vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   Community Lounge (https://vborg.vbsupport.ru/forumdisplay.php?f=13)
-   -   Look what I found on my logs today (https://vborg.vbsupport.ru/showthread.php?t=152631)

mihai11 07-18-2007 05:03 PM

Look what I found on my logs today
 
This is the list of not found pages: (errors of type 404)


Quote:

/impex/ImpExData.php
/showthread.php%3Ft%3D270
/sumthin
/showthread.php%3Ft%3D27
/_vti_inf.html
/vbgsitemap/vbgsitemap-config.php
/_vti_bin/shtml.exe/_vti_rpc
//addpost_newpoll.php
//components/com_performs/performs.php
/clientscript/Mozilla/
//header.php
/chat3//chat/messagesL.php
/mmtixsln.html
/horde-3.0.5//README
///bb_usage_stats/include/bb_usage_stats.php
//README
/mails//README
/chat//chat/messagesL.php
/php/phpmychat//chat/messagesL.php
/mail//README
/lbtrivtj.html
/%20http:/www.360romania.eu/sendmessage.php
/phpMyChat-0.14.5//chat/messagesL.php
/_vti_bin/owssvr.dll
/chats//chat/messagesL.php
/clientscript/console.log('
/chat2//chat/messagesL.php
/clientscript/application/x-www-form-urlencoded
/chat1//chat/messagesL.php
/chatroom//chat/messagesL.php
/oghviqhjousdsta.html
/other-images/july-2007/shark-kayak.jpg
/newmail//README
/cacti/include/config.php
/horde-3.0.8//README
/forum//chat/messagesL.php3
/phpchat//chat/messagesL.php3
/horde3//README
//administrator/components/com_remository/admin.remository.php
/clientscript/ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwx yz0123456789+/
/MSOffice/cltreq.asp
/PhpMyChat//chat/messagesL.php
/webmail//README
/kdblxtjxtpvfj.html
/phpMyChat-0.14.2//chat/messagesL.php
/forums//chat/messagesL.php
/community//chat/messagesL.php
//impex/ImpExData.php
/gyxmompskjpovmyu.html
/horde-3.0.9//README
/clientscript/misc.php
/xekizokf.html
/clientscript/help.php
/clientscript/DXImageTransform.Microsoft.alpha
/clientscript/forumdisplay.php
/mailz//README
/sumthin/
/phpMyChat//chat/messagesL.php
/other-images/calin-popa/calin-luca-1.jpg
//bb_usage_stats/include/bb_usage_stats.php
/other-images/imagini-anti-fumat/anti-fumat01.png
/horde-3.0.7//README
/email//README
Somebody worked very hard to break my box. I am thinking to ban their IP address, but I am not sure how to do that. From .htacces file, right ?

What else can I do to stop these people from attacking my server ?



Regards,
Razvan M.

EnIgMa1234 07-18-2007 05:15 PM

You can ban I.P from admincp -> vbulletin settings -> banning options

Attilitus 07-18-2007 05:30 PM

It would be better to ban then at the root level, not merely from vbulletin. Otherwise they could continue to break through your defences through non-vbulletin scripts on your server.

Check the activity of that IP an see if it was also browsing other pages. If those were the only (or the main) pages that it was visiting, ban it.

mihai11 07-18-2007 05:35 PM

Quote:

Originally Posted by Attilitus (Post 1294798)
It would be better to ban then at the root level, not merely from vbulletin. Otherwise they could continue to break through your defences through non-vbulletin scripts on your server.

Check the activity of that IP an see if it was also browsing other pages. If those were the only (or the main) pages that it was visiting, ban it.

How can I ban them at the "root" level ?

I am on a VPS with Apache + Free BSD. I don't have CPANEL or stuff like that. To my knowledge, the way to ban IPs is to modify the .htaccess file. Is there any other way ?

More info: on my box there is *only* VB without any hacks. My site is about politics and, frankly, I expected this kind of behavior from people that don't agree with some topics. In that case, is it enough to ban them from VB control panel ?

Update:
There are many IPs.... as much as 20. These people are professionals.



Regards,
Razvan M.

cheat-master30 07-18-2007 06:00 PM

Quote:

Originally Posted by mihai11 (Post 1294808)
How can I ban them at the "root" level ?

I am on a VPS with Apache + Free BSD. I don't have CPANEL or stuff like that. To my knowledge, the way to ban IPs is to modify the .htaccess file. Is there any other way ?

More info: on my box there is *only* VB without any hacks. My site is about politics and, frankly, I expected this kind of behavior from people that don't agree with some topics. In that case, is it enough to ban them from VB control panel ?

Update:
There are many IPs.... as much as 20. These people are professionals.



Regards,
Razvan M.

I don't think blocking them with .htaccess is that difficult. Try something like:

Code:

deny from [their ip here]
in that .htaccess file.

Secondly, yes, it is a hacking attempt, but obviously not much of a good one, and a bit strange that they never tried breaking into the install directory. Try blocking access from those directories in future (install directory and directory where you installed impex).

mihai11 07-18-2007 06:02 PM

There are 21 IP addresses from which they attacked by box. Take a look below:

66.249.72.201 = 1
205.134.161.114 = 11
83.16.76.50 = 1
81.177.16.71 = 1
66.35.110.180 = 1
208.99.195.54 = 18
82.199.192.2 = 1
75.126.134.16 = 1
64.131.86.2 = 1
67.99.202.5 = 1
86.121.14.71 = 2
24.83.72.98 = 1
81.3.4.103 = 2
70.87.229.2 = 1
89.120.209.12 = 4
86.35.254.29 = 2
86.124.17.151 = 1
89.42.84.165 = 1
85.54.158.71 = 5
202.88.176.109 = 27
213.203.208.154 = 5


What I mean by the above is this:

[IP address] = [no. of 404 errors]

To be more clear: how many requests they have done from a given IP address.

I only counted requests that were looking for some known vulnerabilities - like the one in "ImpExData.php".

If you will closely analyze the data, you can see that from most IPs there is only 1 request !?!?! Why ? They were anticipating a ban ?

Quote:

Originally Posted by cheat-master30 (Post 1294831)
I don't think blocking them with .htaccess is that difficult. Try something like:

Code:

deny from [their ip here]
in that .htaccess file.

Secondly, yes, it is a hacking attempt, but obviously not much of a good one, and a bit strange that they never tried breaking into the install directory. Try blocking access from those directories in future (install directory and directory where you installed impex).

I don't have ImpEx on my board. I did not use it because my board started with VBulletin.

You are right about this: they were not looking for the "install" folder.

Attilitus 07-18-2007 06:34 PM

If you only have vb installed I would just remove all unnecessary files from your server and sit tight. Make sure you keep frequent backups like all responsible webmonkeys and you'll be fine.

You want to be careful when banning IPs indiscriminently because it is possible that those ips just happened to stumble upon those directories while doing a completely benign web-crawl.

mihai11 07-18-2007 06:39 PM

Quote:

Originally Posted by Attilitus (Post 1294872)
If you only have vb installed I would just remove all unnecessary files from your server and sit tight. Make sure you keep frequent backups like all responsible webmonkeys and you'll be fine.

You want to be careful when banning IPs indiscriminently because it is possible that those ips just happened to stumble upon those directories while doing a completely benign web-crawl.

My VB install is already strip-naked. There is not a single hack on my box. I deleted the install folder. There are not any other unnecessary files that I know of. Like I said, my setup only contains a clean VB - nothing else. Also, the admincp and modcp folders are secret. ( I did not used the defaults)

And yes, I am trying to be a good web monkey :) :) :) I do frequent backups :)


All times are GMT. The time now is 03:56 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01105 seconds
  • Memory Usage 1,743KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_code_printable
  • (5)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (8)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete