PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
vaudevillian
Worker
Worker


Joined: Jan 18, 2008
Posts: 139

PostPosted: Mon Jun 02, 2008 9:24 am Reply with quote Back to top

I have been under attack from a website
Only registered users can see links on this board!
Get registered or login to the forums!
for the past few weeks. The ip keeps changing as well.

They are always trying to access my foum prune. It is getting a little annoying.
View user's profile Send private message Send e-mail
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Mon Jun 02, 2008 3:51 pm Reply with quote Back to top

I don't know why they would go for forum prune. Do you have an example of such attacks?
View user's profile Send private message Visit poster's website
vaudevillian
Worker
Worker


Joined: Jan 18, 2008
Posts: 139

PostPosted: Mon Jun 02, 2008 8:28 pm Reply with quote Back to top

next attack I will post the code and the info relating to it.
View user's profile Send private message Send e-mail
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3143
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Tue Jun 03, 2008 9:14 am Reply with quote Back to top

These attacks are nothing special and doesn´t work. Search for libwww-perl
and maybe try this in your .htaccess



Quote:
RewriteEngine on
RewriteCond %{HTTP_USER_AGENT} ^libwww-perl/[0-9].[0-9]*
RewriteRule ^.*$
Only registered users can see links on this board!
Get registered or login to the forums!
[R,L]
View user's profile Send private message Visit poster's website
vaudevillian
Worker
Worker


Joined: Jan 18, 2008
Posts: 139

PostPosted: Tue Jun 03, 2008 9:56 am Reply with quote Back to top

Does that block all perl agents?
View user's profile Send private message Send e-mail
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3143
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Tue Jun 03, 2008 10:32 am Reply with quote Back to top

R = redirect

I don´t get notifications but I see these agents in my logs.
View user's profile Send private message Visit poster's website
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Tue Jun 03, 2008 12:31 pm Reply with quote Back to top

It should block most dumb Perl scripts that don't forge a User-Agent. Smile
View user's profile Send private message Visit poster's website
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1191

PostPosted: Sun Jul 13, 2008 10:29 am Reply with quote Back to top

Add this to your .htaccess and it will stop most scripts from getting in.

Code:

# Stop Scripts Beforehand
RewriteEngine On
RewriteCond %{THE_REQUEST} .*http:\/\/.* [OR]
RewriteCond %{THE_REQUEST} .*http%3A%2F%2F.*
Rewriterule ^.* - [F]


Been a long time since I've seen Sentinel block a script because of the above entry.

Cheers
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum