PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
dad7732
Worker
Worker


Joined: Mar 18, 2007
Posts: 224

PostPosted: Thu May 29, 2008 4:30 am Reply with quote Back to top

NS 2.5.18

Ok, educate me here please ...

Was CLike attempted FOUR times by the same IP: 89.249.160.180 for you folks that want to add this to your blocker.

What I don't understand is the timing:

1. 0428 CDT
2. 0429 CDT
3. 0429 CDT
4. 0430 CDT

My question is why isn't the IP blocked from attempts 2 thru 4 if the first attempt is "blocked"?? Is it a session thing where the hacker makes 4 quick attempts and THEN is blocked if he returns in a new session?

Cheers, Jay

BTW: Obviously not going to publish the method but it was two different strings that was tried twice each.
View user's profile Send private message
dad7732
Worker
Worker


Joined: Mar 18, 2007
Posts: 224

PostPosted: Thu May 29, 2008 4:40 am Reply with quote Back to top

Ok, I'm back and I think I can answer my own question after some deep thought. Wink

The first attempt is intercepted because it's a CLike.

The second, third and fourth attempts are actually blocked by IP, not by the CLike string itself.

Is this correct ?

Cheers
View user's profile Send private message
jakec
Moderator


Joined: Feb 06, 2006
Posts: 1733
Location: United Kingdom

PostPosted: Thu May 29, 2008 5:39 am Reply with quote Back to top

What message is Sentinel giving you for each attempt?

Has the IP been written to the .htaccess file?

If the IP has been written to the .htaccess then the subsequent attempts should never get through to Sentinel.
View user's profile Send private message
dad7732
Worker
Worker


Joined: Mar 18, 2007
Posts: 224

PostPosted: Thu May 29, 2008 7:11 am Reply with quote Back to top

The message is the same from Sentinel, the only changes are the times and the script tried.

.htaccess

deny from 89.249.160

I'd have to look at the server log to see what actual time the deny was added. If it works correctly it should be on the first attempt. Also, the server log should show the subsequent attempts as well.

Same session attempts? If the hacker closed the session and tried again then the htaccess would deny the access. Dunno, guessing on this one.

Cheers
View user's profile Send private message
dad7732
Worker
Worker


Joined: Mar 18, 2007
Posts: 224

PostPosted: Thu May 29, 2008 7:29 am Reply with quote Back to top

Ok, here's your answer from the logs.

The first attempt was at 00:04:29 CDT after which the log shows over 150 attempts the last one being at 00:05:10 CDT

Note: The above are attempts shown in the main server log

The error log shows:

[Thu May 29 00:04:33 2008] [error] [client 89.249.160.180] client denied by server configuration: /[server path]/[my domain]/modules.php

This proves that the htaccess did it's job as the remaining 100 or so attempts showed the same error log entries for each attempt at access.

Also obvious that he was using a script as the attempts are literally fractions of a second apart.

Sentinel did it's job for sure !!!! Smile

Cheers
View user's profile Send private message
jakec
Moderator


Joined: Feb 06, 2006
Posts: 1733
Location: United Kingdom

PostPosted: Thu May 29, 2008 1:10 pm Reply with quote Back to top

Great analysis. It good to show that Sentinel does its job. Smile
View user's profile Send private message
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2795

PostPosted: Thu May 29, 2008 6:20 pm Reply with quote Back to top

It is possible that .htaccess hasn't been written to yet, before Apache processes the next 3 requests. Such automated scripts make requests in quick succession, there isn't really anything you can do about it. At least Sentinel is working Smile
View user's profile Send private message Visit poster's website
dad7732
Worker
Worker


Joined: Mar 18, 2007
Posts: 224

PostPosted: Fri May 30, 2008 7:25 am Reply with quote Back to top

evaders .. that's exactly it, the time lag. But like I emphasized, NS is working up to snuff. Wink

Cheers
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum