Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Design Forum > Web Serving and Management
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Web Serving and Management how to web server support forum

Reply
 
LinkBack Thread Tools
Old 12-19-2007, 02:46 PM   #1 (permalink)
TSF Enthusiast
 
BMR777's Avatar
 
Join Date: Apr 2005
Location: Chicago, IL
Posts: 1,398
OS: XP Pro, XP Home, Vista Home Basic, Ubuntu Studio


Blog Entries: 2
Anyone ever seen anything like this? DoS attack!

Hello,

Today one of my servers was square in the middle of a DoS attack. I run a small forum hosting website that hosts many PHPBB forums. Some bot or something began crawling EVERY SINGLE FORUM AND DIRECTORY AT ONE TIME! This caused MySql and eventually the server to crash. After about six hours my host banned the bot on a server level by IP, but it's still trying to get in.

Looking at the log for the bot I noticed something interesting. The bot from this IP keeps changing it's user agent with every request to try and bypass the filters. Here's an exerpt from the log:

Quote:
Host: 66.29.115.6
/5/criticism/
Http Code: 403 Date: Dec 19 16:29:52 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; ezPeer+ v1.0 (0.5.0.78); Alexa Toolbar; mxie; .NET CLR 1.1.4322; .NET CLR 2.0.50727)

/5/concrete/
Http Code: 403 Date: Dec 19 16:29:53 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; {12D85DE1-530A-41FE-8D8C-6BE367B509D9}; .NET CLR 1.1.4322)

/5/compound/
Http Code: 403 Date: Dec 19 16:29:53 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Foxy/1; InfoPath.1; .NET CLR 1.1.4322; IEMB3; IEMB3)


/5/metaphor/
Http Code: 403 Date: Dec 19 16:29:53 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; fr; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3 Creative ZENcast v1.02.10

/5/isolation/
Http Code: 403 Date: Dec 19 16:29:53 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; {E543C779-AA50-BED5-BDF5-F038E5E3F75F}; .NET CLR 1.1.4322; .NET CLR 2.0.50727)

/5/guest/
Http Code: 403 Date: Dec 19 16:29:53 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.8) Gecko/20051111 Firefox/1.5


/5/decrease/
Http Code: 403 Date: Dec 19 16:29:53 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; SIMBAR={8987975A-5CFF-4478-BE02-E2E69353B489}; SIMBAR=0; .NET CLR 2.0.50727)

/5/nation/
Http Code: 403 Date: Dec 19 16:29:54 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; SIMBAR={1B42AA8C-5696-4867-AFDD-2B7B2AEBA7FF}; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)


/5/stability/
Http Code: 403 Date: Dec 19 16:29:54 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; YPC 3.2.0; (R1 1.5; yplus 5.1.04b); .NET CLR 1.1.4322; .NET CLR 2.0.50727)

/5/sighting/
Http Code: 403 Date: Dec 19 16:29:55 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Sky Broadband; .NET CLR 1.1.4322; .NET CLR 2.0.50727; FDM)


/5/employ/
Http Code: 403 Date: Dec 19 16:29:55 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X; sk-sk) AppleWebKit/418.8 (KHTML, like Gecko) Safari/419.3



/5/presentation/
Http Code: 403 Date: Dec 19 16:29:56 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; digit_may2002; SV1; .NET CLR 1.1.4322)


/5/luck/
Http Code: 403 Date: Dec 19 16:29:56 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts; .NET CLR 2.0.50727; ZangoToolbar 4.8.3)



/5/trolley/
Http Code: 403 Date: Dec 19 16:29:56 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; SIMBAR={FC6DF565-9843-4755-AF80-C4C0B391B159}; .NET CLR 1.1.4322)


/5/drain/
Http Code: 403 Date: Dec 19 16:29:57 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; MSN 6.1; MSNbMSFT; MSNmde-at; MSNc00; v5m)

/5/productivity/
Http Code: 403 Date: Dec 19 16:29:57 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90; SC/5.55/1.70/HP-FriSurf)


/5/chosen/
Http Code: 403 Date: Dec 19 16:29:57 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; pl) Opera 8.54

/5/mania/
Http Code: 403 Date: Dec 19 16:29:57 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; ja-JP-mac; rv:1.8.0.10) Gecko/20070216 Firefox/1.5.0.10

/5/growing/
Http Code: 403 Date: Dec 19 16:29:57 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; cs; rv:1.8.1.4) Gecko/20070515 Firefox/1.5.0.12;MEGAUPLOAD 1.0


/5/economy/
Http Code: 403 Date: Dec 19 16:29:57 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; SIMBAR={5D459827-DAF3-49f6-9F13-BCF192D07A2A}; .NET CLR 1.1.4322)

/5/region/
Http Code: 403 Date: Dec 19 16:29:58 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.1; HbTools 4.8.2)


/5/barred/
Http Code: 403 Date: Dec 19 16:29:58 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; FunWebProducts; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; InfoPath.2)


/5/guard/
Http Code: 403 Date: Dec 19 16:29:58 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.8.1.8) Gecko/20071008 Firefox/2.0.0.4;MEGAUPLOAD 1.0


/5/comparative/
Http Code: 403 Date: Dec 19 16:29:58 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MEGAUPLOAD 1.0; .NET CLR 2.0.50727; SeekmoToolbar 4.8.4)


/5/replacing/
Http Code: 403 Date: Dec 19 16:29:58 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; es-AR; rv:1.7.3) Gecko/20040913 Firefox/0.10

/5/paraphrase/
Http Code: 403 Date: Dec 19 16:29:58 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Datamark; .NET CLR 1.1.4322; .NET CLR 2.0.50727; Datamark; Datamark)

/5/frequency/
Http Code: 403 Date: Dec 19 16:29:59 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ADVPLUGIN|K115|165|S1411705558|dialno)

/5/active/
Http Code: 403 Date: Dec 19 16:29:59 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; SIMBAR={35A0C28F-614F-47cf-ADA3-CCAB15DB8089}; MRA 4.8 (build 01709); .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
chanical/
Http Code: 403 Date: Dec 19 16:29:59 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; {B62FAB49-37D7-2139-6680-DA8A30B18220})

/5/motto/
Http Code: 403 Date: Dec 19 16:29:59 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/5.0 (X11; U; NetBSD bstg vax; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4


/5/limiting/
Http Code: 403 Date: Dec 19 16:29:59 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SIMBAR Enabled; (R1 1.5); .NET CLR 2.0.50727; .NET CLR 1.1.4322)


/5/outside/
Http Code: 403 Date: Dec 19 16:29:59 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; FDM; MEGAUPLOAD 2.0; .NET CLR 2.0.50727)


/5/offering/
Http Code: 403 Date: Dec 19 16:30:00 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.04506; Seekmo 10.0.341.0)

/5/sound/
Http Code: 403 Date: Dec 19 16:30:00 Http Version: HTTP/1.1 Size in Bytes: -
Referer: -
Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461; SYMPA; SV1; (R1 1.1); .NET CLR 1.1.4322)
Anyone seen anything like this? Any tips?
BMR777
__________________
Brandon Rusnak

Protection: AVG Free Anti Virus :: Windows Defender :: Hosts File :: SiteAdvisor :: ZoneAlarm
Quick Fixes: 5 Steps to remove spyware
BMR777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 12-22-2007, 04:32 AM   #2 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 24
OS: xp


Re: Anyone ever seen anything like this? DoS attack!

Look up the persons IP and see what kind of info you can get. After which, look up their ISP and give them a call, if you can.
And post the IP of the DoSer please.

http://www.showmyip.com/lookups/#DoLookup
Pyro-Fire is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 12-22-2007, 08:10 AM   #3 (permalink)
TSF Enthusiast
 
BMR777's Avatar
 
Join Date: Apr 2005
Location: Chicago, IL
Posts: 1,398
OS: XP Pro, XP Home, Vista Home Basic, Ubuntu Studio


Blog Entries: 2
Re: Anyone ever seen anything like this? DoS attack!

Their IP was 66.29.115.6.
__________________
Brandon Rusnak

Protection: AVG Free Anti Virus :: Windows Defender :: Hosts File :: SiteAdvisor :: ZoneAlarm
Quick Fixes: 5 Steps to remove spyware
BMR777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 12-23-2007, 01:04 AM   #4 (permalink)
Registered User
 
Join Date: Dec 2007
Posts: 24
OS: xp


Re: Anyone ever seen anything like this? DoS attack!

their ISP is Net Access Corporation, and they live in the USA.

Try giving the isp a call, and telling them about this attack against your website.

Include Time/Date of the attack, and IP at the time.

ISP Home:
http://www.nac.net/

Contact details:
http://www.nac.net/enterprise/contact.asp

i recommend you use this number:
Abuse Department (973) 590-5040

tell us how it goes.
Pyro-Fire is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 12-25-2007, 08:32 AM   #5 (permalink)
Manager, Alternative Comp
 
Skie's Avatar
 
Join Date: Mar 2003
Location: Chicago burbs
Posts: 2,194
OS: Gentoo Linux, CentOS, OS X

My System

Re: Anyone ever seen anything like this? DoS attack!

If you haven't already, I would add that IP to your firewall's Deny list.
__________________
Skie is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 10:56 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85