PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
ms_combatmedic
New Member
New Member


Joined: May 15, 2006
Posts: 12

PostPosted: Sun Sep 21, 2008 8:25 am Reply with quote Back to top

Over the last several weeks I have seen an increase in this manner of hacking - What are they trying for & should I worry?

Code:
Date & Time: 2008-09-20 20:33:30 CDT GMT -0500Blocked IP: 61.18.170.*User ID: Anonymous (1)Reason: Abuse-Filter--------------------Referer: noneUser Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Foxy/1; Foxy/1; Foxy/2; SINU/2; InfoPath.1)HTTP Host: mgcclan.comScript Name: /index.phpQuery String: ';DECLARE @S CHAR(4000);SET @S=CAST(0x4445434C415245204054207661726437572736F72 AS CHAR(4000));EXEC(@S);Get String: \';DECLARE_@S_CHAR(4000);SET_@S=CAST(0x4445434C4152452040542076617 AS CHAR(4000));EXEC(@S);Post String: Not AvailableForwarded For: noneClient IP: noneRemote Address: 61.18.170.114Remote Port: 39762Request Method: GET


Last edited by ms_combatmedic on Sun Sep 21, 2008 9:18 am; edited 1 time in total
View user's profile Send private message Visit poster's website
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3132
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Sun Sep 21, 2008 8:44 am Reply with quote Back to top

No this isn´t new. Just use the search and maybe try Gremmies .htaccess solution.
View user's profile Send private message Visit poster's website
ms_combatmedic
New Member
New Member


Joined: May 15, 2006
Posts: 12

PostPosted: Sun Sep 21, 2008 8:47 am Reply with quote Back to top

ok, thanks for your rapid reply - what is this script suppose to do if Sentinel didn't block it?
View user's profile Send private message Visit poster's website
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3132
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Sun Sep 21, 2008 8:58 am Reply with quote Back to top

This is a mass attack.
Check this:
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message Visit poster's website
ms_combatmedic
New Member
New Member


Joined: May 15, 2006
Posts: 12

PostPosted: Sun Sep 21, 2008 9:19 am Reply with quote Back to top

Susann - Am I understanding Gremmie, putting that fix into the .htaccess file?
View user's profile Send private message Visit poster's website
Susann
Moderator


Joined: Dec 19, 2004
Posts: 3132
Location: Germany:Moderator German NukeSentinel Support

PostPosted: Sun Sep 21, 2008 9:23 am Reply with quote Back to top

Yes, try it out.
View user's profile Send private message Visit poster's website
ms_combatmedic
New Member
New Member


Joined: May 15, 2006
Posts: 12

PostPosted: Sun Sep 21, 2008 9:30 am Reply with quote Back to top

Cheers!
View user's profile Send private message Visit poster's website
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 6299
Location: Vsetin, Czech Republic

PostPosted: Mon Sep 22, 2008 5:22 am Reply with quote Back to top

NS should block it but very often you will get two emails per attack as the attack is so fast, NS doesn't have time to execute the 'write the banned IP to htaccess' before the second one gets through.

I got sick of these and now block them at server level with mod_security
View user's profile Send private message Send e-mail Visit poster's website
ms_combatmedic
New Member
New Member


Joined: May 15, 2006
Posts: 12

PostPosted: Mon Sep 22, 2008 5:26 am Reply with quote Back to top

Guardian2003 wrote:
I got sick of these and now block them at server level with mod_security


How is this done? I tried what Susann suggested yesterday, but this morning I awoke to 4 emails ( 2 attacks )
View user's profile Send private message Visit poster's website
Guardian2003
Site Admin


Joined: Aug 28, 2003
Posts: 6299
Location: Vsetin, Czech Republic

PostPosted: Mon Sep 22, 2008 5:38 am Reply with quote Back to top

You need server level access so unless you have your own server or VPS you would not be able to use mod_security

If you do have that sort of access, then you can use
Code:

SecFilterSelective REQUEST_URI "DECLARE @S CHAR\(4000\)"
View user's profile Send private message Send e-mail Visit poster's website
dad7732
RavenNuke(tm) Development Team


Joined: Mar 18, 2007
Posts: 1174

PostPosted: Wed Oct 08, 2008 7:40 am Reply with quote Back to top

Use to get over 100 per day. After adding the blocker to .htaccess I get ZERO now. IT WORKS !!!
View user's profile Send private message
ms_combatmedic
New Member
New Member


Joined: May 15, 2006
Posts: 12

PostPosted: Wed Oct 08, 2008 8:51 am Reply with quote Back to top

Thanks dad7732! I will try that as well.
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum