Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 07-05-2009, 10:59 AM   #1
jmcb420
So Fucking Drunk
 
jmcb420's Avatar
 
Industry Role:
Join Date: Oct 2006
Posts: 2,155
Attempted Hacking? WTF can I do to stop this?

I took a few minutes to look at traffic on one of my bigger sites and noticed a huge increase in my 404 traffic on that site. 404's are already double this month what they were last month, that raised a red flag.
So I checked it out. the SE's still list around 20 pages that no longer exist, and that is my normal 404 traffic. Nothing to care about at all.
Then I found these urls that do not and never have existed:

Required but not found URLs (HTTP code 404):

/krheupfile_flash.asp
/suozftp.rar
/srestmdqq.asp
/arknmirserver.rar
/xmwywebeditor/ewebeditor.asp
/pjhkplus/infosearch.php


What do you guys make of it? Hacking attempt? Thats my thought, but whats more is i've never been proactive in stopping anything like this beyond going with a decent host.

Anything I can do to safeguard myself from a low level attempt such as this?

Thanks in advance.
__________________
I'm funner than AIDS, and easier to explain to your parents.
jmcb420 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:01 AM   #2
Phoenix
BACON BACON BACON
 
Industry Role:
Join Date: Nov 2002
Location: Poems everybody, the laddie fancies himself a poet
Posts: 35,457
hit up your host...maybe they can help
__________________
Skype Phoenixskype1
Telegram PhoenixBrad
https://quantads.io
Phoenix is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:05 AM   #3
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
Quote:
Originally Posted by jmcb420 View Post
I took a few minutes to look at traffic on one of my bigger sites and noticed a huge increase in my 404 traffic on that site. 404's are already double this month what they were last month, that raised a red flag.
So I checked it out. the SE's still list around 20 pages that no longer exist, and that is my normal 404 traffic. Nothing to care about at all.
Then I found these urls that do not and never have existed:

Required but not found URLs (HTTP code 404):

/krheupfile_flash.asp
/suozftp.rar
/srestmdqq.asp
/arknmirserver.rar
/xmwywebeditor/ewebeditor.asp
/pjhkplus/infosearch.php


What do you guys make of it? Hacking attempt? Thats my thought, but whats more is i've never been proactive in stopping anything like this beyond going with a decent host.

Anything I can do to safeguard myself from a low level attempt such as this?

Thanks in advance.
don't recognise any of those, but i get lots of similar requests for non existant urls on my servers and i think they are looking to see if you have certain scripts installed that they know have vulnerabilities that they can hack. it's nothing to worry about, unless someone knows different?
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:09 AM   #4
jmcb420
So Fucking Drunk
 
jmcb420's Avatar
 
Industry Role:
Join Date: Oct 2006
Posts: 2,155
Quote:
Originally Posted by Phoenix View Post
hit up your host...maybe they can help
I already went there, they of course told me (without going into much detail) that "on thier end they have evey measure in place to protect my sites in the event of an attack."

I would say that if a client were asking me that question and my biz was hosting thier network.

Shit sometimes happens, you know? i'm a bit worried
__________________
I'm funner than AIDS, and easier to explain to your parents.
jmcb420 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:10 AM   #5
HouseHead
Confirmed User
 
HouseHead's Avatar
 
Join Date: Aug 2003
Location: Aim - Hydromorphone
Posts: 5,539
Yea contact your host man..
__________________
The Sexiest place to Buy & Sell Adult Ads - JuicyAds is where YOUR profits matter!

---> SPOTS AVAILABLE
:|: SIGN UP RIGHT NOW <---
HouseHead is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:32 AM   #6
Merrioc
Confirmed User
 
Join Date: Jul 2003
Posts: 249
it looks like simple exploit scanning. There isn't to much preventative that could be done.

unless your seeing actual load problems from this I wouldn't wast energy on it. If your really paranoid you could write some for of script to determine the number of 404 requests sent by a script kiddie, determine a threshold and drop them at the firewall level.
Merrioc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:50 AM   #7
seeandsee
Check SIG!
 
seeandsee's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Europe (Skype: gojkoas)
Posts: 50,945
they do it across many sites looking for exploits, don't know how to block that
__________________
BUY MY SIG - 50$/Year

Contact here
seeandsee is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 12:03 PM   #8
Klen
 
Klen's Avatar
 
Industry Role:
Join Date: Aug 2006
Location: Little Vienna
Posts: 32,235
Yes looks like either exploit scanning or warez scanning (they looking for hosts with upload permissions where they can upload files).But more likely exploit scanning
Klen is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 12:03 PM   #9
jmcb420
So Fucking Drunk
 
jmcb420's Avatar
 
Industry Role:
Join Date: Oct 2006
Posts: 2,155
Quote:
Originally Posted by Merrioc View Post
it looks like simple exploit scanning. There isn't to much preventative that could be done.

unless your seeing actual load problems from this I wouldn't wast energy on it. If your really paranoid you could write some for of script to determine the number of 404 requests sent by a script kiddie, determine a threshold and drop them at the firewall level.
Everything on the site and in my network loads fine and works like it should.

For peace of mind I should learn more about this from his point of view, learn a few tricks and try to hack my own stuff then learn what I can do to prevent others from being sucessful in the event that I should.

At the same time, I should install a 3 strikes your out script. Although, thats gonna take me learning new stuff too. Damnit.


For the most part it looks like I dont have to worry. Thanks for the input everyone, much appreciated.
__________________
I'm funner than AIDS, and easier to explain to your parents.

Last edited by jmcb420; 07-05-2009 at 12:05 PM..
jmcb420 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 03:21 PM   #10
Carmine Raguso
So Fucking Banned
 
Join Date: Dec 2008
Location: Prescott, AZ
Posts: 2,158
1.) Create the nonexistent pages they are scanning for on your server

2.) Become an affiliate for one of the bullshit scam antivirus companies

3.) Have pages autoinstall trojans

4.) ???????

5.) Profit.
Carmine Raguso is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 03:59 PM   #11
fris
Too lazy to set a custom title
 
fris's Avatar
 
Industry Role:
Join Date: Aug 2002
Posts: 55,248
have your isp add the ip ranges to their firewall rules
__________________
Since 1999: 69 Adult Industry awards for Best Hosting Company and professional excellence.


WP Stuff
fris is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 04:12 PM   #12
psili
Confirmed User
 
Join Date: Apr 2003
Location: Loveland, CO
Posts: 5,526
Don't know if it exists, but maybe for an added piece of mind:
- Take a recursive directory snapshot of known files you want / power your stuff.
- Every once in a while, take new snapshots and compare to the baseline.
- If there's a "new" file that looks amiss, research it.

Don't know if there's an automated solution that does that, and if so, unless it scans file contents, won't really help if someone's modified a pre-existing file.

Anyway. Just throwing my nonsense out there.
__________________
Your post count means nothing.
psili is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 04:16 PM   #13
Babaganoosh
♥♥♥ Likes Hugs ♥♥♥
 
Babaganoosh's Avatar
 
Industry Role:
Join Date: Nov 2001
Location: /home
Posts: 15,841
Just ignore it. Almost all of my sites get scanned for that crap. If you're using 3rd party scripts that you aren't sure about, .htaccess them to keep out the riff-raff.
__________________
I like pie.
Babaganoosh is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 04:20 PM   #14
CYF
Coupon Guru
 
CYF's Avatar
 
Industry Role:
Join Date: Mar 2009
Location: Minneapolis
Posts: 10,973
Quote:
Originally Posted by psili View Post
Don't know if it exists, but maybe for an added piece of mind:
- Take a recursive directory snapshot of known files you want / power your stuff.
- Every once in a while, take new snapshots and compare to the baseline.
- If there's a "new" file that looks amiss, research it.

Don't know if there's an automated solution that does that, and if so, unless it scans file contents, won't really help if someone's modified a pre-existing file.

Anyway. Just throwing my nonsense out there.
If you're running unix I believe you're thinking of Tripwire.
__________________
Webmaster Coupons Coupons and discounts for hosting, domains, SSL Certs, and more!
AmeriNOC Coupons | Certified Hosting Coupons | Hosting Coupons | Domain Name Coupons

CYF is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 04:25 PM   #15
Killswitch - BANNED FOR LIFE
Guest
 
Posts: n/a
Not hard, all you have to do is create a link on a search engine crawled page with some random page that doesn't exist on your server, it it will come back 404 by the search engines.
  Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 04:25 PM   #16
Net Money
Confirmed User
 
Join Date: Dec 2007
Posts: 539
Quote:
Originally Posted by jmcb420 View Post
I already went there, they of course told me (without going into much detail) that "on thier end they have evey measure in place to protect my sites in the event of an attack."

I would say that if a client were asking me that question and my biz was hosting thier network.

Shit sometimes happens, you know? i'm a bit worried

You're at the wrong host dude. Any good host would tace it down and block them for you.
Net Money is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 04:35 PM   #17
~Ray
visit hardlinks.org
 
~Ray's Avatar
 
Industry Role:
Join Date: Jun 2003
Location: Las Vegas , Nv >>> [email protected] or icq 94994627 anytime
Posts: 18,362
have a script written to place on pages named after the exploits on your server, chmod your htaccess to allow your server to modify the htaccess file. Each time someone request one of those pages, the script will record their ip, and bann it by adding it to the htaccess file.

Last edited by ~Ray; 07-05-2009 at 04:37 PM..
~Ray is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 10:25 PM   #18
d-null
. . .
 
d-null's Avatar
 
Industry Role:
Join Date: Apr 2007
Location: NY
Posts: 13,724
Quote:
Originally Posted by Carmine Raguso View Post
1.) Create the nonexistent pages they are scanning for on your server

2.) Become an affiliate for one of the bullshit scam antivirus companies

3.) Have pages autoinstall trojans

4.) ???????

5.) Profit.
__________________

__________________

Looking for a custom TUBE SCRIPT that supports massive traffic, load balancing, billing support, and h264 encoding? Hit up Konrad!
Looking for designs for your websites or custom tubesite design? Hit up Zuzana Designs
Check out the #1 WordPress SEO Plugin: CyberSEO Suite
d-null is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:07 PM   #19
V_RocKs
Damn Right I Kiss Ass!
 
Industry Role:
Join Date: Dec 2003
Location: Cowtown, USA
Posts: 32,391
Worrying about this is like worrying about the sky falling...

What they are doing is akin to fishing. If you are a fish and you don't want to get eaten, don't eat worms...

Other than that... Nothing to worry about.
V_RocKs is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-05-2009, 11:30 PM   #20
niche25
GoFuckYourself
 
niche25's Avatar
 
Industry Role:
Join Date: Nov 2006
Location: Paradise Valley, AZ
Posts: 407
Google Webmaster tools is your friend. Remove pages in GWT, notify host, get a firewall & check shit regularly.

It is extremely rare I get hacked now and when I do its a quick turn around. A couple years ago I was getting hit regularly. Karma for me I guess LOL.
niche25 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-06-2009, 01:21 AM   #21
roly
Confirmed User
 
Join Date: Aug 2002
Posts: 1,844
Quote:
Originally Posted by Net Money View Post
You're at the wrong host dude. Any good host would tace it down and block them for you.
why would they bother? it would be a never ending battle, this goes on all day, every day. as long as you haven't got outdated scripts and stuff with known exploits your safe (from the people who are scanning for this).
roly is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-06-2009, 02:03 AM   #22
Iron Fist
Too lazy to set a custom title
 
Join Date: Dec 2006
Posts: 23,400
Quote:
Originally Posted by Carmine Raguso View Post
1.) Create the nonexistent pages they are scanning for on your server

2.) Become an affiliate for one of the bullshit scam antivirus companies

3.) Have pages autoinstall trojans

4.) ???????

5.) Profit.
Can you knock that down to 3 steps please? kthxbye.
__________________
i like waffles
Iron Fist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-06-2009, 02:07 AM   #23
HerPimp
Confirmed User
 
HerPimp's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Earth
Posts: 1,197
Quote:
Originally Posted by fris View Post
have your isp add the ip ranges to their firewall rules
i agree
__________________
HerPimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-06-2009, 02:26 AM   #24
milambur
Mainstream since 2010
 
milambur's Avatar
 
Industry Role:
Join Date: Jan 2003
Posts: 1,327
IP banning is never a good solution, they use botnets that have millions of infected computers, you risk blocking out a lot of potential customers in the long run.
To be safer, use custom scripts that are coded to handle malicious input. If you have to use a script that is commonly available, make sure you always have the latest updates.
__________________
Alea iacta est
milambur is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 07-06-2009, 02:40 AM   #25
spook
Registered User
 
spook's Avatar
 
Join Date: Jun 2009
Location: .au
Posts: 16
looks like its just skiddies scanning for holes. Adding their ip's manually will be a pain in the arse if they are using proxies (which they most times do). Best thing to do is just make sure all your scripts and your box is up to date. Also you could install mod_security if you haven't already (but if you install it, get someone who knows what they are doing to tune it for you).
spook is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.