• Welcome to H4O! For a reduced ad experience, please login or register with the forum.

Web Server Logs

cbetts

NERD!!!
Messages
3,188
Location
Rancho Palos Verdes, CA
I have been catching up on some long needed server maintenance on my personal web server and found some interesting data once I dug down into the web logs:
  • Someone had been trying to hack into my database through some known phpmyadmin vulnerabilities. I thought I had it locked down so only my IP could access it. Apparently, I forgot to make sure it wasn't configured in my other virtual servers and the hackers found it. So far, I have not found any evidence of munged data.
  • More people are going to Hummer Forums. Up to 2009, I was a regular user over there and posted a lot of pics that are hosted from my web server. The last two months have shown an increase of traffic from HF of 500%!
  • Some sites have been snarfing my pics to use in their spam. Here is a good example: LINKY Hey, at least they credit H4O even though I had the old club stickers on my truck still.

Time to spend some geek time this weekend that doesn't involve Xbox.
 

alrock

El Diablo
Staff member
Messages
10,670
Location
Scottsdale
Our traffic is also up significantly over last year; visits, for example, are up about 60%. I'm simply amazed at the number of new members we have signing up over here. A significant amount of our traffic is links from other forums, both Hummer and non-Hummer forums.

Our (somewhat cumbersome) signup process has been good at keeping out spammers. We get anywhere from 3-25 spammers trying to sign up each week, from such famous Hummer-owning countries like Vietnam, Philippines and Pakistan.
 

LagunaH1

Well-Known Member
Messages
3,730
Location
Idaho
Reviewing logs can be super tedious and also really important. A while back, I had a honeypot Windows XP virtual machine running with the RDP interface exposed to the internet. For a looong time nothing happened, bu then one day I started seeing LOTS of failed authentication attempts in the system log and then finally, i saw a successful login from the same IP address that had been brute-forcing my XP honeypot.

The IP address traced back to a residential IP address in Bulgaria, likely someone's home PC that had become a zombie / bot / whatever. Once the account had been compromised, I shut down the VM and deleted it.
 

LagunaH1

Well-Known Member
Messages
3,730
Location
Idaho
I can't speak to what did or didn't happen to Craig, but I completely agree that striking back is not wise. In my opinion, doing so is like picking a fight with someone who's strength and capabilities are completely unknown to you.

Edit: Not to mention that you, strictly speaking, would be violating a bunch of laws and terms of service agreements with your ISP if you were to strike back
 

Kyle

Well-Known Member
Messages
1,707
Location
Santa Clarita, CA
I can't speak to what did or didn't happen to Craig, but I completely agree that striking back is not wise. In my opinion, doing so is like picking a fight with someone who's strength and capabilities are completely unknown to you.

Edit: Not to mention that you, strictly speaking, would be violating a bunch of laws and terms of service agreements with your ISP if you were to strike back
Okay good point.
 

cbetts

NERD!!!
Messages
3,188
Location
Rancho Palos Verdes, CA
I can't speak to what did or didn't happen to Craig, but I completely agree that striking back is not wise. In my opinion, doing so is like picking a fight with someone who's strength and capabilities are completely unknown to you.

Edit: Not to mention that you, strictly speaking, would be violating a bunch of laws and terms of service agreements with your ISP if you were to strike back

Exactly on both points!
 

abearden

Well-Known Member
Messages
609
Location
N. Idaho
Yeah, pissing off someone with a botnet on rent or handy is not the way to keep your internet connection functional. That said, unless you reverse engineer and disassemble their botnet chances are they won't even notice a few hosts getting hacked.
 

autumn walker

Well-Known Member
Messages
707
Location
Nova Scotia, Canada
Reviewing logs can be super tedious and also really important. A while back, I had a honeypot Windows XP virtual machine running with the RDP interface exposed to the internet. For a looong time nothing happened, bu then one day I started seeing LOTS of failed authentication attempts in the system log and then finally, i saw a successful login from the same IP address that had been brute-forcing my XP honeypot.

The IP address traced back to a residential IP address in Bulgaria, likely someone's home PC that had become a zombie / bot / whatever. Once the account had been compromised, I shut down the VM and deleted it.

Just curious - why would you bother to set this up?
 
Top