is my site been hacked?

Thread Solved

Join Date: Jan 2006
Posts: 3
Reputation: weedguru_animal is an unknown quantity at this point 
Solved Threads: 0
weedguru_animal weedguru_animal is offline Offline
Newbie Poster

is my site been hacked?

 
0
  #1
Jan 27th, 2006
i run a forum powered by phpbb version .19...

one of my moderators is very concerned about an ip address been seen logged onto 10-30 pages on the forums, at the exact same time.
spme of these pages were private messages, profiles.anyway the ip is called a googlebot, but this moderator saw the patterns 3 times in one day and yeh each time he said 'that is no way the signature of a cralwer'

'Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing Private Messages 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Varieties 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Varieties 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Member Competitions and Details 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Virgin Lungs 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing Private Messages 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Virgin Lungs 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Viewing profile 66.249.72.8
Guest Fri Jan 27, 2006 5:41 am Fri Jan 27, 2006 5:57 am Forum index 68.9.195.215
Guest Fri Jan 27, 2006 5:57 am Fri Jan 27, 2006 5:57 am Stoners' Poems 66.249.72.8 '

sorry if this along post, i just really worried and this seemed like a place to get some help, and fast...

that incident above happened 4 times today, all same ip..
something like this was also noticed a week before we had problems with passwords/random member deactivations/posts made by not right members...

is the above suspicios in any way??

ne help is greatly appreacited..
cheers
ANimAL
Reply With Quote Quick reply to this message  
Join Date: Feb 2002
Posts: 12,056
Reputation: cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light 
Solved Threads: 129
Administrator
Staff Writer
cscgal's Avatar
cscgal cscgal is online now Online
The Queen of DaniWeb

Re: is my site been hacked?

 
0
  #2
Jan 27th, 2006
That seems perfectly fine to me. Googlebot (google.com's crawler) is well known for visiting many pages at once in bursts that can last up to a couple of hours to a day. They're known as "deep crawls".
Dani the Computer Science Gal
Follow my Twitter feed! twitter.com/DaniWeb
And if you're interested in Internet marketing there is twitter.com/DaniWebAds
Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 3
Reputation: weedguru_animal is an unknown quantity at this point 
Solved Threads: 0
weedguru_animal weedguru_animal is offline Offline
Newbie Poster

Re: is my site been hacked?

 
0
  #3
Jan 27th, 2006
thank for your quick response!!!
Reply With Quote Quick reply to this message  
Join Date: Feb 2002
Posts: 12,056
Reputation: cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light cscgal is a glorious beacon of light 
Solved Threads: 129
Administrator
Staff Writer
cscgal's Avatar
cscgal cscgal is online now Online
The Queen of DaniWeb

Re: is my site been hacked?

 
0
  #4
Jan 28th, 2006
No problem. Just to double check, I resolved the IP and, indeed, it goes to a googlebot crawler. This is a good thing. It means your pages will be well-indexed in the Google search engine.
Dani the Computer Science Gal
Follow my Twitter feed! twitter.com/DaniWeb
And if you're interested in Internet marketing there is twitter.com/DaniWebAds
Reply With Quote Quick reply to this message  
Join Date: Apr 2004
Posts: 167
Reputation: Drew is an unknown quantity at this point 
Solved Threads: 7
Drew's Avatar
Drew Drew is offline Offline
Junior Poster

Re: is my site been hacked?

 
0
  #5
Jan 28th, 2006
Watch the IP's show up and watch your bandwidth meeter go up! hehe
Drew Gauderman
ASP / MSSQL Coder
http://www.iportalx.net - My ASP Portal
Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 3
Reputation: weedguru_animal is an unknown quantity at this point 
Solved Threads: 0
weedguru_animal weedguru_animal is offline Offline
Newbie Poster

Re: is my site been hacked?

 
0
  #6
Jan 28th, 2006
I trace routed the ip of the googlebot, which had mainly legitimate ips.

However one IP, owned by ABOVENET, was in the same range as 4 ips on every trace route taken from the member on the site who is most suspected of been behind any malicious activity.
This same user was using some kind of router/masking device as despite the fact that he says he is from Massechusits( i dont disbelieve this) all his ip's noted on the forums, end in the UK. I tracerouted his ips and 4 out of every 7 ip (which come up for the trace route) share a ip range ,owned by ABOVENET.
I checked trace routes on other US members of the forums and didnt get this ip range again, as of yet..

64.125.30.118 AS6461 was on the googlebots ip traceroute
and
64.125.30.118
64.125.29.133
64.125.28.129
64.125.27.166
are on the traceroutes of the 'uk' ip's logged in the phpbb forums which the suspected member has posted on lots.


does this mean anything??is it a hub which most users online in the US go through???and normal for the googlebot to be going through thee also???

EVery one of the ips we have for this user, yields traceroutes with 4 ips from that (ABOVENET)range.

Also, on every traceroute i have made for the ips from this member, the ending is the same:
[10.x.x.x] AS16559
REALCONNECT-01
[10.x.x.x] AS16559
REALCONNECT-01
then 4 hops that hit a firewall.
the last valid ip before the REALCONNECT hops is always a UK ip.

Am I completely mistaken with these connections?
and what does the REALCONNECT [10,x.x.x] mean on a traceroute???



as ever all help is very greatly appreciated...


(207.234.129.8 is the ip of a user who made threats about hacking our site)
(213.249.245.169 ) ip logged from the active member we suspect(from our phpbb boards)
Reply With Quote Quick reply to this message  
Join Date: Oct 2004
Posts: 348
Reputation: paradox814 is an unknown quantity at this point 
Solved Threads: 4
paradox814's Avatar
paradox814 paradox814 is offline Offline
Posting Whiz

Re: is my site been hacked?

 
0
  #7
Jan 30th, 2006
assuming the above user crawler is enfact google, you can tell them to slow down the way they crawl your site. You can even tell them not to crawl certain pages such as those private files/messages you mentioned

http://www.searchengineworld.com/rob...s_tutorial.htm

they even have a validator to make sure you set it up correctly.
Reply With Quote Quick reply to this message  
Reply

This thread has been marked solved.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the PHP Forum


Views: 2733 | Replies: 6
Thread Tools Search this Thread



Tag cloud for PHP
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC