PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 11:52 am Reply with quote Back to top

Using Sentinel(tm) 1.2, I was banned, and I wasn't even on the site.
Quote:
Date & Time: 2004-07-26 11:50:02
Blocked IP: my IP
User ID: Anonymous (1)
Reason: Abuse - AGENT
--------------------
User Agent: Mozilla/3.0 (compatible; Indy Library)
I used the user agent look up and found the reason - indy library. Is it possible to spoof an IP and add the indy library? I am confused!! Exclamation


Last edited by sharlein on Mon Jul 26, 2004 4:31 pm; edited 1 time in total
View user's profile Send private message
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Mon Jul 26, 2004 2:24 pm Reply with quote Back to top

Tons of browser addons like to change the user agent without permission. I'd check the browsers user agent to see if something has altered it recently.
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 2:53 pm Reply with quote Back to top

How can I do that, please?
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 4:34 pm Reply with quote Back to top

I checked my user agent
Quote:
and your browser is Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
Can I do anything to stop this from happening in the future? Thanks, Steve
View user's profile Send private message
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Mon Jul 26, 2004 4:40 pm Reply with quote Back to top

The user agent you have doesn't seem to trigger any resonse in the "Agent Inspector". So I'm a little confused why you got banned. What happens when you unban yourself and go back?
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 4:42 pm Reply with quote Back to top

It just happened again, this time on my site.
Quote:
Date & Time: 2004-07-26 17:25:47
Blocked IP: my IP
User ID: Anonymous (1)
Reason: Abuse-Harvest
String Match: indy library
User Agent: Mozilla/3.0 (compatible; Indy Library)
Please help, I'm at a loss.
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 5:04 pm Reply with quote Back to top

The agent
Quote:
User Agent: Mozilla/3.0 (compatible; Indy Library)
brings back
Quote:
Agent: User Agent: Mozilla/3.0 (compatible; Indy Library) is trapped by this Harvester entry: indy library
It is my IP, but a diffenent agent. Both times, on different sites, same server, I was not on the site at the time. After I fixed the .htaccess and the database, I can get back on. I tried to get on before the change, and I was blocked.
View user's profile Send private message
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Mon Jul 26, 2004 7:53 pm Reply with quote Back to top

Are you blocking IP# or by range? If not number try taking it to number
Options are:
Full IP Specific
1 Octet
2 Octet
3 Octet Broadest

I'd try Full IP or 1 Octet here and see if that resolves it. If you are blocking by Full IP and it is your IP we'll have to dig a little deeper.

G'luck!
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 8:22 pm Reply with quote Back to top

Yes, I am blocking by full IP, and the IP getting blocked is mine. Whatever is happening is changing my user agent to trigger the harvester block. It only happened twice, once each on sites that I run.
View user's profile Send private message
sixonetonoffun
Spouse Contemplates Divorce


Joined: Jan 02, 2003
Posts: 2499

PostPosted: Mon Jul 26, 2004 8:23 pm Reply with quote Back to top

For the time being try removing Indy from the harvestor list see if that helps.
View user's profile Send private message
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Mon Jul 26, 2004 8:48 pm Reply with quote Back to top

It only happened twice Six. Now I am back to my normal user agent (not 3.0 with Indy) I have not changed a thing. Somehow, someone spoofed my IP and added Mozilla 3.0 with the indy harvester. I don't know if I am explaining things correctly, but I wasn't on the site when I got banned. I received the ban notice from Sentinel(tm). I didn't even recognize my own IP, but I attempted to go to the site and was surprised to see I was banned. I fixed the .htaccess and table, and got back on without incident. This site was using Sentinel(tm) 1.2.

My other site is running Sentinel(tm) 2.0 and exactly the same thing happened. I don't think my user agent changed at all. Can someone use my IP and add their own agent? Thanks, Steve
View user's profile Send private message
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Mon Jul 26, 2004 9:44 pm Reply with quote Back to top

Some routers can be programed with ip's. This is a trick that mr. Hitwalker likes to use to try and get by a sites defenses.
View user's profile Send private message Send e-mail Visit poster's website
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Tue Jul 27, 2004 3:54 am Reply with quote Back to top

Then I would say that Sentinel(tm) is an unqualified success. Thank you very much. Having to fix a couple of entries is a small price to pay for security. Thank you all very much. Steve Very Happy
View user's profile Send private message
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Tue Jul 27, 2004 9:21 pm Reply with quote Back to top

sharlein, would you email please. I monitor 3 different sites sentinel block reports and I just got one from all 3 with the same ip using Indy Library. I want to make sure it's not yours and if it is I want to get the ip cleared on all the sites.
View user's profile Send private message Send e-mail Visit poster's website
sharlein
Member Emeritus


Joined: Nov 19, 2002
Posts: 322
Location: On the Road

PostPosted: Wed Jul 28, 2004 6:39 am Reply with quote Back to top

Email is on the way, Bob. That is not me, even though it may be my IP.
View user's profile Send private message
Raven
Site Admin/Owner


Joined: Aug 27, 2002
Posts: 16976
Location: Kansas

PostPosted: Wed Jul 28, 2004 6:43 am Reply with quote Back to top

I've gotten several this week and none of them are your IP.
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger
BobMarion
Former Admin in Good Standing


Joined: Oct 30, 2002
Posts: 1043
Location: RedNeck Land (known as Kentucky)

PostPosted: Wed Jul 28, 2004 9:42 am Reply with quote Back to top

The ip with these are a 209.*.*.* so it's not your ip from the email you sent .
View user's profile Send private message Send e-mail Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum