PDA

View Full Version : what should i do?


CarpCharacin
01-03-2015, 06:11 PM
I was looking at the who's online list and there was this one guest. It said that they were moderating. What should i do? I banned the IP address.

Max Taxable
01-03-2015, 06:43 PM
Visiting the page doesn't mean it is able to actually do anything. So what we see in WoL isn't always what's actually going on.

For example i could go to your site and manually type in /inlinemod.php but if i am not logged in and/or don't have the necessary permissions, you'll still see me as "moderating" in WoL anyway.

I recommend you check that IP address to see if it is a legitimate hostname - one that normal people use - before banning. You could well be blocking legitimate people especially if it is a mobile service.

ozzy47
01-03-2015, 08:01 PM
Yes there is nothing to worry about. You should have see the https://vborg.vbsupport.ru/external/2015/01/45.png Viewing Error Message next to the Location, so you know they were not actually doing anything.

CAG CheechDogg
01-04-2015, 12:19 AM
Also what could of happen is one of your moderators clicking on a saved bookmark and going to a page where they moderate something ... I banned a moderator once for this very thing lol ...

What you can do is do an IP search from the admin panel to see if it belongs to one of your members first ...

CarpCharacin
01-04-2015, 12:54 AM
Also what could of happen is one of your moderators clicking on a saved bookmark and going to a page where they moderate something ... I banned a moderator once for this very thing lol ...

What you can do is do an IP search from the admin panel to see if it belongs to one of your members first ...

i did a search on StopForumSpam and the IP was listed as a spammer.

Yes there is nothing to worry about. You should have see the http://ozzmodz.com/images/statusicon/wol_error.png Viewing Error Message next to the Location, so you know they were not actually doing anything.
i did see the viewing error message symbol next to it.

MarkFL
01-04-2015, 01:00 AM
When I first was promoted to admin at the site with which I help, I was startled to see a guest administrating the site...but I was assured by the site owner this is fairly normal to see, and he cited the same issues given in this thread. It is understandable that you found this disconcerting. :D

ozzy47
01-04-2015, 01:02 AM
I would just ignore the issue, unless the same IP is always trying.

CarpCharacin
01-04-2015, 01:05 AM
I would just ignore the issue, unless the same IP is always trying.

I just checked it and the IP was trying to, even though i banned it.

ozzy47
01-04-2015, 01:12 AM
You may have to wait for your online page to update, it will take as much time as you have set in Session Timeout for it to not show anymore.

CarpCharacin
01-04-2015, 02:43 AM
the hostname was this "rate-limited proxy". There are now a lot of these "rate limited proxy" IPs on my site right now trying to access areas they should not be accessing like the modcp and the admincp. The other admin got an email saying he had been locked out of his account because the failed password attempts. Is someone trying to hack/brute force my site?

ozzy47
01-04-2015, 02:59 AM
What is the useragent string of the users?

CarpCharacin
01-04-2015, 03:02 AM
What is the useragent string of the users?

what is a useragent string of users?

ozzy47
01-04-2015, 03:04 AM
On your online.php page scroll to the bottom and for the option User Agent: select Yes, then click on the display button.

Max Taxable
01-04-2015, 03:06 AM
what is a useragent string of users?This little edit will make your site always show you the UA strings in WoL:

https://vborg.vbsupport.ru/showthread.php?t=306009

CarpCharacin
01-04-2015, 03:06 AM
this is what it gave me
Mediapartners-Google

Max Taxable
01-04-2015, 03:09 AM
Need to see the entire UA string, IP and all.

ozzy47
01-04-2015, 03:09 AM
Then they are safe, http://en.wikipedia.org/wiki/Mediabot

Max Taxable
01-04-2015, 03:10 AM
Then they are safe, http://en.wikipedia.org/wiki/MediabotThis is why we need to see the whole thing, especially the IP. Might be a spoofed UA.

ozzy47
01-04-2015, 03:12 AM
This is why we need to see the whole thing, especially the IP. Might be a spoofed UA.

That is all they use, https://support.google.com/webmasters/answer/1061943?hl=en

Max Taxable
01-04-2015, 03:17 AM
But it will be from their IP. Not some singapore spammer IP.

ozzy47
01-04-2015, 03:19 AM
True, but we don't know the IP as it was not asked yet. :p

Max Taxable
01-04-2015, 03:21 AM
True, but we don't know the IP as it was not asked yet. :pOther than me asking for the whole UA string including the IP.:D

ozzy47
01-04-2015, 03:23 AM
But they do not add it, that is what I said, it only shows up as Mediapartners-Google

CarpCharacin
01-04-2015, 03:24 AM
Other than me asking for the whole UA string including the IP.:D

it is currently not online. I will give the hostname when it is online again. It was also trying to register.

ozzy47
01-04-2015, 03:28 AM
If it is in the below IP ranges you should be ok.

robots ip address ranges Google (Googlebot)

From | To
64.233.160.0 | 64.233.191.255
66.102.0.0 | 66.102.15.255
66.249.64.0 | 66.249.95.255
72.14.192.0 | 72.14.255.255
74.125.0.0 | 74.125.255.255
209.85.128.0 | 209.85.255.255
216.239.32.0 | 216.239.63.255

ozzy47
01-04-2015, 03:30 AM
Also if they are showing up as guests, you are not using the most current spiders.xml

You need to get it from here, vBulletin Spiders List Hits 1000 Spiders! (http://ozzmodz.com/showthread.php/4845-vBulletin-Spiders-List-Hits-1000-Spiders%21)

CarpCharacin
01-04-2015, 03:31 AM
I am now locked out of my account on my site for 15 minutes. seems i tried to get brute forced. I will update after my account is unlocked.

ozzy47
01-04-2015, 03:32 AM
On here or your site, or mine?

CarpCharacin
01-04-2015, 03:33 AM
On here or your site, or mine?

on my site. The other admin was locked out a while ago.

ozzy47
01-04-2015, 03:34 AM
Well that stinks.

CarpCharacin
01-04-2015, 03:36 AM
Well that stinks.

yes it does. I just googled it, and there was a tutorial on how to spoof your IP and make it look like you are a google bot. Maybe someone is doing that.

ozzy47
01-04-2015, 03:37 AM
Doubtful since the site is so new.

CarpCharacin
01-04-2015, 03:39 AM
Doubtful since the site is so new.

it could be joey.

ozzy47
01-04-2015, 03:44 AM
Who or what is joey?

Max Taxable
01-04-2015, 03:47 AM
Not hard to spoof google adsense using Brutus, or most any other brute force type password cracking tool.

CarpCharacin
01-04-2015, 03:50 AM
Who or what is joey?

Just some troll that follows me around on every forum i go on. I was on his fish site, until he blocked my IP for no reason, and joined my friends site .under the name elaine and used his avatar, but changed the words on it so it said elaine instead of joey and the IP traced back to Truro, Nova Scotia (joey lives in Truro, Nova Scotia) and then he tried to get into my friend's site. I posted a link to my vBulletin site on my friend's site, and maybe joey found his way there.