Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    May 2006
    Posts
    6

    Default Strange http query attack

    Hello Im Daniel,

    I have a problem since yesterday in one of my servers, Im receiving between 200 and 300 hits by second from different IPs to a non existent path in a site, the hits are going to different cracks, films and download query's, but this site is a directory and its not a warez or p2p site.

    The site is onemilliondirectory.com, and I have suspended it because it was using a lot of recourses of the first server, now its being redirected to other location, I have placed some traffic trackers to determine the referer or any other usefull info about the visitors, but the referer is always empty and I think that they are fake users because the statcounter tracker do not recognize the visits.

    For example, some of the hits are:
    Code:
    GET /suspended.page/?v=ABC%204%20KIDS%20Workshop%201.0.zip HTTP
    GET /suspended.page/?v=DecryptSQL%202.8.zip HTTP/1.1
    GET /suspended.page/?v=[0]%20Msn%20Live%20Messenger%20Mobile.zip
    GET /inactive.html?v=Able%20Photo%20Slide%20Show%202.2.5.5.zip
    GET /suspended.page/?v=English%20Grammar%20Worksheet%201.4.zip
    GET /inactive.html?v=Karaoke%205%2030.zip HTTP/1.1
    GET /suspended.page/?v=Nero%208%208.3.2.1.zip HTTP/1.1
    Detail of one of the visits from the cpanel latest visitors tool:
    Code:
    Host: 82.246.88.241
    /inactive.html?a=Knowing.2009.TS.FRENCH.XVID-PaGlop.****************.[emule-island.com].avi
    	Http Code: 200 	Date: Apr 07 16:39:54 	Http Version: HTTP/1.1 	Size in Bytes: 262
    	Referer: -
    	Agent: Internet Explorer
    Someone knows what could be happening and how to stop it? Someone had a similar experience?

    PD:I was checking the stats of the site and I have seen as a referer of one of the visits this url: blackhatbootcamp.com /affiliates.html, Im not sure if it has any relation with the problem.

    Thanks in advance
    Daniel
    Last edited by dannet; 04-09-2009 at 02:27 PM.

  2. #2
    Member big_bull's Avatar
    Join Date
    Nov 2006
    Posts
    148
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Hello,

    Please check following links and install the script.

    http://www.webhostingtalk.com/showthread.php?t=515259
    http://deflate.medialayer.com/
    Last edited by big_bull; 04-12-2009 at 08:59 PM.
    “I am easily satisfied with the very best.”

  3. #3
    Member
    Join Date
    May 2006
    Posts
    6

    Default

    Hi big_bull, thanks for your reply, I have tryied with the script but the problem is that all the requests are from different IPs.

  4. #4
    cPanel Partner NOC cPanel Partner NOC Badge
    Join Date
    Oct 2003
    Posts
    1,931

    Default

    make sure your running the APF firewall if not set it to APF_BAN=0 in the config file else it will do nothing
    Lowest Host/Empire Technology LLC
    Affordable hosting solutions http://empire-hosting.net
    List Your hosting site FREE in http://hostgeneration.com

Similar Threads & Tags
Similar threads

  1. Apache Status and HTTP Requests of "OPTIONS * HTTP/1.0"
    By DReade83 in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 12-02-2009, 12:47 AM
  2. HTTP Response Splitting Attack
    By helper in forum Security
    Replies: 1
    Last Post: 11-20-2009, 12:11 PM
  3. HELP PLZ - http://domain + http://www.domain same target using cpanel
    By britishnproud in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-12-2007, 06:20 PM
  4. installing mambo at http://www... not http://
    By taite11 in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-03-2005, 12:40 PM
  5. Replies: 9
    Last Post: 04-21-2005, 03:56 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube