| | |
is my site been hacked?
Please support our PHP advertiser: PostgreSQL or MySQL? Compare and contrast the two most popular open source databases
Thread Solved |
•
•
Join Date: Jan 2006
Posts: 3
Reputation:
Solved Threads: 0
i run a forum powered by phpbb version .19...
one of my moderators is very concerned about an ip address been seen logged onto 10-30 pages on the forums, at the exact same time.
spme of these pages were private messages, profiles.anyway the ip is called a googlebot, but this moderator saw the patterns 3 times in one day and yeh each time he said 'that is no way the signature of a cralwer'
'Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing Private Messages 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Varieties 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Varieties 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Virgin Lungs 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing Private Messages 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Virgin Lungs 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:41 am Fri Jan 27, 2006 5:57 am Forum index 68.9.195.215
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8 '
sorry if this along post, i just really worried and this seemed like a place to get some help, and fast...
that incident above happened 4 times today, all same ip..
something like this was also noticed a week before we had problems with passwords/random member deactivations/posts made by not right members...
is the above suspicios in any way??
ne help is greatly appreacited..
cheers
ANimAL
one of my moderators is very concerned about an ip address been seen logged onto 10-30 pages on the forums, at the exact same time.
spme of these pages were private messages, profiles.anyway the ip is called a googlebot, but this moderator saw the patterns 3 times in one day and yeh each time he said 'that is no way the signature of a cralwer'
'Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing Private Messages 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Varieties 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Varieties 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Virgin Lungs 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing Private Messages 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Virgin Lungs 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:41 am Fri Jan 27, 2006 5:57 am Forum index 68.9.195.215
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8 '
sorry if this along post, i just really worried and this seemed like a place to get some help, and fast...
that incident above happened 4 times today, all same ip..
something like this was also noticed a week before we had problems with passwords/random member deactivations/posts made by not right members...
is the above suspicios in any way??
ne help is greatly appreacited..
cheers
ANimAL
That seems perfectly fine to me. Googlebot (google.com's crawler) is well known for visiting many pages at once in bursts that can last up to a couple of hours to a day. They're known as "deep crawls".
Dani the Computer Science Gal 
Follow my Twitter feed! twitter.com/DaniWeb
And if you're interested in Internet marketing there is twitter.com/DaniWebAds

Follow my Twitter feed! twitter.com/DaniWeb
And if you're interested in Internet marketing there is twitter.com/DaniWebAds
No problem. Just to double check, I resolved the IP and, indeed, it goes to a googlebot crawler. This is a good thing. It means your pages will be well-indexed in the Google search engine.
Dani the Computer Science Gal 
Follow my Twitter feed! twitter.com/DaniWeb
And if you're interested in Internet marketing there is twitter.com/DaniWebAds

Follow my Twitter feed! twitter.com/DaniWeb
And if you're interested in Internet marketing there is twitter.com/DaniWebAds
•
•
Join Date: Jan 2006
Posts: 3
Reputation:
Solved Threads: 0
I trace routed the ip of the googlebot, which had mainly legitimate ips.
However one IP, owned by ABOVENET, was in the same range as 4 ips on every trace route taken from the member on the site who is most suspected of been behind any malicious activity.
This same user was using some kind of router/masking device as despite the fact that he says he is from Massechusits( i dont disbelieve this) all his ip's noted on the forums, end in the UK. I tracerouted his ips and 4 out of every 7 ip (which come up for the trace route) share a ip range ,owned by ABOVENET.
I checked trace routes on other US members of the forums and didnt get this ip range again, as of yet..
64.125.30.118 AS6461 was on the googlebots ip traceroute
and
64.125.30.118
64.125.29.133
64.125.28.129
64.125.27.166
are on the traceroutes of the 'uk' ip's logged in the phpbb forums which the suspected member has posted on lots.
does this mean anything??is it a hub which most users online in the US go through???and normal for the googlebot to be going through thee also???
EVery one of the ips we have for this user, yields traceroutes with 4 ips from that (ABOVENET)range.
Also, on every traceroute i have made for the ips from this member, the ending is the same:
[10.x.x.x] AS16559
REALCONNECT-01
[10.x.x.x] AS16559
REALCONNECT-01
then 4 hops that hit a firewall.
the last valid ip before the REALCONNECT hops is always a UK ip.
Am I completely mistaken with these connections?
and what does the REALCONNECT [10,x.x.x] mean on a traceroute???
as ever all help is very greatly appreciated...
(207.234.129.8 is the ip of a user who made threats about hacking our site)
(213.249.245.169 ) ip logged from the active member we suspect(from our phpbb boards)
However one IP, owned by ABOVENET, was in the same range as 4 ips on every trace route taken from the member on the site who is most suspected of been behind any malicious activity.
This same user was using some kind of router/masking device as despite the fact that he says he is from Massechusits( i dont disbelieve this) all his ip's noted on the forums, end in the UK. I tracerouted his ips and 4 out of every 7 ip (which come up for the trace route) share a ip range ,owned by ABOVENET.
I checked trace routes on other US members of the forums and didnt get this ip range again, as of yet..
64.125.30.118 AS6461 was on the googlebots ip traceroute
and
64.125.30.118
64.125.29.133
64.125.28.129
64.125.27.166
are on the traceroutes of the 'uk' ip's logged in the phpbb forums which the suspected member has posted on lots.
does this mean anything??is it a hub which most users online in the US go through???and normal for the googlebot to be going through thee also???
EVery one of the ips we have for this user, yields traceroutes with 4 ips from that (ABOVENET)range.
Also, on every traceroute i have made for the ips from this member, the ending is the same:
[10.x.x.x] AS16559
REALCONNECT-01
[10.x.x.x] AS16559
REALCONNECT-01
then 4 hops that hit a firewall.
the last valid ip before the REALCONNECT hops is always a UK ip.
Am I completely mistaken with these connections?
and what does the REALCONNECT [10,x.x.x] mean on a traceroute???
as ever all help is very greatly appreciated...
(207.234.129.8 is the ip of a user who made threats about hacking our site)
(213.249.245.169 ) ip logged from the active member we suspect(from our phpbb boards)
assuming the above user crawler is enfact google, you can tell them to slow down the way they crawl your site. You can even tell them not to crawl certain pages such as those private files/messages you mentioned
http://www.searchengineworld.com/rob...s_tutorial.htm
they even have a validator to make sure you set it up correctly.
http://www.searchengineworld.com/rob...s_tutorial.htm
they even have a validator to make sure you set it up correctly.
![]() |
Similar Threads
- Selling PR4 Arcade Gaming and Video site (Websites for Sale)
- Random Web Site Redirects (Viruses, Spyware and other Nasties)
- Please review my new site (Website Reviews)
- Please Crit my site Devilsown Alcohol-Injection (Website Reviews)
- Redesigned my site/forum. Please review! (Website Reviews)
- ISP or IE showing false DNS error for particular site (Web Browsers)
Other Threads in the PHP Forum
- Previous Thread: How to change the meta tag?
- Next Thread: need help in C/PHP
Views: 2733 | Replies: 6
| Thread Tools | Search this Thread |
Tag cloud for PHP
.htaccess access ajax apache api array autosuggest beginner binary broken cakephp checkbox class cms code cron curl database date directory display download dynamic echo email emptydisplayvalue error explodefunction file files folder form forms function functions google href htaccess html image include insert integration ip java javascript joomla jquery keywords limit link login loop mail menu methods mlm mod_rewrite multiple mysql oop parse paypal pdf php problem query radio random recursion regex remote script search searchbox select server sessions sms soap source space speed sql structure syntax system table tutorial update updates upload url validation validator variable video web xml youtube






