Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 08-20-2005, 09:47 AM
PT_
Guest
 
Posts: n/a
Default How to block website script "hacker"?

Guys

Saw a big sustained use of b/w on one of my sites yesterday and it affected the load a lot so I think it must have slowed down the site for other visitors. Been through Apache logs and it seems like some script kiddie browsed my site as normal then tried to "hack" a guestbook on the site (see screenshot below - at least that's what I think he did). 55,252 page hits, 1.62 GB b/w and 4 hours later he gave up, switched his program off and went away.

Is there an automated way of preventing something like this with Apache? I know I can block his IP manually but a little investigation in the logs suggest he has visited the site before and has a dynamic ISP IP.







Cheers

An Irritated PT
Reply With Quote

  #2  
Old 08-20-2005, 09:54 AM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default

I'd suggest using mod_security which can block maclious traffic. www.eth0.us has a nice guide for installing it.
__________________
Got clue?
Reply With Quote

  #3  
Old 08-20-2005, 10:15 AM
PT_
Guest
 
Posts: n/a
Default

Elix, that's a very useful site. Thanks
.
I will install mod_security but I don't think that will stop this particular kind of nuisance (I could be wrong?!). However, that site had a guide on mod_dosevasive which seems perfect:

Quote:
denying any single IP address from any of the following:
Requesting the same page more than a few times per second
Making more than 50 concurrent requests on the same child per second
Making any requests while temporarily blacklisted (on a blocking list)
Anyone have experience of this?
Reply With Quote

  #4  
Old 08-20-2005, 09:09 PM
StingRay StingRay is offline
Senior Member
 
Join Date: Jul 2005
Posts: 155
StingRay is on a distinguished road
Default

There is another thread here about mod_dosevasive
Reply With Quote

  #5  
Old 08-21-2005, 01:00 AM
Jad
Guest
 
Posts: n/a
Default

mod security available via WHM Addon Modules.
Reply With Quote

  #6  
Old 08-23-2005, 05:33 PM
PT_
Guest
 
Posts: n/a
Default

Cheers for the info guys.
Reply With Quote

  #7  
Old 08-23-2005, 05:44 PM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default

Just recently found this site:
http://modsecrules.monkeydev.org/

Try the normal ruiles there for mod_security....that may help
__________________
Got clue?
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
crontab - running php script PaulH Linux VPS - General 1 11-01-2006 05:27 PM
Remote script (cron) ? ricardo Linux VPS - HOWTOs and FAQs 0 09-07-2006 12:35 PM
Remote script (cron) ? ricardo Linux VPS - HOWTOs and FAQs 0 09-07-2006 12:35 PM
IP Block on DirectAdmin? cparodi The Lounge 3 12-10-2005 02:10 PM
WHM script error for creating new domain firefly Linux VPS - cPanel 0 06-23-2005 03:51 PM



All times are GMT -4. The time now is 04:12 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006