PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Muffin
Client


Joined: Apr 10, 2004
Posts: 649
Location: UK

PostPosted: Sun Dec 26, 2004 9:19 am Reply with quote Back to top

lol I didnt think it could be that simple so didnt do it doh!

There was me looking for a complicated solution

Thanks Raven.

Hope my dumbness helps lots of others like me (thats my way of getting out of being a real thicko at this lol)
View user's profile Send private message
Muffin
Client


Joined: Apr 10, 2004
Posts: 649
Location: UK

PostPosted: Sun Dec 26, 2004 10:24 am Reply with quote Back to top

ermm Raven do we need to put

RewriteEngine on (at the beginning)
and

RewriteEngine Off (at the end of the new code?)
View user's profile Send private message
Viper-
New Member
New Member


Joined: Dec 24, 2004
Posts: 5

PostPosted: Sun Dec 26, 2004 10:35 am Reply with quote Back to top

Place RewriteEngine on at the very top of your .htaccess file, I wouldn't worry about RewriteEnging Off, just leave that out altogether.

Also, if it would help you, I can talk to you on one of the IM services and fix your .htaccess file up for you Smile

Viper
View user's profile Send private message Visit poster's website
Muffin
Client


Joined: Apr 10, 2004
Posts: 649
Location: UK

PostPosted: Sun Dec 26, 2004 12:29 pm Reply with quote Back to top

Hi Viper

Thanks I'll put that back in then cos I'm getting loads of emails again from Sentinel since I left the rewrite engine bit off the code.

If I get stuck I'll get back to you here, thanks for offering, much appreciated.
View user's profile Send private message
tango
New Member
New Member


Joined: Dec 26, 2004
Posts: 3

PostPosted: Sun Dec 26, 2004 4:55 pm Reply with quote Back to top

Sorry Raven I am little be confused

In the last 3 days my sentinel 2.1.2 blocked about 100 ips for day and I received 300 email like this, buth with different ip Smile

Date & Time: 2004-12-26 23:50:25
Blocked IP: 69.72.230.138
User ID: Anonymous (1)
Reason: Abuse-Script
--------------------
User Agent: lwp-trivial/1.41
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

Forwarded For: none
Client IP: none
Remote Address: 69.72.230.138
Remote Port: 36273
Request Method: GET
-------------------------------------------------------


Date & Time: 2004-12-26 23:46:37
Blocked IP: 193.178.158.26
User ID: Anonymous (1)
Reason: Abuse-Script
--------------------
User Agent: LWP::Simple/5.64
Date & Time: 2004-12-26 23:46:37
Blocked IP: 193.178.158.26
User ID: Anonymous (1)
Reason: Abuse-Script
--------------------
User Agent: LWP::Simple/5.64
Query String:
Only registered users can see links on this board!
Get registered or login to the forums!

Forwarded For: none

----------------------------------

I read all topics befor write this message, about the Worm, about the Agent and about the rewrite, but I am little be confused.

I am under attack ? or it is a new agent/spiders not tratted correctly buy Sentinel ?
I read your fix in .Htaccess but I don't have the mod rewrite installed.

Could you explain me How fix this problem in simply words please

Thanks in advance
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Sun Dec 26, 2004 5:15 pm Reply with quote Back to top

NukeSentinel traps it, but mod_rewrite is a way to stop it before it ever reaches your site. If your host doesn't offer mod_rewrite then they are ages behind. Seriously, I woul try to change hosts. it's so simple to install.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
tango
New Member
New Member


Joined: Dec 26, 2004
Posts: 3

PostPosted: Sun Dec 26, 2004 5:19 pm Reply with quote Back to top

k thanks sorry for my host lol Smile

But is the only whay to stop it ????

Are dangerus hack attack ????
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Sun Dec 26, 2004 5:21 pm Reply with quote Back to top

NukeSentinel is stopping it, like I said. Yes, it is dangerous but so far, not to worry.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
tango
New Member
New Member


Joined: Dec 26, 2004
Posts: 3

PostPosted: Sun Dec 26, 2004 5:43 pm Reply with quote Back to top

k thanks a lot !
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Mon Dec 27, 2004 12:05 am Reply with quote Back to top

hey dont thank me man i thank you Smile all i did was trying to see if it made a diff ...and it did i copy and pasted your code and moved the options-index to the bottom with a few spaces in between the pasted code and wa la no emails today ,thanks so much for you being here ....i will update to the code posted above ..it seems the user agent has been all the same (LWP) i must of just misread and thought it was diff. on one of several i was checking out...is this what you are referring to as the redirect url ?
Quote:
RewriteRule ^.*$ emailsforyou.php [L]


HAPPY HOLIDAYS

P.s
from this post
Quote:
Posted: Sun Dec 26, 2004 3:17 pm


to this Posted: Mon Dec 27, 2004 4:05 pm i still sit at 633 blocked Cheers Wave

hmm seems i need to change the time in my profile its actually 1:15 am
View user's profile Send private message
mds
Client


Joined: Dec 24, 2004
Posts: 194
Location: Michigan

PostPosted: Mon Dec 27, 2004 12:52 am Reply with quote Back to top

never mind the redirect question found the answer in your sticky Embarassed
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Dec 27, 2004 5:01 am Reply with quote Back to top

Great! I appreciate your support Wink
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cprompt
Regular
Regular


Joined: Jun 08, 2004
Posts: 64

PostPosted: Mon Dec 27, 2004 7:22 am Reply with quote Back to top

I have been hit by two more

Code:
RewriteCond %{REQUEST_URI} ^envidiosos                [NC,OR]

RewriteCond %{REQUEST_URI} ^civa                [NC,OR]


civa.org and envidiosos.org

visualcoders domain has been suspended.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16986
Location: Kansas

PostPosted: Mon Dec 27, 2004 7:28 am Reply with quote Back to top

Thanks!
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
cprompt
Regular
Regular


Joined: Jun 08, 2004
Posts: 64

PostPosted: Mon Dec 27, 2004 8:08 pm Reply with quote Back to top

Here's another compromised site by LW::Simple
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum