Active TopicsActive Topics  Display List of Forum MembersMemberlist  Search The ForumSearch  HelpHelp
  RegisterRegister  LoginLogin
PowerHome General
 PowerHome Messageboard : PowerHome General
Subject Topic: Securing the PH webserver Post ReplyPost New Topic
Author
Message << Prev Topic | Next Topic >>
MrGibbage
Super User
Super User
Avatar

Joined: October 23 2006
Location: United States
Online Status: Offline
Posts: 513
Posted: January 30 2010 at 17:32 | IP Logged Quote MrGibbage

I get log entries like this just about every day:

From: 204.236.188.16
GET http://proxyjudge1.proxyfire.net/fastenv HTTP/1.1
Host: proxyjudge1.proxyfire.net
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Accept: */*
Accept-Language: zh-cn
Connection: Keep-Alive

It's is often times different IP addresses, and sometimes the GET statement is a little different, but nonetheless, I usually have one or two of these a day. I have noticed that these entries look quite different than the entries that are logged when I log onto the server, namely in that these entries always appear singularly, as a single, lonely post. When I log into the server, there is a long stream of entries.

I have had some success blocking the IP addresses at my router, and I can keep doing that, but I was wondering what the PH community at large is doing. I always do a WHOIS on the IP address (the one here is from Amazon.com. Why in the world would they be trying to connect to my server???) I have now banned the entire APNIC (sorry, but just too many entries coming from over there). So, am I safe? It doesn't look like they found anything, but I don't see any 404 errors. Does PH log them somewhere else? Oh, I run my server on a very non-standard port, so these guys aren't just looking to see if I am running a web server.

Ideas? Comments?
Back to Top View MrGibbage's Profile Search for other posts by MrGibbage
 
TonyNo
Moderator Group
Moderator Group
Avatar

Joined: December 05 2001
Location: United States
Online Status: Offline
Posts: 2889
Posted: February 01 2010 at 07:34 | IP Logged Quote TonyNo

All I do is add IP's to the blacklist when I see more than one or two.

I'm guessing that there are not too many people trying to exploit PH. ;)
Back to Top View TonyNo's Profile Search for other posts by TonyNo Visit TonyNo's Homepage
 

If you wish to post a reply to this topic you must first login
If you are not already registered you must first register

  Post ReplyPost New Topic
Printable version Printable version

Forum Jump
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot delete your posts in this forum
You cannot edit your posts in this forum
You cannot create polls in this forum
You cannot vote in polls in this forum