vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Specific bot (https://vborg.vbsupport.ru/showthread.php?t=324516)

RSprinkel 02-23-2017 10:01 PM

Specific bot
 
1 Attachment(s)
Hello all,

Sorry if this is not the place to post, but I am currently running a new Gaming community and we have had a few bots register. I have since banned a few IP's and mail servers like .ru and .yandex. I have created a robots.txt file as well. Anyway I banned one user that I though was a bot. I have noticed he has been on the site many times and seeing the "Viewing 'No Permission' Message" and the one IP I added to Ban User section in options his IP showed to be the same. I have since deleted his account via admin section and now I am seeing him accessing the site with many variations of this IP info:

107-172-195-39-host.colocrossing.com
107-172-205-106-host.colocrossing.com
107-173-224-144-host.colocrossing.com
Etc. this host.colocrossing.com is showing for guest over 14 times at a time on my whos online.

Anyway I can block all of this? I have many spambot mods from vBulletin.org installed as well as Spam o Matic and still having issues with this bot or bots. Attached is an image of what I am seeing all the time.

Your help would be greatly appreciated.

Forgot to mention I am using VB 4.2.3.

Dave 02-23-2017 11:37 PM

It's very well possible that it's a (small) DDoS attack. Simply said, there's no way to stop it without getting DDoS protection or flood protection. Actually stopping proxies and IP addresses that belong to hosting companies is also very difficult.

RSprinkel 02-24-2017 09:48 PM

Hello Dave,

Thanks for your reply. I sent in a support ticket where I have my VPS and they looked at my files and saw no signs of DDos attacks. I do have DDos protection on my site and I think flood protection too. Today I come home and I see I have 40 guests online which 3 were Google bots, the rest from those IPs that are in the image. I don't know what to do get stop this crap.

Again thanks for your reply

Dave 02-24-2017 10:12 PM

If the IP addresses are mostly in the 107.172.*.* range then you can try to block that IP range but just keep in mind that it's possible that you block legitimate traffic/users that way.

Kane@airrifle 02-25-2017 08:31 AM

1 Attachment(s)
In my experience no good traffic ever comes from Colocrossing and their allies. Attached is my block list, it has not been updated for the most recent address blocks but it should suffice.

RSprinkel 02-25-2017 11:35 AM

Dave, thanks again for your reply. Yup I know about blocking ranges. I guess thats the chance I will have to take.

Kane, Thanks for your reply and your information, its good to know. Very much appreciate your block list. I will have to add the other IP's to it later.

Again thanks all for the info, very much appreciated.

Snowhog 02-26-2017 11:22 PM

Look at installing ZB Block (see the link in my signature). It is an outstanding solution to protecting ones forum from spam/spammers. We have been using it on our vBulletin forum since 2012, and spam/spammers are as rare as hens teeth for us.

Kane@airrifle 02-27-2017 06:32 AM

Quote:

Originally Posted by Snowhog (Post 2582947)
Look at installing ZB Block (see the link in my signature). It is an outstanding solution to protecting ones forum from spam/spammers. We have been using it on our vBulletin forum since 2012, and spam/spammers are as rare as hens teeth for us.

I use it too and it is excellent at what it does. However, it is not a Vbulletin mod and does not integrate so certain tasks you do in ACP or even on the board itself, will trigger a SQL injection attack (among others) block, thread titles that contain wildcard characters too.

That said, you can tune the signature file to suit your needs.

Snowhog 02-27-2017 04:19 PM

Quote:

Originally Posted by Kane@airrifle (Post 2582958)
I use it too and it is excellent at what it does. However, it is not a Vbulletin mod and does not integrate so certain tasks you do in ACP or even on the board itself, will trigger a SQL injection attack (among others) block, thread titles that contain wildcard characters too.

That said, you can tune the signature file to suit your needs.

I've simply taken to turning ZB Block off temporarily when I have something that needs doing either in the AdminCP or from a SSH konsole connection that would trigger a false positive. When I'm done, I turn it on again.

Before we installed ZB Block, I was cleaning up spam and spam accounts every day, and the number of such was increasing, and that was, even then, with Spam-O-Matic installed. After installing ZB Block, the number of spam accounts that got registered (and as a consequence, spam posts) went to practically zero. I'm a firm believer in ZB Block. It simply works.


All times are GMT. The time now is 12:37 AM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01057 seconds
  • Memory Usage 1,730KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote_printable
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (9)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete