Blog · Forums · Podcast
Advertisement



fake phpBB user sessions crashing server

 
Post new topic   Reply to topic    Talk About Comics Forum Index -> TalkAboutComics.com Forum Help
View previous topic :: View next topic  
Author Message
joey
Site Admin


Joined: 28 May 2002
Posts: 3601

PostPosted: Fri Sep 01, 2006 9:21 pm    Post subject: fake phpBB user sessions crashing server Reply with quote

There's a flood of fake phpBB user sessions, coming from numerous different IP addresses, crashing the whole server every few hours.

Probably spambots.

Fellow admins: any thoughts on solving this?

Note that I tried my best to install bad behavior, but its header-pushing ways conflicted with sessions.php and page_header.php no matter what I tried.

Joey
www.webcomicsnation.com
Back to top
View user's profile Send private message Send e-mail
joey
Site Admin


Joined: 28 May 2002
Posts: 3601

PostPosted: Fri Sep 01, 2006 9:27 pm    Post subject: Re: fake phpBB user sessions crashing server Reply with quote

A large number of the spambots seem to have IP addresses that resolved to:

red.telefonica-wholesale.net

I know that Reinder has banned an entire ISP or two before, but I don't know how to do this. Any help?

Joey
Back to top
View user's profile Send private message Send e-mail
reinder
Modern Tales Family Cartoonist


Joined: 29 May 2002
Posts: 2024
Location: Groningen, the Netherlands

PostPosted: Sat Sep 02, 2006 10:00 am    Post subject: Reply with quote

Are there any consecutive IP ranges you can find? I can at least ban those.
By the way, from Samspade.org it looks like the Telefonica in that address is the same Telefonica, in Spain, that owned the IP ranges I banned earlier.

Two problems with banning all of Telefonica:

1) They are a near-monopolist in Spain;
2) They are aggressively expanding into other countries, buying up ISPs and privatised telephone companies left and right. One of the companies they have their eyes on is the Dutch Telephone Company KPN, which owns several of the largest ISPs in the Netherlands. The collateral damage would, in other words, be considerable, bordering on making TAC an Anglosphere-only shop.

Reasons to do it anyway:
Telefonica has a reputation for being completely unresponsive to complaints about spam and generally deserve to be destroyed. The collateral damage would be considerable but so would the contribution to solving the spam problem.
_________________
Reinder Dijkhuis
Rogues of Clwyd-Rhan | Blog |
Preorder Headsmen minicomic now
Back to top
View user's profile Send private message Send e-mail Visit poster's website
joey
Site Admin


Joined: 28 May 2002
Posts: 3601

PostPosted: Sun Sep 03, 2006 10:02 am    Post subject: Reply with quote

Okay, so, here's the thing.

I looked at the user sessions in the actual database table, and I found some weirdnesses with the spambots:

1. They were showing up with user_id numbers that were less than -1. Apparantly a non-logged-in user is supposed to show up with a user_id of -1 (I tested this myself while I had the TAC forums hidden on the server, by coming to the site as a non-logged-in user), and a logged-in user, of course, shows up with his/her actual user id in the sessions table. These guys were showing up with user id numbers of -6 or -8 or -9, which technically shouldn't be possible -- meaning that they are probably screwing with the scripts by sending along weird querystrings -- perhaps this is a new bug in phpBB that is just now being exploited (I've noticed that most of the bugs in phpBB in the past have related to poor filtering of user input). So I changed sessions.php to take any user session that is less than -1 and change it to -1 before adding it to the database.

2. They were showing up with page numbers that were also negative. I changed sessions.php to die if a user requested a page number that was negative.

This seems to have stabilized the server for now, though we are still getting flooded.

Joey
www.talkaboutcomics.com
Back to top
View user's profile Send private message Send e-mail
joey
Site Admin


Joined: 28 May 2002
Posts: 3601

PostPosted: Mon Sep 11, 2006 8:32 pm    Post subject: Reply with quote

After running unabated for about two weeks, the flood seems to have ended just as abruptly as it began.

Weird.

Maybe EV1 (or somebody further upstream) put some sort of filtering mechanism in place for whatever kinds of requests the flooders were making.

Joey
www.webcomicsnation.com
Back to top
View user's profile Send private message Send e-mail
joey
Site Admin


Joined: 28 May 2002
Posts: 3601

PostPosted: Sun Sep 17, 2006 8:35 pm    Post subject: Reply with quote

Well, they're back, and they managed to crash the server again.

Joey
Back to top
View user's profile Send private message Send e-mail
Display posts from previous:   
Post new topic   Reply to topic    Talk About Comics Forum Index -> TalkAboutComics.com Forum Help All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

File a Trouble Ticket
Request a New Forum
View All Forums