Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
Digital-Overload
Hangin' Around



Joined: May 13, 2005
Posts: 26

PostPosted: Sat Oct 15, 2005 9:21 pm Reply with quote

A User That I Know is Not a Hacker Keeps Getting, IP Was Confirmed By the Person, and I've Been Emailing Back and forth, and the person gets added immediately after i take the IP off the list...

This started happening to the person about a week ago..
ISP = Earthlink

Date & Time: 2005-10-14 21:25:53 Pacific Daylight Time GMT -0700
Blocked IP:
User ID: Anonymous (1)
Reason: Abuse-HarvestString Match: joc--------------------
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; iebar; acc=jocker; acc=none; .NET CLR 1.1.4322)
Query String: [ Only registered users can see links on this board! Get registered or login! ]
Get String: [ Only registered users can see links on this board! Get registered or login! ]
Post String: [ Only registered users can see links on this board! Get registered or login! ]
For: 4.152.210.65
Client IP: noneRemote
Address: 207.69.139.142
Remote Port: none
Request Method: GET

And Gets A Permanent Ban, I Remove the IP Address from the Database and It Re-Adds It,

What Is Causing this?

Ie.. a Virus or Something? (ie. Jocker.exe) [guessing since acc=jocker is present]
 
View user's profile Send private message
kguske
Site Admin



Joined: Jun 04, 2004
Posts: 6432

PostPosted: Sat Oct 15, 2005 10:55 pm Reply with quote

Did you have him/her try a different browser? You might also suggest the user run a virus check on that system.

_________________
I search, therefore I exist...
nukeSEO - nukeFEED - nukePIE - nukeSPAM - nukeWYSIWYG
 
View user's profile Send private message
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Sat Oct 15, 2005 10:55 pm Reply with quote

You ask what is causing this. Your email tells you very clearly
Reason: Abuse-HarvestString Match: joc--------------------

If you look in your NukeSentinel Blocker Configuration you will find an entry for joc web spider under Harvester Blocker Settings. Remove it at your own risk - probably very small.
 
View user's profile Send private message
Digital-Overload







PostPosted: Sun Oct 16, 2005 10:07 am Reply with quote

K, I Will Tell the Person to Run Virus Scan First,
I Dont know What "ACC=JOCKER" is.. But Google Gave me Positive results for Earthlink+Joc Webspider

thanks....
 
Digital-Overload







PostPosted: Mon Oct 17, 2005 11:23 am Reply with quote

Raven,

Would Adding 4.152.210.0 ->< 4.152.210.255 To Protected IP Range Let the User have access without Disabling any Secuirity Options?
 
Raven







PostPosted: Mon Oct 17, 2005 11:34 am Reply with quote

Yes, but if his IP changes due to DHCP outside of that range then he will still have issues.
 
Digital-Overload







PostPosted: Mon Oct 17, 2005 12:39 pm Reply with quote

so far all the IPs the user has, have been in that range (4.152.210.xxx), so.. its temp fix for now, the user has run dozens of virus / anti spyware scans, and still gets blocked regardless of using IE Mozilla/Firefox etc, is there a particular Program Name Causing this?

also, if i turned Off the Jocker Harvest Blocker Would would be the Risks? ie, what could someone do...

you've been a tremendous help and Sentinel has Blcoked well over 100 admin abusers and stuff in the short 4 or 5 months i've been running it..
 
Raven







PostPosted: Mon Oct 17, 2005 2:14 pm Reply with quote

If he is still being blocked after all that, then have him clear his cache and delete all cookies. Also, if he is using Zone Alarm or Norton make sure that they are not interferring at the firewall level.
 
Digital-Overload







PostPosted: Mon Oct 17, 2005 7:11 pm Reply with quote

thanks, lmao, you were right, I add IP range to protected list and the IP Shifts a Little when she comes back, yeesh,

so what would disabling Joc Web Spider Harvest Open Me Up To?

Thanks IN Advance, You've been a Tremendous Help..
 
Raven







PostPosted: Mon Oct 17, 2005 7:15 pm Reply with quote

Maybe nothing but a little bandwidth. Google on Joc Web Spider and read what it's all about and then just make the call.
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©