Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Other - Chit Chat
Author Message
hitwalker
Sells PC To Pay For Divorce



Joined:
Posts: 5661

PostPosted: Mon Jun 12, 2006 5:44 pm Reply with quote

everybody with My_eGallery ,heavy attacks are going on at this moment.
doesnt mean your next but be warned...
they tried about 80 x by now...
but i dont have My_eGallery....lol

target is ....My_eGallery/public/displayCategory.php?basepathxxxxx etc..
 
View user's profile Send private message
kguske
Site Admin



Joined: Jun 04, 2004
Posts: 6437

PostPosted: Mon Jun 12, 2006 7:04 pm Reply with quote

I've seen than on sites that have neither Nuke nor My_eGallery. Pretty pathetic, really. I mean, do a little research! I've thought about putting a honeypot on some sites. Just goes to show that kids have nothing better to do in the summer!

_________________
I search, therefore I exist...
Only registered users can see links on this board! Get registered or login!
 
View user's profile Send private message
kenwood
Worker
Worker



Joined: May 18, 2005
Posts: 119
Location: SVCDPlaza

PostPosted: Tue Jun 13, 2006 12:35 am Reply with quote

The same here and al lot of attacks on 4nalbum and coppermine and sins 2 days Forums/admin/index.php?phpbb_root_path and the all are from turkey.
 
View user's profile Send private message Visit poster's website
hitwalker







PostPosted: Tue Jun 13, 2006 4:02 am Reply with quote

yeah nice huh,got another 40 while i was sleeping..... Laughing
should i publish a news story "i dont have My_eGallery" ?
 
Susann
Moderator



Joined: Dec 19, 2004
Posts: 3191
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Tue Jun 13, 2006 8:24 am Reply with quote

That doesn´t help Hitwalker because nobody reads the story about your installed modules. The most attacks are more automatic therefore the Hackers will never visit you site. You know this also. Smile But if you ever had such a module installed there are probably after some years still links to your website on some search engines.

So "Think before you install !" if you really need this module, addon or whatever.
 
View user's profile Send private message
hitwalker







PostPosted: Tue Jun 13, 2006 9:13 am Reply with quote

ah susann...you missed the humor in my post... Sad
but i also never had My_eGallery installed...
that they do this by remote i know,topic was just to warn others...
 
Susann







PostPosted: Tue Jun 13, 2006 9:28 am Reply with quote

I ´m sure that topic helps some people in any way. Believe it or not I found a page and he published an admin message like" I don´t have such modules installed" however, sometimes it´s possible to talk back to hackers and it would be great if the phrase:" The hackers from today are the security experts from tomorrow" is really true.

The meaning of the word hacker we discussed already. Wink
 
djmaze
Subject Matter Expert



Joined: May 15, 2004
Posts: 727
Location: http://tinyurl.com/5z8dmv

PostPosted: Tue Jun 13, 2006 11:52 am Reply with quote

<?php
$ip = '216.255.189.226';
$host = gethostbyaddr($ip);
if (preg_match('#([a-z0-9_\-]+\.([a-z]{2,5}|[a-z]{2,3}\.[a-z]{2,3}))$#i',$host,$match)) {
mail($match[1],"one of your customers tried to hack our website using IP $ip on date $time");
}

good luck Laughing
 
View user's profile Send private message Visit poster's website
kguske







PostPosted: Tue Jun 13, 2006 12:12 pm Reply with quote

An interesting approach, djmaze. I think it would be more effective to try something like this when abuse occurs using a file hosted on another website...
 
kguske







PostPosted: Tue Jun 13, 2006 9:12 pm Reply with quote

There were at least 10 different sites hosting attacks on nukeSEO.com today. All standard script kiddie stuff - no creativity, all blocked, some of them tried the same attack 100 times - with various IP addresses (isn't blocking pointless?). We'll see how many of these sites are online tomorrow...

One interesting note, a couple of the attacks appeared to be hosted on legitimate sites that were themselves attacked unknowingly. The attack script was uploaded to these sites (e.g. through SPAW in one case!) without the owners realizing their sites were being used to launch attacks against other sites. I gave those owners a chance to fix the problem before I did...
 
hitwalker







PostPosted: Wed Jun 14, 2006 4:37 am Reply with quote

your so kind.... killing me
 
djmaze







PostPosted: Wed Jun 14, 2006 9:11 am Reply with quote

kguske wrote:
An interesting approach, djmaze. I think it would be more effective to try something like this when abuse occurs using a file hosted on another website...


Doesn't matter which kind of attack as long as the ip resolves to a hostname.
The mailed host wether a website or a ISP knows that something happens from their system either thru illegal scripts or just bad customers.
 
kguske







PostPosted: Wed Jun 14, 2006 9:19 am Reply with quote

Unless the IP is spoofed...
 
kguske







PostPosted: Wed Jun 14, 2006 10:56 am Reply with quote

Update: 5 of the 10 sites that attacked nukeSEO.com yesterday have already been shut down. One who was unwillingly hosting the attacks has secured his site. 4 more to go!
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> Other - Chit Chat

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©