PHP Web Host - Quality Web Hosting For All PHP Applications Just Great Software
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
spurtus
Regular
Regular


Joined: May 13, 2006
Posts: 89

PostPosted: Mon Nov 26, 2007 10:25 pm Reply with quote Back to top

I got hit this weekend with several hundred of this type of message from sentinel:

    Date & Time: 2007-11-24 02:06:42 PST GMT -0800 Blocked IP: 81.220.61.* User ID: Anonymous (1)
    Reason: Abuse-Filter
    --------------------
    User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322) Query String:
    Only registered users can see links on this board!
    Get registered or login to the forums!

    Get String:
    Only registered users can see links on this board!
    Get registered or login to the forums!

    Post String:
    Only registered users can see links on this board!
    Get registered or login to the forums!

    Forwarded For: none
    Client IP: none
    Remote Address: 81.220.61.150
    Remote Port: 15618
    Request Method: GET
    --------------------
    Who-Is for IP


There is no whois content for the IPs in any of the several hundred cases, not sure why. But the URL after the "name=" parameter on the get string is always a different URL, all from the .RU domain. Can someone tell me what this type of message means? I am glad that Sentinel caught it, but not sure how bad this is.

Thanks!

Spurt
View user's profile Send private message Yahoo Messenger
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2846

PostPosted: Tue Nov 27, 2007 1:19 am Reply with quote Back to top

Automated bots are attacking your site... don't worry, they are attacking ours too!
81.220.61.150 pulls up a French ISP in whois, my guess is another compromised machine.

You are safe from this using Sentinel and phpNuke itself has been patched against this exploit for a long while. Still, remain vigilant and keep your software up-to-date.
View user's profile Send private message Visit poster's website
spurtus
Regular
Regular


Joined: May 13, 2006
Posts: 89

PostPosted: Tue Nov 27, 2007 6:13 pm Reply with quote Back to top

Thanks!

According to my Sentinel Admin panel, I am on version 2.5.08, and a newer version is available (2.5.14). Do you recommend I upgrade (and do I get those bits here?). I presume so...will check.

spurt
View user's profile Send private message Yahoo Messenger
evaders99
Moderator


Joined: Apr 30, 2004
Posts: 2846

PostPosted: Tue Nov 27, 2007 10:00 pm Reply with quote Back to top

Yes you will want to upgrade. Get the latest version from
Only registered users can see links on this board!
Get registered or login to the forums!
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2008 by Raven
Proud to be listed at Lobo Links Web Directory

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::

:: fisubice Theme Recoded To 100% W3C CSS & HTML 4.01 Transitional Compliance by Raven and 64bitguy ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum