Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
Admin32
Regular
Regular



Joined: Sep 14, 2003
Posts: 74

PostPosted: Wed Jul 28, 2004 1:02 am Reply with quote

Good morning everyone,

I've just finished installing Sentinel on my site, replacing the IP Protector I've been using until now.

First impressions are quite good, so I though I'd give it a try and see how effective it is. I launched a program in attempt to leech my site, expecting Sentinel to catch me and block my IP, but this did not happen.

From what I understand, the havester part of sentinel works by examining the HTTP requests sent from the visitor to the server, and if it sees any information that shows a 'leeching' program (such as the ones in the list of the havester section), it will automatically take action.

The program I used, is called Aeria Leech 3.2, but was not detected by Sentiel. I checked my http logs and here they are :

Code:


212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /themes/smartDark/images/7px.gif HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /themes/smartDark/images/cellpic3.gif HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /pictures/headers/header-left.jpg HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /pictures/headers/header-right.jpg HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "HEAD /modules.php?name=Alternative_Menu HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "GET /coolmenu.css HTTP/1.0" 200 4035 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "GET /themes/smartDark/style/style.css HTTP/1.0" 200 4421 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "GET /images/blocks/group-2.gif HTTP/1.0" 200 996 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:23 +0300] "GET /images/blocks/group-4.gif HTTP/1.0" 200 996 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:23 +0300] "GET /themes/smartDark/images/7px.gif HTTP/1.0" 200 817 "-"


As you can see, there is no information on what agent/program is being used to leech the site, and therefore I gather that Sentiel is unable to successfully 'catch' it.

The older Protector module I used, did in fact have customisable settings such as 'pages per second' and more, to help the system 'find' a leecher according to his download patterns and this did work quite well.

My question is does Sentinell have any such settings to successfully catch leechers or does it only rely on the http requests to stop leechers from abusing our sites?

Thanks for hearing me out! Smile

_________________
___________________
Chris Partsenidis
Founder & Senior Editor [ Only registered users can see links on this board! Get registered or login! ]
___________________ 
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Wed Jul 28, 2004 4:59 am Reply with quote

As we stated before, Sentinel is designed to protect a site from exploitable attacks, like SQL Injections and XSS attacks. We have purposely avoided trying to be an all-in-all to avoid bloat and response degredation. Having said that, we will look into this as a possible functionality for a future version. Thanks!

BTW, your email address is being rejected. Please verify and/or correct it
 
View user's profile Send private message
BobMarion
Former Admin in Good Standing



Joined: Oct 30, 2002
Posts: 1037
Location: RedNeck Land (known as Kentucky)

PostPosted: Wed Jul 28, 2004 10:22 am Reply with quote

We have considered a "Hammer Protector" but felt it would be too query intense (slowing site load times) and causing a ton of bloat.

Now with that have you noticed how many of the lines from your log have a "Request Method" of HEAD? You can block the use or the HEAD request method by adding it to your "Request Blocker" list.

_________________
Bob Marion
Codito Ergo Sum
http://www.nukescripts.net 
View user's profile Send private message Send e-mail Visit poster's website
Admin32







PostPosted: Wed Jul 28, 2004 1:40 pm Reply with quote

Thanks for your reply guys,

I'm hoping to see you implement the feture as an additional option for those who are willing to add a small delay on the site's generation time, to save them from having their site leeched and watching that bandwidth meter hit the roof!
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©