Using .htaccess to block hackers and SPAM robots

This is an archive of the phpBB 2.0.x support forum. Support for phpBB2 has now ended.
Forum rules
Following phpBB2's EoL, this forum is now archived for reference purposes only.
Please see the following announcement for more information: viewtopic.php?f=14&t=1385785

Using .htaccess to block hackers and SPAM robots

Postby snpmarq » Sun Dec 12, 2004 8:43 pm

If you seriously want to cut down on the number of scum that are attacking phpBB web sites, you should start monitoring your system logs and using the .htaccess file to start prohibiting the morons from accessing your site.

Although the phpBB gives you some control at restricting IP's... I prefer to just deny access to the entire web sever to anyone who has shown that their intentions are strictly for hacking a server.

In some cases it is entire ranges that you need to block out to cut the weasles down and reduce the number of hijacked proxies that they travel through to attack your site.

Attached below is an .htaccess file that effectively eliminates about 80% of the internet scumbags. Before copying and pasting this .htaccess file onto your server ( if your server can handle .htaccess - just make sure that YOUR IP range is not included in this list - otherwise you will not be able to access your own site without FTPing in and altering the file ).

Some of these scumbag IP's are SPAM robots that search your forums to find e-mail addresses to add to their spamming efforts. Not only are they breaching the privacy of your user - but they are also STEALING YOUR BANDWIDTH as they parse every message posted in your forums. This cost you money.

Some of these scumbags are companies that turn robots loose on YOUR forum searching for keywords that relate to some commercial client of theirs that is paying for these robots to search the net to keep track of people who are talking about their company or product.

Mostly though, these IP's and their ranges are either blocks of the Internet that are under the control of hackers and used to launch their attacks or mass probes against sites.

And if you can cut down on the huge amounts of illegitimate traffic that will result in less traffic going to your mySQL database - leaving more CPU and database power to server your LEGITIMATE visitors.

Either way I have no patience for people who scum around the net trying to foul up web sites for some twisted pleasure.

So by using this .htaccess file you will not only cut down on the scumbags of the world who have no legitimate purpose coming to your web site, but as well you will save valuable and expensive bandwidth by not letting scums ferret through your forums in search of e-mail addresses or keywords.

Many of the IP blocks knock out entire regions of Chinese, Korean, Phillipine, Muslim extremist regions, Russian, Slovak and even some parts of Sweden where oddly enough scum bags are starting to make their presence on the Internet known...

You will be able to look at your error logs to see how many folks are getting snared up with these IP blocks and can adjust it if you find a large amount of your user traffic originates from these IP's. But I think most ENGLISH SPEAKING web sites will not suffer any real interference in their normal user traffic by using this .htaccess file in the main root of their forum or web site.

Nuff said.



<!-- copy begins directly below this -->
<Files 403.shtml>
order allow,deny
allow from all
</Files>

deny from 107.70.60.188
deny from 12.10.130.114
deny from 12.119.251.194
deny from 12.164.84.
deny from 12.170.99.
deny from 12.175.0.
deny from 12.200.10.232
deny from 12.22.85.3
deny from 12.46.236.114
deny from 129.113.29.21
deny from 129.132.49.4
deny from 129.174.163.41
deny from 129.21.24.
deny from 129.27.100.155
deny from 129.41.90.70
deny from 130.219.8.
deny from 133.163.194.
deny from 138.88.116.36
deny from 139.30.60.
deny from 140.122.
deny from 140.131.117.
deny from 141.154.195.77
deny from 141.154.96.67
deny from 141.158.65.245
deny from 141.204.246.103
deny from 141.225.101.163
deny from 142.169.66.226
deny from 142.176.239.229
deny from 142.207.113.59
deny from 147.147.20.94
deny from 148.223.48.226
deny from 148.233.165.155
deny from 148.235.0.23
deny from 148.244.
deny from 150.187.4.87
deny from 150.84.243.
deny from 151.200.140.229
deny from 151.201.40.33
deny from 151.204.137.174
deny from 152.163.253.98
deny from 153.110.132.10
deny from 155.245.23.151
deny from 156.110.28.
deny from 157.193.58.107
deny from 157.78.176.220
deny from 158.196.
deny from 159.148.
deny from 159.240.10.
deny from 161.74.11.
deny from 161.88.
deny from 162.83.119.70
deny from 162.84.114.60
deny from 163.117.139.
deny from 163.25.204.122
deny from 163.27.
deny from 163.28.48.
deny from 164.109.154.28
deny from 164.125.148.168
deny from 165.194.
deny from 165.21.154.
deny from 166.82.222.184
deny from 168.120.28.
deny from 168.143.113.138
deny from 168.143.113.241
deny from 168.166.157.3
deny from 168.240.1.2
deny from 168.9.85.227
deny from 169.199.168.3
deny from 172.176.201.170
deny from 172.178.100.239
deny from 172.192.191.250
deny from 172.197.199.186
deny from 192.231.63.
deny from 192.44.35.99
deny from 192.68.113.198
deny from 192.86.99.168
deny from 193.129.22.146
deny from 193.145.88.17
deny from 193.151.96.
deny from 193.158.30.147
deny from 193.165.
deny from 193.188.96.
deny from 193.188.97.
deny from 193.194.65.
deny from 193.198.
deny from 193.231.8.
deny from 193.251.59.214
deny from 193.251.9.124
deny from 193.255.207.253
deny from 194.108.75.90
deny from 194.125.61.
deny from 194.170.246.
deny from 194.177.254.11
deny from 194.203.201.
deny from 194.205.223.57
deny from 194.224.199.204
deny from 194.251.242.243
deny from 194.44.
deny from 194.54.59.133
deny from 194.63.235.148
deny from 194.76.219.67
deny from 194.78.30.
deny from 194.90.132.89
deny from 195.116.133.200
deny from 195.117.196.6
deny from 195.134.113.
deny from 195.144.131.35
deny from 195.149.98.
deny from 195.167.197.
deny from 195.174.127.7
deny from 195.199.138.161
deny from 195.229.241.
deny from 195.29.150.105
deny from 195.53.31.
deny from 195.68.138.
deny from 195.68.94.164
deny from 195.70.5.220
deny from 195.76.0.233
deny from 195.87.69.26
deny from 196.30.111.
deny from 196.33.
deny from 198.232.129.124
deny from 198.242.81.43
deny from 198.7.243.46
deny from 199.104.82.18
deny from 199.239.214.72
deny from 199.71.136.
deny from 20.5.130.87
deny from 200.103.137.169
deny from 200.103.181.102
deny from 200.104.70.87
deny from 200.105.135.
deny from 200.12.238.
deny from 200.138.
deny from 200.141.
deny from 200.141.132.176
deny from 200.149.244.147
deny from 200.162.
deny from 200.167.
deny from 200.170.104.
deny from 200.171.
deny from 200.177.97.71
deny from 200.182.
deny from 200.182.221.55
deny from 200.191.174.
deny from 200.195.
deny from 200.198.
deny from 200.204.196.188
deny from 200.205.
deny from 200.207.
deny from 200.211.218.131
deny from 200.216.
deny from 200.217.
deny from 200.232.
deny from 200.238.100.15
deny from 200.245.65.25
deny from 200.251.
deny from 200.255.82.3
deny from 200.31.10.19
deny from 200.34.1.91
deny from 200.35.81.
deny from 200.35.83.27
deny from 200.42.212.42
deny from 200.48.218.
deny from 200.48.235.19
deny from 200.55.4.27
deny from 200.57.151.145
deny from 200.57.45.30
deny from 200.60.
deny from 200.62.136.145
deny from 200.62.146.126
deny from 200.66.97.91
deny from 200.66.98.
deny from 200.67.53.214
deny from 200.69.
deny from 200.75.
deny from 200.83.0.197
deny from 200.83.0.201
deny from 200.87.
deny from 200.90.98.
deny from 200.93.
deny from 201.1.107.
deny from 201.1.25.
deny from 201.133.125.150
deny from 201.135.136.
deny from 202-177-154-55.sify.net
deny from 202.102.
deny from 202.108.
deny from 202.125.129.
deny from 202.129.0.14
deny from 202.131.115.
deny from 202.141.
deny from 202.144.39.154
deny from 202.149.200.
deny from 202.155.36.189
deny from 202.156.2.
deny from 202.157.192.
deny from 202.159.230.248
deny from 202.164.160.
deny from 202.177.
deny from 202.52.
deny from 202.54.193.238
deny from 202.62.
deny from 202.64.131.
deny from 202.68.143.124
deny from 202.78.
deny from 202.96.159.234
deny from 203.101.4.
deny from 203.101.74.2
deny from 203.115.31.210
deny from 203.120.188.3
deny from 203.124.158.
deny from 203.129.224.118
deny from 203.131.
deny from 203.132.226.226
deny from 203.144.
deny from 203.145.157.
deny from 203.151.
deny from 203.160.1.
deny from 203.162.
deny from 203.177.112.
deny from 203.177.148.
deny from 203.198.167.217
deny from 203.200.134.
deny from 203.200.178.
deny from 203.200.20.
deny from 203.210.
deny from 203.213.56.18
deny from 203.213.58.
deny from 204.118.191.154
deny from 204.156.186.102
deny from 204.167.116.2
deny from 204.2.20.221
deny from 204.202.2.221
deny from 204.249.102.34
deny from 204.249.102.35
deny from 205.137.32.56
deny from 205.138.200.2
deny from 205.141.207.226
deny from 205.142.119.14
deny from 205.155.196.131
deny from 205.158.224.234
deny from 205.188.116.68
deny from 205.206.126.230
deny from 205.218.254.
deny from 205.221.40.142
deny from 205.236.2.
deny from 206.163.199.1
deny from 206.204.190.4
deny from 206.78.202.225
deny from 206.82.81.5
deny from 207.127.0.2
deny from 207.127.1.2
deny from 207.127.8.2
deny from 207.134.160.78
deny from 207.134.161.61
deny from 207.14.106.1
deny from 207.234.131.126
deny from 207.248.159.230
deny from 207.248.159.253
deny from 207.30.229.130
deny from 207.31.251.140
deny from 207.46.98.
deny from 207.68.50.57
deny from 207.68.79.5
deny from 207.68.98.5
deny from 207.69.138.143
deny from 208.0.125.18
deny from 208.18.144.13
deny from 208.185.16.39
deny from 208.201.244.132
deny from 208.216.88.41
deny from 208.234.37.71
deny from 208.35.141.40
deny from 208.42.101.241
deny from 208.42.127.45
deny from 208.6.1.5
deny from 209.10.134.56
deny from 209.10.134.57
deny from 209.10.134.58
deny from 209.10.134.59
deny from 209.10.134.60
deny from 209.10.134.61
deny from 209.10.134.62
deny from 209.10.134.63
deny from 209.113.151.
deny from 209.137.251.218
deny from 209.158.182.202
deny from 209.166.55.15
deny from 209.183.136.159
deny from 209.184.108.162
deny from 209.198.
deny from 209.226.98.131
deny from 209.232.65.
deny from 209.235.241.82
deny from 209.251.3.194
deny from 209.26.56.10
deny from 209.50.252.
deny from 209.51.138.18
deny from 209.61.157.
deny from 209.67.219.178
deny from 210.119.114.6
deny from 210.14.
deny from 210.150.253.
deny from 210.172.204.52
deny from 210.173.179.
deny from 210.177.253.73
deny from 210.18.136.
deny from 210.18.184.
deny from 210.187.5.196
deny from 210.212.
deny from 211.1.102.67
deny from 211.133.241.165
deny from 211.151.
deny from 211.161.
deny from 211.162.
deny from 211.185.
deny from 211.20.
deny from 211.215.21.154
deny from 211.239.74.
deny from 211.248.
deny from 211.250.81.252
deny from 211.26.172.142
deny from 211.46.75.189
deny from 211.90.168.94
deny from 211.92.
deny from 211.93.
deny from 211.98.28.105
deny from 211.99.79.100
deny from 212.11.184.
deny from 212.129.232.100
deny from 212.138.64.
deny from 212.138.65.
deny from 212.138.66.
deny from 212.138.67.
deny from 212.138.68.
deny from 212.138.69.
deny from 212.138.70.
deny from 212.158.243.
deny from 212.160.159.60
deny from 212.165.
deny from 212.199.252.21
deny from 212.205.245.
deny from 212.21.121.196
deny from 212.217.0.
deny from 212.217.1.
deny from 212.217.2.
deny from 212.27.41.
deny from 212.29.32.
deny from 212.31.242.
deny from 212.33.86.47
deny from 212.42.
deny from 212.47.27.186
deny from 212.86.208.
deny from 213.10.103.110
deny from 213.112.195.17
deny from 213.115.201.207
deny from 213.128.225.93
deny from 213.130.53.94
deny from 213.131.168.204
deny from 213.131.168.205
deny from 213.131.168.206
deny from 213.131.168.207
deny from 213.131.65.
deny from 213.131.74.
deny from 213.134.168.35
deny from 213.139.192.139
deny from 213.146.148.179
deny from 213.156.63.50
deny from 213.178.
deny from 213.193.131.122
deny from 213.200.242.18
deny from 213.203.138.51
deny from 213.210.152.
deny from 213.219.84.
deny from 213.219.85.
deny from 213.24.168.
deny from 213.24.169.
deny from 213.249.155.239
deny from 213.25.96.194
deny from 213.250.163.50
deny from 213.27.139.109
deny from 213.42.2.
deny from 213.46.99.
deny from 213.69.149.153
deny from 213.77.160.158
deny from 213.8.52.84
deny from 213.80.133.
deny from 213.81.198.
deny from 213.81.198.239
deny from 213.9.220.254
deny from 216.11.71.2
deny from 216.119.173.251
deny from 216.124.224.123
deny from 216.139.176.
deny from 216.142.221.99
deny from 216.143.84.
deny from 216.148.62.202
deny from 216.157.225.36
deny from 216.160.35.130
deny from 216.185.83.
deny from 216.224.44.42
deny from 216.226.43.91
deny from 216.23.208.220
deny from 216.244.131.
deny from 216.26.248.18
deny from 216.31.40.2
deny from 216.31.40.34
deny from 216.43.79.67
deny from 216.60.21.4
deny from 216.63.70.170
deny from 216.66.110.34
deny from 216.70.34.17
deny from 216.72.28.100
deny from 216.83.96.37
deny from 216.94.44.109
deny from 217.113.112.17
deny from 217.118.
deny from 217.144.
deny from 217.149.51.130
deny from 217.153.183.230
deny from 217.157.162.
deny from 217.17.18.17
deny from 217.217.
deny from 217.218.
deny from 217.219.
deny from 217.222.94.
deny from 217.227.106.24
deny from 217.248.87.
deny from 217.37.119.42
deny from 217.6.171.36
deny from 217.68.109.5
deny from 217.73.171.
deny from 217.73.172.
deny from 217.73.173.
deny from 217.81.20.
deny from 218.12.196.42
deny from 218.156.24.251
deny from 218.188.8.
deny from 218.2.
deny from 218.3.
deny from 218.4.
deny from 218.50.
deny from 218.51.
deny from 218.52.
deny from 218.53.
deny from 218.54.
deny from 218.55.
deny from 218.57.113.11
deny from 218.57.143.253
deny from 218.58.50.68
deny from 218.6.
deny from 218.78.
deny from 218.79.
deny from 218.80.
deny from 218.81.
deny from 218.82.
deny from 218.83.
deny from 218.90.
deny from 218.91.
deny from 218.92.
deny from 218.93.
deny from 218.94.
deny from 219.128.
deny from 219.129.
deny from 219.130.
deny from 219.131.
deny from 219.132.
deny from 219.133.
deny from 219.134.
deny from 219.135.
deny from 219.136.
deny from 219.137.
deny from 219.144.
deny from 219.148.151.187
deny from 219.163.74.244
deny from 219.213.
deny from 219.64.
deny from 219.65.
deny from 219.76.190.217
deny from 219.95.
deny from 220.107.233.
deny from 220.141.
deny from 220.224.
deny from 220.225.
deny from 220.226.
deny from 220.227.
deny from 220.228.
deny from 220.229.
deny from 220.234.
deny from 220.247.244.
deny from 220.65.103.124
deny from 220.76.248.
deny from 221.13.
deny from 221.137.
deny from 221.14.
deny from 221.15.
deny from 221.186.130.115
deny from 221.192.
deny from 221.193.
deny from 221.194.
deny from 221.195.
deny from 221.224.33.227
deny from 221.24.17.
deny from 222.115.
deny from 222.150.
deny from 24.10.158.104
deny from 24.11.115.24
deny from 24.110.37.37
deny from 24.114.169.104
deny from 24.131.109.26
deny from 24.150.141.30
deny from 24.171.132.150
deny from 24.199.170.210
deny from 24.239.146.100
deny from 24.25.214.116
deny from 24.3.40.91
deny from 24.31.253.194
deny from 24.45.253.
deny from 24.53.214.63
deny from 24.76.7.124
deny from 24.91.161.26
deny from 24.95.134.142
deny from 24.95.227.86
deny from 4.11.65.239
deny from 4.15.116.
deny from 4.226.204.72
deny from 44.218.
deny from 47.248.0.4
deny from 61.0.
deny from 61.1.
deny from 61.11.
deny from 61.129.69.166
deny from 61.185.214.114
deny from 61.193.
deny from 61.2.
deny from 61.3.
deny from 61.55.
deny from 61.57.30.20
deny from 61.66.90.
deny from 62.119.133.
deny from 62.131.81.
deny from 62.135.
deny from 62.139.1.3
deny from 62.153.127.75
deny from 62.159.241.206
deny from 62.161.77.185
deny from 62.193.130.
deny from 62.212.232.
deny from 62.23.87.51
deny from 62.233.244.13
deny from 62.241.
deny from 62.254.0.30
deny from 62.254.193.
deny from 62.39.245.170
deny from 62.49.25.139
deny from 62.58.77.
deny from 62.60.128.
deny from 62.60.129.
deny from 62.60.130.
deny from 62.60.131.
deny from 62.65.205.
deny from 62.84.71.
deny from 62.87.136.
deny from 62.87.154.42
deny from 62.96.53.
deny from 63.148.99.
deny from 63.168.93.50
deny from 63.171.232.248
deny from 63.188.168.60
deny from 63.197.109.187
deny from 63.203.65.
deny from 63.208.219.
deny from 63.218.109.130
deny from 63.227.76.25
deny from 63.237.47.170
deny from 63.240.253.
deny from 63.242.156.234
deny from 63.245.15.201
deny from 64.110.74.244
deny from 64.124.25.
deny from 64.124.85.
deny from 64.14.144.85
deny from 64.14.241.60
deny from 64.140.
deny from 64.169.91.
deny from 64.172.130.219
deny from 64.185.35.10
deny from 64.201.174.37
deny from 64.216.87.88
deny from 64.217.122.131
deny from 64.230.69.59
deny from 64.25.11.13
deny from 64.250.195.33
deny from 64.62.142.
deny from 64.62.168.
deny from 64.71.144.
deny from 64.86.231.
deny from 64.90.204.86
deny from 65.10.14.170
deny from 65.100.172.162
deny from 65.103.182.5
deny from 65.110.54.92
deny from 65.121.189.240
deny from 65.121.189.241
deny from 65.121.189.243
deny from 65.121.189.244
deny from 65.121.189.245
deny from 65.121.189.246
deny from 65.121.189.247
deny from 65.126.250.14
deny from 65.16.245.131
deny from 65.207.49.69
deny from 65.254.129.40
deny from 65.27.132.213
deny from 65.31.224.88
deny from 65.34.149.86
deny from 65.35.214.192
deny from 65.5.253.51
deny from 65.50.50.243
deny from 65.54.188.
deny from 65.67.56.74
deny from 65.82.181.165
deny from 66.103.44.115
deny from 66.109.103.117
deny from 66.110.115.
deny from 66.126.225.69
deny from 66.130.147.44
deny from 66.133.240.172
deny from 66.14.145.9
deny from 66.147.166.131
deny from 66.151.181.
deny from 66.162.218.108
deny from 66.166.111.48
deny from 66.166.195.107
deny from 66.168.167.76
deny from 66.172.174.132
deny from 66.192.30.22
deny from 66.192.31.98
deny from 66.193.160.126
deny from 66.193.64.163
deny from 66.194.55.
deny from 66.194.6.
deny from 66.198.
deny from 66.205.54.
deny from 66.205.55.
deny from 66.207.118.
deny from 66.207.120.227
deny from 66.213.223.218
deny from 66.216.85.154
deny from 66.229.158.211
deny from 66.229.163.227
deny from 66.234.235.202
deny from 66.234.255.2
deny from 66.239.80.25
deny from 66.239.80.52
deny from 66.24.229.173
deny from 66.30.17.58
deny from 66.35.206.150
deny from 66.41.201.93
deny from 66.43.173.226
deny from 66.57.251.148
deny from 66.68.213.87
deny from 66.72.186.
deny from 66.74.194.101
deny from 66.82.9.41
deny from 66.9.142.98
deny from 66.95.12.10
deny from 66.98.208.
deny from 66.98.212.
deny from 66.98.226.
deny from 66.99.56.130
deny from 66.99.56.2
deny from 67.107.64.65
deny from 67.113.59.194
deny from 67.115.135.
deny from 67.115.135.84
deny from 67.122.183.22
deny from 67.128.27.
deny from 67.138.247.
deny from 67.153.93.156
deny from 67.161.0.152
deny from 67.3.155.100
deny from 67.37.184.228
deny from 67.40.239.217
deny from 67.64.106.99
deny from 67.95.211.196
deny from 67.97.9.
deny from 67.98.152.
deny from 68.102.109.157
deny from 68.110.130.167
deny from 68.114.113.147
deny from 68.123.102.165
deny from 68.123.45.10
deny from 68.126.62.12
deny from 68.150.206.51
deny from 68.152.252.74
deny from 68.153.184.60
deny from 68.161.240.236
deny from 68.165.169.202
deny from 68.17.179.61
deny from 68.203.209.193
deny from 68.206.39.236
deny from 68.209.178.57
deny from 68.33.2.161
deny from 68.43.241.79
deny from 68.47.80.230
deny from 68.49.39.117
deny from 68.50.157.69
deny from 68.69.9.209
deny from 68.81.248.22
deny from 68.82.71.118
deny from 68.83.130.39
deny from 68.9.52.89
deny from 68.95.163.
deny from 69.111.170.
deny from 69.141.0.209
deny from 69.164.142.246
deny from 69.17.70.106
deny from 69.172.2.76
deny from 69.200.17.142
deny from 69.200.20.241
deny from 69.200.29.117
deny from 69.226.45.
deny from 69.41.207.134
deny from 69.44.61.
deny from 69.56.215.106
deny from 69.57.158.85
deny from 69.64.34.
deny from 69.8.178.
deny from 70.245.126.71
deny from 80.133.101.
deny from 80.133.103.
deny from 80.133.115.187
deny from 80.138.68.
deny from 80.146.179.178
deny from 80.16.106.83
deny from 80.164.55.
deny from 80.164.58.
deny from 80.191.
deny from 80.206.246.195
deny from 80.247.154.
deny from 80.247.155.
deny from 80.51.
deny from 80.53.214.243
deny from 80.55.
deny from 80.55.205.
deny from 80.58.
deny from 80.65.103.231
deny from 80.98.224.
deny from 81.118.4.
deny from 81.134.245.43
deny from 81.144.175.75
deny from 81.189.238.
deny from 81.19.98.
deny from 81.191.126.
deny from 81.192.194.
deny from 81.210.123.250
deny from 81.223.24.101
deny from 81.241.227.142
deny from 81.75.88.186
deny from 81.80.165.
deny from 81.93.4.
deny from 81.95.102.101
deny from 82.135.33.100
deny from 82.187.20.210
deny from 82.189.153.
deny from 82.55.120.
deny from 82.67.84.
deny from 82.67.85.
deny from 82.76.74.61
deny from 83.116.108.
deny from 83.16.
deny from 83.36.
deny from 83.64.161.34
deny from 84.121.129.245
deny from 84.205.2.29
deny from 84.219.18.
deny from 84.31.118.
deny from eth1.cache1.dubaiinternetcity.net
deny from eth1.cache2.dubaiinternetcity.net
deny from ns.hatena.ne.jp
deny from r58.realnet.ds.netlab.sk
deny from 84.219.18.
deny from 24.8.99.28
deny from 194.224.225.
deny from 219.101.248.
deny from 65.68.3.
deny from 63.87.232.89
deny from 70.17.66.63
<!-- copy ends immediately above this -- >

Paste this content to a file called .htaccess and tranfer the saved file to the html directory of your web site and also place it in the forum root of your phpBB.

The file should list in your directory as .htaccess

Yes... there is a period and then the word htaccess

If your server knows what to do with this file, it should cut down on the nonsense you are being subjected to... as this list has been built up over the last 9 months and still keeps nailing the turkeys who all tend to use the same IP's to launch their attacks.

Please NOTE : None of the major search engine IPs are included in this list... although there are three 'experimental' search engines listed that have proven to be totally abusive are bandwidth consumption as they ferret sites. They won't be missed because it is not likely that anyone needs traffic from some experimental search engine being developed in Turkey etc. that will probably never become mainstream or even operational.




.
Last edited by snpmarq on Sun Dec 12, 2004 9:55 pm, edited 2 times in total.
snpmarq
Registered User
 
Posts: 30
Joined: Sun Jan 05, 2003 11:00 pm

Postby bico » Sun Dec 12, 2004 9:23 pm

What are the sources of those IP-addresses and domain-names? How did someone collect them? How were they identified as being "scum(bags)"?

And what does

Code: Select all
<Files 403.shtml>
order allow,deny
allow from all
</Files>


do? I don't remember and I'm to lazy to RTFM... ;-).
bico
Registered User
 
Posts: 385
Joined: Thu Aug 12, 2004 6:39 pm
Location: Stockholm, Sweden.

Postby snpmarq » Sun Dec 12, 2004 9:46 pm

I am sorry but I really cannot give a lesson on the use of .htaccess files here. People who do not know what an .htaccess file is shouldn't really be tinkering with that on their web server.

The info is really for the benefit of those folks who know already what the .htaccess file does on their server.

Use Google and search out the information if you want to learn more about them.

http://www.google.ca/search?num=100&hl= ... file&meta=

Suffice to say that it instructs the server which IP's to allow on to the server and which ones to DENY and it will only throw a 403 error page at those visitors originating from any of the blacklisted IPs. It basically blocks them from accessing ANYTHING on your server other then the 403.shtml error page.

The IP's are a culmulative collection gathered from the error logs of four security specific web sites. As such they encounter an extremely high number of lads trying to hack the phpBB...

.
snpmarq
Registered User
 
Posts: 30
Joined: Sun Jan 05, 2003 11:00 pm

Postby josian » Fri Dec 17, 2004 1:31 am

snpmarq wrote:I am sorry but I really cannot give a lesson on the use of .htaccess files here. People who do not know what an .htaccess file is shouldn't really be tinkering with that on their web server.

The info is really for the benefit of those folks who know already what the .htaccess file does on their server.

Use Google and search out the information if you want to learn more about them.

http://www.google.ca/search?num=100&hl= ... file&meta=

Suffice to say that it instructs the server which IP's to allow on to the server and which ones to DENY and it will only throw a 403 error page at those visitors originating from any of the blacklisted IPs. It basically blocks them from accessing ANYTHING on your server other then the 403.shtml error page.

The IP's are a culmulative collection gathered from the error logs of four security specific web sites. As such they encounter an extremely high number of lads trying to hack the phpBB...

.


Thank you very much my friend!

This should be put on sticky, and you should update this list frequently.
My firewall techs have work to do tonite! :D
josian
Registered User
 
Posts: 142
Joined: Sat Mar 20, 2004 2:56 am

Postby tim_welch » Tue Nov 08, 2005 1:01 pm

Does anyone know if this list is still 'active' and current and should be added to .htaccess? Or if there is a better/updated list?
User avatar
tim_welch
Registered User
 
Posts: 163
Joined: Tue Aug 17, 2004 11:41 am
Location: London, UK

Postby TasDevil » Tue Nov 08, 2005 2:29 pm

Well, in my opinion this list maybe useful for a few users, but not at all for many of us. Why not add the IP addresses of FBI/CIA/NSA, etc., too? I could give you a link to a website where they all are listed.

I think everyone has to make an own list according to the own needs.

Tas.
TasDevil
Registered User
 
Posts: 319
Joined: Tue Mar 15, 2005 5:49 am

Postby tim_welch » Tue Nov 08, 2005 2:38 pm

Yeah, I didn't really read the text around this post, just the IP listing. I guess I see what you mean. Perhaps my question should be more 'How does one identify IPs that are killing bandwidth and server processing power?'.
User avatar
tim_welch
Registered User
 
Posts: 163
Joined: Tue Aug 17, 2004 11:41 am
Location: London, UK

Postby TasDevil » Tue Nov 08, 2005 2:49 pm

tim_welch wrote:Perhaps my question should be more 'How does one identify IPs that are killing bandwidth and server processing power?'.

Sorry to answer a bit ironically, but as I don't beleave that to block whole countries or usergroups of any kind with *technical* solutions is useful, you could on a small board: block all search engines, and on a large board: block additionally all users.

You'll have much less traffic then. But is that the sense of a bulletin board?

Tas.
TasDevil
Registered User
 
Posts: 319
Joined: Tue Mar 15, 2005 5:49 am

Postby tim_welch » Tue Nov 08, 2005 2:53 pm

No, I understand what you are saying. Perhaps I'm misunderstanding something along these lines then. Let me explain why I'm asking in the first place:

I've been getting around 10 concurrent guest hits on my account repeatedly from 207.226.22.176 (Beyond The Network America) which appears to have been browsing my site quite aggressively. To my knowledge this isn't a Google-bot or anything 'nice' so my assumption was that it was a bad-bot of some sort. Hence, for the moment, I've added this to my deny list on .htaccess. Perhaps I'm wrong to do so... I guess that's why I was looking for a similar listing.
User avatar
tim_welch
Registered User
 
Posts: 163
Joined: Tue Aug 17, 2004 11:41 am
Location: London, UK

Postby TasDevil » Tue Nov 08, 2005 3:02 pm

tim_welch wrote:I've been getting around 10 concurrent guest hits on my account repeatedly from 207.226.22.176 (Beyond The Network America) which appears to have been browsing my site quite aggressively.

That will be a private user's web spider like Teleport Pro or HTTrack which is downloading your site. Nothing unusual. Just ban the single IP addess as you did. My first answer above was also on the IP list in the first post, and I don't trust "just a list" without any comments on the listed addresses as everyone has different needs, such a list will seldom be useful for others but the author without checking every single entry.

Tas.
TasDevil
Registered User
 
Posts: 319
Joined: Tue Mar 15, 2005 5:49 am

Postby tim_welch » Tue Nov 08, 2005 3:07 pm

I understand and your comments are much appreciated. Would you know of any easy way to identify such spiders other than simply looking at the list of current users on the main ACP page?

For example, if my site appears to have more than 2 sessions from the same IP, is that a spider? Or should you ban only if you get 5 or 10 or ...? Perhaps the question has no one answer.

I presume if someone has more than one current and active browser windows open connecting to the site, that doesn't make two IP sessions appear, does it?
User avatar
tim_welch
Registered User
 
Posts: 163
Joined: Tue Aug 17, 2004 11:41 am
Location: London, UK

Postby TasDevil » Tue Nov 08, 2005 3:24 pm

tim_welch wrote:I understand and your comments are much appreciated. Would you know of any easy way to identify such spiders other than simply looking at the list of current users on the main ACP page?

For example, if my site appears to have more than 2 sessions from the same IP, is that a spider? Or should you ban only if you get 5 or 10 or ...? Perhaps the question has no one answer.

I presume if someone has more than one current and active browser windows open connecting to the site, that doesn't make two IP sessions appear, does it?

First question: No, I don't think so. These programs can emulate any browser, so the only difference will be the number of page views per time interval.

Second question: It maybe a spider, but not always. I use two computers, too, so I also have two sessions for the same username. But there's a fix for that in this KB article: http://www.phpbb.com/kb/article.php?article_id=42

Limiting the number of sessions per IP

This fix should only be used if you are experiencing problems with too many sessions being created for one user

Maybe you want to try this fix.

Third question: afaik different browser windows don't generate multiple sessions, but different browser installations will do that, even on the same machine.

Tas.
TasDevil
Registered User
 
Posts: 319
Joined: Tue Mar 15, 2005 5:49 am

Postby tim_welch » Tue Nov 08, 2005 4:47 pm

Thanks. :)
User avatar
tim_welch
Registered User
 
Posts: 163
Joined: Tue Aug 17, 2004 11:41 am
Location: London, UK


Return to 2.0.x Support Forum

Who is online

Users browsing this forum: No registered users and 13 guests