&r=y,Player: [Player 2 Name],Attendance: 48170,Game: 1425,Team: 68,Response: y,Error: ,IP: 184.147.117.186,User Agent: Mozilla/5.0 (Linux; Android 11; SAMSUNG SM-G781W) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/15.0 Chrome/90.0.4430.210 Mobile Safari/537.36,Referer

20211008 090050 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 104.47.60.254,User Agent: ,Referer
20211008 090051 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 184.145.50.95,User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.81 Safari/537.36,Referer
20211008 090207 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 184.72.165.49,User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36,Referer
20211008 090232 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 52.90.211.63,User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36,Referer
20211008 090236 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 40.94.16.18,User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.140 Safari/537.36,Referer
20211008 090244 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 104.47.61.254,User Agent: ,Referer
20211008 090245 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 54.84.28.125,User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36,Referer
20211008 090409 - a=48168&k=[TOKEN 3]&r=n,Player: [Player 3 Name],Attendance: 48168,Game: 1425,Team: 68,Response: n,Error: ,IP: 54.209.227.48,User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.109 Safari/537.36,Referer

我已经将一些 IP 追踪到我所在国家的 ISP,这很合理,但其中一些是 AWS,一些位于不同的国家/地区,等等。我注意到这种情况也发生在多个用户代理上,因此它不是某一个特定的设备。这种情况也不是发生在每个人身上,似乎没有任何规律或原因。有人知道为什么会发生这种情况吗,或者我是否应该担心?

谢谢。

答案1

猜测:恶意软件会检查收件人的计算机,这些计算机使用基于云的服务来检查邮件中的链接是否存在恶意软件。相关邮件服务器上的反垃圾邮件措施也会这样做。

相关内容