PHP Web Host - Quality Web Hosting For All PHP Applications Sign up for PayPal and start accepting credit card payments instantly
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
Admin32
Regular
Regular


Joined: Sep 14, 2003
Posts: 74

PostPosted: Wed Jul 28, 2004 1:02 am Reply with quote Back to top

Good morning everyone,

I've just finished installing Sentinel on my site, replacing the IP Protector I've been using until now.

First impressions are quite good, so I though I'd give it a try and see how effective it is. I launched a program in attempt to leech my site, expecting Sentinel to catch me and block my IP, but this did not happen.

From what I understand, the havester part of sentinel works by examining the HTTP requests sent from the visitor to the server, and if it sees any information that shows a 'leeching' program (such as the ones in the list of the havester section), it will automatically take action.

The program I used, is called Aeria Leech 3.2, but was not detected by Sentiel. I checked my http logs and here they are :

Code:

212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /themes/smartDark/images/7px.gif HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /themes/smartDark/images/cellpic3.gif HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /pictures/headers/header-left.jpg HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:21 +0300] "HEAD /pictures/headers/header-right.jpg HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "HEAD /modules.php?name=Alternative_Menu HTTP/1.0" 200 0 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "GET /coolmenu.css HTTP/1.0" 200 4035 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "GET /themes/smartDark/style/style.css HTTP/1.0" 200 4421 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:22 +0300] "GET /images/blocks/group-2.gif HTTP/1.0" 200 996 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:23 +0300] "GET /images/blocks/group-4.gif HTTP/1.0" 200 996 "-" "-"
212.205.59.20 - - [28/Jul/2004:09:34:23 +0300] "GET /themes/smartDark/images/7px.gif HTTP/1.0" 200 817 "-"


As you can see, there is no information on what agent/program is being used to leech the site, and therefore I gather that Sentiel is unable to successfully 'catch' it.

The older Protector module I used, did in fact have customisable settings such as 'pages per second' and more, to help the system 'find' a leecher according to his download patterns and this did work quite well.

My question is does Sentinell have any such settings to successfully catch leechers or does it only rely on the http requests to stop leechers from abusing our sites?

Thanks for hearing me out! Smile
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Jul 28, 2004 4:59 am Reply with quote Back to top

As we stated before, Sentinel is designed to protect a site from exploitable attacks, like SQL Injections and XSS attacks. We have purposely avoided trying to be an all-in-all to avoid bloat and response degredation. Having said that, we will look into this as a possible functionality for a future version. Thanks!

BTW, your email address is being rejected. Please verify and/or correct it
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Wed Jul 28, 2004 10:22 am Reply with quote Back to top

We have considered a "Hammer Protector" but felt it would be too query intense (slowing site load times) and causing a ton of bloat.

Now with that have you noticed how many of the lines from your log have a "Request Method" of HEAD? You can block the use or the HEAD request method by adding it to your "Request Blocker" list.
View user's profile Send private message Send e-mail Visit poster's website
Admin32
Regular
Regular


Joined: Sep 14, 2003
Posts: 74

PostPosted: Wed Jul 28, 2004 1:40 pm Reply with quote Back to top

Thanks for your reply guys,

I'm hoping to see you implement the feture as an additional option for those who are willing to add a small delay on the site's generation time, to save them from having their site leeched and watching that bandwidth meter hit the roof!
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum