Go Back   IceInSpace > General Astronomy > General Chat
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread
  #1  
Old 14-07-2006, 08:59 PM
Doug
Registered User

Doug is offline
 
Join Date: Mar 2006
Posts: 645
Forum under attack! But not Iceinspace.

Relax, not this one, or if it is I wouldn't know. I moderate a forum and it has been observed that certain IP addresses, not associated with registered members have been logged on as 'guests' But when I look at the area that tells me what they are doing, the system reports back that they are involved in an 'unknown activity'.
So I banned those IP addresses, with a note to email a certain address with an explanation of their activities before access might be resumed. Now, checking the 'banned log', I see that these ip addresses are hammering away trying to login day after day, with many attempts being every two minutes or so.
As for myself, I could print my entire knowledge of the workings of the internet on the point of a pin. I think there are many here though that would know, are there auto hacking programs that just keep pecking away, or is it likely that some low lifers are trying to defeat the ban?

Any informed ideas much appreciated.

Doug
Reply With Quote
  #2  
Old 14-07-2006, 09:03 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Are you sure they aren't seach bots from google et al? Some nights there are more bots wandering around this site than there are real people. Have a look on the Forum home page at the most users online any one night. The record is 393 and 90% of those were search bots .
Reply With Quote
  #3  
Old 14-07-2006, 09:08 PM
iceman's Avatar
iceman (Mike)
Sir Post a Lot!

iceman is offline
 
Join Date: Sep 2004
Location: Gosford, NSW, Australia
Posts: 36,799
Paul's probably right. Search bots are always trawling through the forum, clicking on every link. They often click on areas which guests can't see, like sending emails, sending PM's, and so they get the unauthorised message etc.

They're just gathering information for their search pages. You can stop them if you want to, do a search for robots.txt or check your forum admin system for other ways to stop them apart from banning the IP's.

They're generally not a problem unless you're strapped for bandwidth. Googlebot traffic on IceInSpace generates over 1.2Gigabytes of bandwidth every MONTH!
Reply With Quote
  #4  
Old 14-07-2006, 09:13 PM
Doug
Registered User

Doug is offline
 
Join Date: Mar 2006
Posts: 645
Paul, I have no idea. Some of them were left in peace for some time, one would think that they would have gleaned what info they wanted and departed?? Maybe not. It is a worthwhile thought though, can I trace back from the ip and perhaps find ot if someone like google or sensis or, or is back of it? It would be good for the forum if it was listed, but I just dont want hackers.

regards,
Doug
Reply With Quote
  #5  
Old 14-07-2006, 09:23 PM
iceman's Avatar
iceman (Mike)
Sir Post a Lot!

iceman is offline
 
Join Date: Sep 2004
Location: Gosford, NSW, Australia
Posts: 36,799
Quote:
would think that they would have gleaned what info they wanted and departed??
They do, but they always come back!

You can find out where they came from, some forum systems will show you where the search bots come from when you look at the "who's online".

If you look at your server stats (awstats, webalizer etc), there'll also be a section for search-engine traffic.
Reply With Quote
  #6  
Old 14-07-2006, 09:50 PM
Doug
Registered User

Doug is offline
 
Join Date: Mar 2006
Posts: 645
Thanks Mike and Paul. Man I feel stupid, but my excuse is ignorance

They are seach bots; 2 were google and 4 were msnbots.
I can't check the robot.txt as far as I can see, I'll need to talk to the guy with admin rights...I just run round with an axe
Thanks for your avice, Paul if you want to hit 'delete' I can be a good spp..sp...spo..its ok be me.

cheers,
Doug
Reply With Quote
  #7  
Old 14-07-2006, 10:03 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778


No I'll leave it as its information that could be useful to someone at some stage. I was in the same boat once upon a time, until Mike and Terry started to straightened me out and teached me enough techo stuff to keep me out of trouble. They have the patience of saints
Reply With Quote
  #8  
Old 15-07-2006, 11:18 AM
Dujon's Avatar
Dujon
SKE

Dujon is offline
 
Join Date: Jun 2006
Location: Blaxland, N.S.W.
Posts: 634
I had a similar problem with a site that was hosted by a free-host. Ask Jeeves bots decided to land on the site and ate up all my bandwidth causing it to be shutdown for days.

After tracing the mongrel I sent AJ a rather ascerbic e-mail, polite but nevertheless forceful. I don't know whether the mail did any good but it stopped. I also banned all the AJ DNS addresses I could find.

If you are keen enough there's a line of code that one can insert on your initial access page (I don't have it handy at the moment) of which well behaved bots will take note and burrow no further. Of course this only keeps the 'good guys' from munching up your available band width - the rest will do as they please.
Reply With Quote
  #9  
Old 15-07-2006, 10:42 PM
Doug
Registered User

Doug is offline
 
Join Date: Mar 2006
Posts: 645
My site, well the one I moderate is add free, it is part of some commercial site. The administrator has conferred with his IT and he has advised that the ones sofar are safe to play with. They are going to checkout the permission codes or whatever....robot.txt. It is just a huge relief to know that it is not a hacker pecking away at the site.
Cheers,
Doug
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 09:32 AM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Advertisement
Bintel
Advertisement