Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Strange activity on my site
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
Bigun
Advocate
Advocate


Joined: 21 Sep 2003
Posts: 2198

PostPosted: Sun Feb 26, 2006 10:31 am    Post subject: Strange activity on my site Reply with quote

I'm having some strange activity on my website right this very moment.

You see, my forum only had a few hundred posts with lower than 40 uses... approx 5 are active.

And for the last 3 hours some "guest" has been browsing my forums, browsing one topic at a time. I'm using phpBB so I can see what he is looking at. I have an IP, but I cannot get a reading on where they are located at, traceroute dies.

What else can I check here? To see what he is up to, or to see if they are doing anything malicious? Or to see if it is just a bot looking for e-mail addy's or something.
_________________
"It's ok, they might have guns but we have flowers." - Perpetual Victim
Back to top
View user's profile Send private message
frenkel
Veteran
Veteran


Joined: 13 May 2003
Posts: 1034
Location: .nl

PostPosted: Sun Feb 26, 2006 11:01 am    Post subject: Reply with quote

Is he not allowed to read your forum? Because somebody is reading the forum doesn't mean he is evil. It could also be somebody who is downloading the whole forum for offline reading.
Back to top
View user's profile Send private message
Bigun
Advocate
Advocate


Joined: 21 Sep 2003
Posts: 2198

PostPosted: Sun Feb 26, 2006 2:00 pm    Post subject: Reply with quote

I wouldn't think anything of one or two hours, but it's an unidentified guest that has been at it for a while.

I'm serious... it's now been 6 hours and hes still there.

There *might* be 3 or 4 Mb worth of data including the graphics. I doubt he's downloading.
_________________
"It's ok, they might have guns but we have flowers." - Perpetual Victim
Back to top
View user's profile Send private message
frenkel
Veteran
Veteran


Joined: 13 May 2003
Posts: 1034
Location: .nl

PostPosted: Sun Feb 26, 2006 3:02 pm    Post subject: Reply with quote

bigun89 wrote:
I wouldn't think anything of one or two hours, but it's an unidentified guest that has been at it for a while.

I'm serious... it's now been 6 hours and hes still there.

There *might* be 3 or 4 Mb worth of data including the graphics. I doubt he's downloading.

Okay, pull the plug :P Or ban him with iptables.
You sure it's the same person?
Back to top
View user's profile Send private message
Bigun
Advocate
Advocate


Joined: 21 Sep 2003
Posts: 2198

PostPosted: Sun Feb 26, 2006 9:20 pm    Post subject: Reply with quote

I have no IPTable rights. And this isn't a local machine I can just pull.

I'll check out phpBB and see what I can do.
_________________
"It's ok, they might have guns but we have flowers." - Perpetual Victim
Back to top
View user's profile Send private message
magic919
Advocate
Advocate


Joined: 17 Jun 2005
Posts: 2182
Location: Berkshire, UK

PostPosted: Sun Feb 26, 2006 9:32 pm    Post subject: Reply with quote

Ban controls in PHPBB.
Back to top
View user's profile Send private message
frenkel
Veteran
Veteran


Joined: 13 May 2003
Posts: 1034
Location: .nl

PostPosted: Mon Feb 27, 2006 7:21 am    Post subject: Reply with quote

bigun89 wrote:
I have no IPTable rights. And this isn't a local machine I can just pull.

I'll check out phpBB and see what I can do.


By pull I mean something like /etc/init.d/apache2 stop.........
Back to top
View user's profile Send private message
Bigun
Advocate
Advocate


Joined: 21 Sep 2003
Posts: 2198

PostPosted: Mon Feb 27, 2006 11:56 am    Post subject: Reply with quote

It isn't Gentoo either.

I'll ban him via IP.

*EDIT*

After banning I did some checking on the IP.

1) It will not traceroute

2) The whois data base shown this:

Code:

~ $ whois **.**.**.**
Internap Network Services PNAP-06-2001 (NET-66-150-0-0-1)
                                  66.150.0.0 - 66.151.255.255
Fast Search and Transfer PNAP-BSN-FASTS-RM-01 (NET-66-151-181-0-1)
                                  66.151.181.0 - 66.151.181.255


I didn't list the IP because I didn't want to break any rules.

At any rate, could that have been a search engine bot?
_________________
"It's ok, they might have guns but we have flowers." - Perpetual Victim


Last edited by Bigun on Mon Feb 27, 2006 3:00 pm; edited 1 time in total
Back to top
View user's profile Send private message
DaveArb
Guru
Guru


Joined: 29 Apr 2004
Posts: 510
Location: Texas, USA

PostPosted: Mon Feb 27, 2006 2:40 pm    Post subject: Reply with quote

www.fastsearch.com wrote:
Fast Search & Transfer(tm) (FAST(tm)) the world leader in enterprise search solutions, provides business and government the ability to intelligently access, retrieve and analyze information in real time, regardless of data format, structure, or location. FAST customers use search to make better-informed, more effective decisions; create new markets, outflank their competitors and increase their profitability.


Searchbot, that's my guess too.

Dave
Back to top
View user's profile Send private message
Bigun
Advocate
Advocate


Joined: 21 Sep 2003
Posts: 2198

PostPosted: Mon Feb 27, 2006 3:02 pm    Post subject: Reply with quote

Great, I just banned a bot that could potentially increase my page hits.
_________________
"It's ok, they might have guns but we have flowers." - Perpetual Victim
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum