Announcement

Collapse
No announcement yet.

Is this a hacker? How do I disconnect him?

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Is this a hacker? How do I disconnect him?

    Hi Folks,

    For the last 36 hours I have been watching an unregistered user who has been connected to our boards continuously (tho I didn't stay up all night ).

    He appears as 'Guest' in the "Who's Online" listing, but has spent all of his time trying to access the forum without registering. or at least I think he has.

    His activities at different times get shown as 'Editing a Post', 'Reporting a Post', 'Sending Post to a Friend', 'Quoting Post', or 'Moderator Duties'. Unregistered users are not allowed to do any of the above and, since we noticed this activity, Guests are not allowed to even view the boards any more (for the moment).

    When a guest tries to perfrom any of the activities listed above, they are taken to the 'You are not allowed to do this. Register or Log In' page. Since he has not registered (neither his ip, nor the subnet he is on has ever been used by a registered user) I can only conclude that it is some kind of attempt to guess a Username/Password combination that will let him masquerade as someone else.

    I have banned his ip and subnet, but banning only seems to apply to registered users. (So at least he will be banned if he DOES guess a password.)

    Turning off the boards for a period makes no difference as he is already past the Homepage stage, so he can apparently carry on regardless.

    Anyone seen this kind of activity before? Can anyone see what it might be if not a hacking attempt? How can I kick him off the boards without shutting down the servers themselves? A restart of Apache should have removed him, but failed.

    Thanks for any ideas!

  • #2
    This is just a search engine spidering your site. Just because you banned the IP doesn't mean it will stop going through your site. All it means is that it's getting the 'No permissions' screen.
    Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
    Change CKEditor Colors to Match Style (for 4.1.4 and above)

    Steve Machol Photography


    Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


    Comment


    • #3
      Thanks for the quick response. The activity has been confined to just one (of 40) forums on the board. Do you know if this is consistent with spiders?

      How long do they tend to keep going before they move on to another site?

      Comment


      • #4
        I've had them on my site for 4-5 days at a time.
        Steve Machol, former vBulletin Customer Support Manager (and NOT retired!)
        Change CKEditor Colors to Match Style (for 4.1.4 and above)

        Steve Machol Photography


        Mankind is the only creature smart enough to know its own history, and dumb enough to ignore it.


        Comment


        • #5
          You can prevent them from stealing unnecessary bandwidth: http://www.vbulletin.com/forum/showt...threadid=45828
          Marc James
          Sports Central — Beyond the Scores
          Sports Central Message Boards

          Comment

          widgetinstance 262 (Related Topics) skipped due to lack of content & hide_module_if_empty option.
          Working...
          X