vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   register.php being attacked (https://vborg.vbsupport.ru/showthread.php?t=296639)

jo-jo 03-29-2013 05:19 PM

register.php being attacked
 
I've had to turn registration off on my vBulletin because someone is hammering away at register.php, and eating up bandwidth. In just 12 days they ran up 380GB of bandwidth.

I was running 4.0.3; upgraded to 4.2, and have tried .htaccess, and vB Bad Behaviour to no avail.

How can I stop this malicious attack?

TheLastSuperman 03-29-2013 05:30 PM

They are more than likely using some type of program such as xRumer or similar...

Check your logs, also check your session table, see if there are similar ip's trying to register at the same time.

Once you find out the ip or several ip addresses simply ban them via htaccess, you may also want to contact your host about this to see if they have any server level alternatives depending on your hosting account type.

I've seen this before, using some methods outlined here I was able to reduce this then the clients host helped as well - https://vborg.vbsupport.ru/showthread.php?t=276547 scroll down to find "Session Table Issues?" and see if that helps.

jo-jo 03-29-2013 11:45 PM

Thank you for the response. :)

A lot of that is gibberish to me though. I'll have to set aside another day to try and learn up on this stuff.

This is so incredibly frustrating. Especially since my site is a hobby site that I offer up to the local community (Island4x4 dot com). The site doesn't generate a lot of revenue. Mainly just pays the hosting bills. I'd say I make about 10 cents an hour administrating it.

Starting to regret the day I installed vBulletin. :(

Someone needs to invent a way to send an electric shock across the Internet for these unscrupulous types. They are driving me insane.

jo-jo 04-05-2013 06:39 AM

It appears that the main culprit(s) was coming from IE6 browser. I had 89,000 hits on register.php in 3 days. I've blocked IE6 users, and am now down to about 300-400 hits on that file in the same time frame.

ForceHSS 04-05-2013 07:51 AM

<a href="https://vborg.vbsupport.ru/showthread.php?t=294164" target="_blank">www.vbulletin.org/forum/showthread.php?t=294164</a>


All times are GMT. The time now is 06:51 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01064 seconds
  • Memory Usage 1,718KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (5)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete