well it all depends to what kind of connection he has,dyn or static..
and believe me...if they are good enough to hack your site they wont be stupid enough to use their own ip.
good step is to set the proxy blocker to on.
but also has consequences...
Joined: Dec 24, 2004 Posts: 194 Location: Michigan
Posted:
Wed Jun 08, 2005 10:14 am
Raven wrote:
mds, Thanks! And keep in mind there's a good chance that he spoofed the IP, but I always send the reports in anyway
right, i thought of this as well..
persona_non_grata wrote:
well it all depends to what kind of connection he has,dyn or static..
and believe me...if they are good enough to hack your site they wont be stupid enough to use their own ip.
good step is to set the proxy blocker to on.
but also has consequences...
can you give me an example of the consequences ?
also , i know its off topic from the rest of the thread but as of bbtonuke version 2.0.13 or so, wasnt the update supposed to take the forum version out of the footer / copyright area ? mine still shows...2.0.14....
well some people without any bad things in mind use a procy or its simple the provider...
as for turning the proxy on will result in banning the person or redirecting them.
Joined: Jun 06, 2005 Posts: 7 Location: Oregon, USA
Posted:
Thu Jun 09, 2005 2:22 am
No problem. Yea, after finding that IP I was aware of being visited frequently in the past by the same guy... Doh! Had I only known... lol
Oh well, live and learn I guess.
EDIT: Oops, missed this second page! lol Yea, the IP could easily be spoofed, although I have recieved about 50 hits on my banned page redirect setup from those IPs already, so...
Last edited by TheLoneInventor on Thu Jun 09, 2005 1:33 pm; edited 1 time in total
Joined: Dec 24, 2004 Posts: 194 Location: Michigan
Posted:
Sat Jun 11, 2005 9:28 am
well it looks like they tried to hack again heres the email and the ip lookup info this they were caught and blocked :
Date & Time: 2005-06-10 12:08:50 PDT GMT -0700
Blocked IP: 81.215.140.100
User ID: Anonymous (1)
Reason: Abuse-Author
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Query String:
Only registered users can see links on this board! Get registered or login to the forums!
Get String:
Only registered users can see links on this board! Get registered or login to the forums!
Post String:
www.XXX.com/admin.php?admin=eCcgVU5JT04gU0VMRUNUIDEvKjox&add_radminsuper=1&op=mod_authors&Submit=Display
Forwarded For: none
Client IP: none
Remote Address: 81.215.140.100
Remote Port: 1229
Request Method: POST
Location: Turkey (high)
% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Note: the default output of the RIPE Whois server
% is changed. Your tools may need to be adjusted. See
%
Only registered users can see links on this board! Get registered or login to the forums!
% for more details.
%
% Rights restricted by copyright.
% See
Only registered users can see links on this board! Get registered or login to the forums!
% Information related to '81.215.128.0 - 81.215.143.255'
Joined: Dec 24, 2004 Posts: 194 Location: Michigan
Posted:
Sun Jun 12, 2005 10:03 am
and tried again
Date & Time: 2005-06-12 02:44:31 PDT GMT -0700
Blocked IP: 85.96.71.187
User ID: Anonymous (1)
Reason: Abuse-Union
--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1;
FunWebProducts)
Query String:
Only registered users can see links on this board! Get registered or login to the forums!
pm.privmsgs_type=-99 UNION SELECT
aid,null,pwd,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null
FROM nuke_authors WHERE radminsuper=1 LIMIT 1/*
Get String:
Only registered users can see links on this board! Get registered or login to the forums!
pm.privmsgs_type=-99 UNION SELECT
aid,null,pwd,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null
FROM nuke_authors WHERE radminsuper=1 LIMIT 1/*
Post String:
Only registered users can see links on this board! Get registered or login to the forums!
Joined: Nov 24, 2004 Posts: 131 Location: Batesville, AR
Posted:
Wed Jun 15, 2005 1:11 pm
TheLoneInventor wrote:
65.19.134.2 - is the one I believe was used to hack the site, through the forums by the look of it. 2608 URLs were hit by this IP from the kralkayra username.
That IP is familiar...
65.19.169.235 was used on my site
Joined: Dec 19, 2004 Posts: 2273 Location: Germany:Moderator German NukeSentinel Support
Posted:
Thu Jun 23, 2005 7:30 am
65.19.169.235 OmniExplorer_Bot/1.07 (+http://www.omni-explorer.com) Internet Categorizer is one of the bad bots doesn´t read robots.txt using different Ip´s and I heard also about different User Agent Strings.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum