vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB3 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=111)
-   -   We were 'Probed' (https://vborg.vbsupport.ru/showthread.php?t=171977)

NeuroLancer 03-03-2008 01:30 PM

We were 'Probed'
 
1 Attachment(s)
I dont know what else to call it, someone or something in hong kong just visited many many times as 100 guests on my site all in the space of 2 mintues, kinda like they were sniffing around looking for a way in (where they should not be)......

Database has just been backed up.

Its sticks out because I know when a spider comes along, it has a specific behaviour... it doesnt just hit everything all at once, it moves around page to page one at a time... This thing whatever it was was very different.

My site is in development and does not quite get this many non spider hits in a day, let alone 2 minutes. Can anyone tell me if this is expected or unexpected behaviour for a very small forum to have in the usual day to day operations? :confused:

snakes1100 03-03-2008 01:32 PM

Its hard to say exactly what they was doing or if it was even a spider, you need to dig up info on the ip for that hostname in the pic.

I would start by banning them in the admincp and using a host deny in a htacess file as well in your public_html dir.

NeuroLancer 03-03-2008 01:42 PM

Quote:

Originally Posted by snakes1100 (Post 1455922)
Its hard to say exactly what they was doing or if it was even a spider, you need to dig up info on the ip for that hostname in the pic.

I would start by banning them in the admincp and using a host deny in a htacess file as well in your public_html dir.

Thanks for the advice.

I had banned them in admincp but didnt think of htaccess, ive now added the range to htaccess as well whilst i look into it further.

illithid 03-03-2008 01:52 PM

I have to agree with Snakes in regards to banning all the IP addresses used during that "Probe". The reason I say that is because, at first glance, it looks to me like a "brute force attack". A method of hacking to crack passwords, etc. Generally this only occurs at the login script, but can occur at other areas of page. Perhaps they are trying to exploit a weakness somewhere. Hard to say though.

Definitely ban those IP's.

NeuroLancer 03-03-2008 01:58 PM

Quote:

Originally Posted by illithid (Post 1455933)
Definitely ban those IP's.

Done ;)

As far as i can tell, its just a miscellaneous range, not a spider. It was weird because the ip was slightly different each time, thus becoming 100 guests.

And also, I just discovered the following:

Quote:

Called with DO = 'a russian url ive removed (because when i went there Kaspersky found malware)'
The site was a Chinese site written in English and hosted in Russia... it was weird.

They will stay banned for good.

Boofo 03-03-2008 02:53 PM

Quote:

Originally Posted by NeuroLancer (Post 1455921)
I dont know what else to call it, someone or something in hong kong just visited many many times as 100 guests on my site all in the space of 2 mintues, kinda like they were sniffing around looking for a way in (where they should not be)......

Database has just been backed up.

Its sticks out because I know when a spider comes along, it has a specific behaviour... it doesnt just hit everything all at once, it moves around page to page one at a time... This thing whatever it was was very different.

My site is in development and does not quite get this many non spider hits in a day, let alone 2 minutes. Can anyone tell me if this is expected or unexpected behaviour for a very small forum to have in the usual day to day operations? :confused:


Next time you notice something like that, go to the Who'd Online page and do an IDENT display. (User Agent in the drop down box). Set it to yes, and display. The INDENTs will tell you if they are Spiders.

What happened to you could very well have been Spiders. I have that happen quite often. Not 100, but quite a few from the same place hitting all at the same time.

DivisionByZero 03-03-2008 09:31 PM

If you really wanna filter the bulls**t, the best thing you can do is block ENTIRE chinese and australian IP space. You can find the latest IP blocks for any given country here:

http://www.apnic.net/apnic-bin/ipv4-....pl?country=cn
http://www.apnic.net/apnic-bin/ipv4-....pl?country=au

Simply add these blocks to your IPtables rules and I GUARANTEE this will eliminate 99.9999% of the spam and foreign attacks. I do this as a rule. I have NO REASON to do business with anyone in China or Australia.

A more interactive way to achieve this is to install the GeoIP module for Apache. It looksup every hostname/IP in the GeoIP table and determines the country. You can then set rules based on visitor country.

NeuroLancer 03-03-2008 10:52 PM

Quote:

Originally Posted by Boofo (Post 1455986)
Next time you notice something like that, go to the Who'd Online page and do an IDENT display. (User Agent in the drop down box). Set it to yes, and display. The INDENTs will tell you if they are Spiders.

Thanks boofo ;) I did do that, they resolved as what appears to be a standard internet user.

Quote:

Originally Posted by MisterPopularity (Post 1456281)
If you really wanna filter the bulls**t, the best thing you can do is block ENTIRE chinese and australian IP space.

LOL, pineapples will grow in space before I filter my own country (Australia ;) ) but I appreciate the advice.

Boofo 03-03-2008 10:57 PM

The IDENT string can be tricky to read on some spiders. One spider that will always show as a guest is the Accoona spider. It's IDENT string shows as a normal user yet when you resolve the IP it shows up as a spider clear as day. So don't always go by that, just as a general rule.


All times are GMT. The time now is 07:11 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.02330 seconds
  • Memory Usage 1,737KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (6)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (9)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete