GetDotted Domains

Viewing Thread:
"Hacking attempt - log spam?"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Wed 05/03/08 at 16:08
Moderator
"Are you sure?"
Posts: 5,000
In the last few weeks I've noticed a new kind of 'log' spam taking place with some of my sites.

It's not the more normal 'referrer spam' - the spam URL is in the page 'requests' - (this is not just Freeola sites!)

Some of my websites track out-going links and sites I have hosted where the raw log is available also show similar problems.

The spammers add their address to the out-going link:
http://www.real-link.co.uk/page.shtml? id=http%3A%2F%2Fwww.spammer - site.com%2Far%2Farticles%2Fjed%2Fumut%2F&links

I'm seeing lots of similar addresses. Searching for snippets of the url shows lots of others are also having the problem:
Google: %2Fadmin%2Fcorreo%2Fenaq% to see more examples and some discussion.

It seems someone/thing has been attacking sites trying to either spam or test for vulnerabilities. The attacks come from numerous addresses - no doubt sites/servers that are acting as zombies.

The links created are broken (404) so don't seem to be serving any purpose (Google bomb for example)?

Thought I would share this with you all ;¬)
I'm following discussions on a few sites to see if anyone has a good way of stopping this (using .htaccess perhaps) - If anything useful comes up I'll update this thread.

Obviously if anyone has any suggestions, please let me know.




Search Freeola Chat
Tue 18/03/08 at 13:17
Moderator
"Are you sure?"
Posts: 5,000
I still see this 'attack' every few weeks or so. I've found lots of other posts but no solution yet.

This page www.seo-blackhat.com removespace /article/someone-is-scraping-me.html documents the IP addresses of the 'zombie' PCs.

I guess someone has released a malicious game or application that is infecting PCs/servers.

Some people have commented saying that they think it may be testing a hosting companies security vulnerabilities - have Freeola seen any of this activity?




Search Freeola Chat
Wed 05/03/08 at 17:02
Regular
"Devil in disguise"
Posts: 3,151
Hmmm... wrote:
> The links created are broken (404) so don't seem to be serving
> any purpose (Google bomb for example)?

Maybe some sort of identification. Brute force attack on thousands of sites with a unique query string. Then you go googling to see what results come up and if anything has done anything "interesting" with the url.

Generally I think its a mistake to believe that most of these attacks have a specific purpose anyway. They're more like playing the percentages, chuck something out there and see what happens.

Easiest solution is mod_rewrite I guess. You can check the query string for http (assuming your sites dont allow http in the query string) and then throw a 403 or 412. Although not going to make an awful lot of difference as it'll still appear in your logs, just with a different error code. :)
Wed 05/03/08 at 16:08
Moderator
"Are you sure?"
Posts: 5,000
In the last few weeks I've noticed a new kind of 'log' spam taking place with some of my sites.

It's not the more normal 'referrer spam' - the spam URL is in the page 'requests' - (this is not just Freeola sites!)

Some of my websites track out-going links and sites I have hosted where the raw log is available also show similar problems.

The spammers add their address to the out-going link:
http://www.real-link.co.uk/page.shtml? id=http%3A%2F%2Fwww.spammer - site.com%2Far%2Farticles%2Fjed%2Fumut%2F&links

I'm seeing lots of similar addresses. Searching for snippets of the url shows lots of others are also having the problem:
Google: %2Fadmin%2Fcorreo%2Fenaq% to see more examples and some discussion.

It seems someone/thing has been attacking sites trying to either spam or test for vulnerabilities. The attacks come from numerous addresses - no doubt sites/servers that are acting as zombies.

The links created are broken (404) so don't seem to be serving any purpose (Google bomb for example)?

Thought I would share this with you all ;¬)
I'm following discussions on a few sites to see if anyone has a good way of stopping this (using .htaccess perhaps) - If anything useful comes up I'll update this thread.

Obviously if anyone has any suggestions, please let me know.




Search Freeola Chat

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

10/10
Over the years I've become very jaded after many bad experiences with customer services, you have bucked the trend. Polite and efficient from the Freeola team, well done to all involved.
Everybody thinks I am an IT genius...
Nothing but admiration. I have been complimented on the church site that I manage through you and everybody thinks I am an IT genius. Your support is unquestionably outstanding.
Brian

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.