PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
gregexp
The Mouse Is Extension Of Arm


Joined: Feb 21, 2006
Posts: 1465
Location: In front of a screen....HELP! lol

PostPosted: Fri Apr 06, 2007 11:18 am Reply with quote Back to top

You know, I've been thinking about this, what do you all think about allowing useragents only, Like get a standard list of user agents, like explorer, firefox and what not as well as search engines.

Then using .htaccess, only allowing standard users-agents and search engines?

Reason I say this, In my time away, I've had to research a LOT of security issues with web based applications. One thing I remember reading from a lot of different sources is that hackers will use a program, ussually a legit one, like Acunetix Web vulnerability scanner, These tools can scan the entire directory of a website and after testing a few, Acunetix seems to be the most aggresively accurate one, but also seems to disregard anything other then .htaccess which simply kills it in its tracks. So to recap, only allowing legitimate user agents and search engine agents we want, could help prevent the intrusion of hackers against legitimate web applications that could be used to harm a site or entire system.
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
kguske
Site Admin


Joined: Jun 04, 2004
Posts: 4624

PostPosted: Fri Apr 06, 2007 11:38 am Reply with quote Back to top

One problem with that approach - really more of a limiting factor - is that user agents can be spoofed.
View user's profile Send private message
kguske
Site Admin


Joined: Jun 04, 2004
Posts: 4624

PostPosted: Fri Apr 06, 2007 11:39 am Reply with quote Back to top

But...a honeypot approach could make it effective...
View user's profile Send private message
gregexp
The Mouse Is Extension Of Arm


Joined: Feb 21, 2006
Posts: 1465
Location: In front of a screen....HELP! lol

PostPosted: Fri Apr 06, 2007 2:44 pm Reply with quote Back to top

honeypot?
hmmm.

I was thinking that limiting yes, and it would need to probably be continually updated, which could be a security threat in itself.

I guess this idea isnt a bad one, but could use some more insight.
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 4557
Location: Poland

PostPosted: Fri Apr 06, 2007 2:51 pm Reply with quote Back to top

The idea of honeypots is basically a link in robots.txt which a bot is told to ignore. When it tries to access the link its referer data is recorded.
The same could be ised within a directory structure where an extra file is added inside the directory which is not linked to anything. If the link is found, someone will try to access it......
View user's profile Send private message Send e-mail Visit poster's website
gregexp
The Mouse Is Extension Of Arm


Joined: Feb 21, 2006
Posts: 1465
Location: In front of a screen....HELP! lol

PostPosted: Fri Apr 06, 2007 3:05 pm Reply with quote Back to top

nice, they call that honeypot?

Well I suppose it works, but if this were people we'd call it entrapment!!

:evil laugh:
I may not be able to do it to a real person but common bots, Imma get you!! lol

sounds like a workable idea.
Thanks for the input.
View user's profile Send private message Send e-mail Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 4557
Location: Poland

PostPosted: Fri Apr 06, 2007 4:41 pm Reply with quote Back to top

A very simple thing I did last year because of new bots was to place a link in robots.txt i.e. disallow: /theurlhere.html
The link was actually an a known exploit path that would trip Sentinel haha.
View user's profile Send private message Send e-mail Visit poster's website
persona_non_grata



Joined:
Posts: 0

PostPosted: Fri Apr 06, 2007 5:33 pm Reply with quote Back to top

lol...thats sneaky guardian... killing me
View user's profile Send private message
Susann
Spouse Contemplates Divorce


Joined: Dec 19, 2004
Posts: 2102
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Fri Apr 06, 2007 6:04 pm Reply with quote Back to top

Darklord nice idea but generally that doesn´t work because every idiot can change the user agent.htaccess is power and I´m sure you can use there easily rules for search engines, Ips etc.. I added one user agent into the nuke sentinel blocker, because thats a user agent which was often used by turkish hackers.
And that did the trick. Of course I don´t tell anyone whats the name of this UA.
View user's profile Send private message Visit poster's website
montego
Site Admin


Joined: Aug 29, 2004
Posts: 7236
Location: Arizona

PostPosted: Sat Apr 07, 2007 8:40 am Reply with quote Back to top

Guardian2003 wrote:
A very simple thing I did last year because of new bots was to place a link in robots.txt i.e. disallow: /theurlhere.html
The link was actually an a known exploit path that would trip Sentinel haha.


Just a side note, it is funny that I have this in place, and no bot has ever gotten banned. If you are finding this banning bots on your site, then I must not have it right.. Sad
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum