Home Private Messages Search
CPG Dragonfly™ CMS stopsoftwarepatents.eu petition banner
Toggle Content
 
Forums ⇒ CMS (All) ⇒ Security ⇒ Brazilians are Reverse Engineering


Brazilians are Reverse Engineering
Post any security related questions in here.
Please send discovered reports to security @ cpgnuke.com
Do Not post links to exploits or hacker sites - your post will be edited/deleted.
If you think you've been hacked, FIRST go through your server logs.

Post new topic    Reply to topic    Printer Friendly Page     Forum Index ⇒  Security

View previous topic :: View next topic  

Has your site had a problem with Brazilians on Lacnic?
Yes
50%
 50%  [ 3 ]
No
33%
 33%  [ 2 ]
Not sure
16%
 16%  [ 1 ]
Total Votes : 6

Author Message
NukeFind
Newbie
Newbie

Offline Offline
Joined: Jun 06, 2004
Posts: 10
Location: Missouri, USA
PostPosted: Thu Jun 10, 2004 2:04 pm
Post subject: Brazilians are Reverse Engineering

As evidenced from our log capture, the Brazilian script kiddies are reverse engineering and looking for vulnerabilities. Except for the bad "bold" code, some of it works:

[Thu Jun 10 08:29:13 2004] [error] [client 200.96.112.43] File does not exist: /home/fivedogs/public_html/<b>modules</themes/PH2/style/style.css
[Thu Jun 10 08:29:13 2004] [error] [client 200.96.112.43] File does not exist: /home/fivedogs/public_html/<b>modules</includes/blockscript.js
[Thu Jun 10 08:29:11 2004] [error] [client 200.96.112.43] File does not exist: /home/fivedogs/public_html/<b>modules</index.php
Forty more lines not included here

Pretty soon I will ban all of Lacnic's customers, from El Paso to the tip of South America. But I hate to see real people take a hit because of these clowns.

---------------------------------------------
NukeFind at www.nukefind.com


NukeFind's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux 2.4.26, Apache 1.3.31 , MySql 4.0.18-standard, PHP Version 4.3.3
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Thu Jun 10, 2004 2:37 pm
Post subject: Re: Brazilians are Reverse Engineering

Your question should probably have been 'Is there anyone who has not had a visit from the Brazilian connection?'

There are vulnerabilities in some theme.php files which are not from cpgnuke.com, so they will eventually succeed.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Jeruvy
Security Team
Security Team

Offline Offline
Joined: Apr 23, 2004
Posts: 1432
Location: Canada
PostPosted: Thu Jun 10, 2004 3:44 pm
Post subject: Re: Brazilians are Reverse Engineering

Actually I heard a rumor they are Peruvian...

_________________
J.
j e r u v y a t y a h o o d o t c o m

Need help? Look here: www.dragonflycms.org/W...d=112.html
Need to chat? Look for me on irc.freenode.net

Jeruvy's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Ubuntu7.10/Debian3.1 - 2.2.3/1.3.37 - 5.0.38/4.0.27 - 5.2.1/4.4.7 - CVS/9.1.2}
Back to top
View user's profile ICQ Number Yahoo Messenger Photo Gallery
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Thu Jun 10, 2004 3:46 pm
Post subject: Re: Brazilians are Reverse Engineering

They could be any number of nationalities and just using anon proxies they have tapped into in Brazil.

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Śyama_Dāsa
Developer
Developer

Offline Offline
Joined: Apr 19, 2004
Posts: 2048
Location: Dragonfly CMS Tribe
PostPosted: Thu Jun 10, 2004 5:19 pm
Post subject: Re: Brazilians are Reverse Engineering

Just ban direct file access in .htaccess. It IS very easy for me or anyone else to use a brazillian proxy

_________________
AKA Akamu / Read these and your life will be successful | Find a Repair
--
Mods and Professional Support via YIM

Śyama_Dāsa's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
win32 / Apache 1.3.33 / MySQL 4.1.16/PHP 4.4/CPG-CVS ( browsers: Mozilla 1.7.x / IE6 / Opera 8.0)
Back to top
View user's profile Visit poster's website Yahoo Messenger Photo Gallery
Tank863
Silver Supporter
Silver Supporter

Offline Offline
Joined: May 08, 2004
Posts: 101
Location: Philadelphia
PostPosted: Tue Feb 08, 2005 3:58 am
Post subject: Re: Brazilians are Reverse Engineering

sorry to bring up such and old article.. but how to you direct ban file access?

_________________
Microsoft MVP
Windows Security
2005-2006

Tank863's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux-2.4.20-43.9/4.0.23a-standard/4.3.11/9.0.6.1
Back to top
View user's profile Visit poster's website
Phoenix
• Many Posts •
• Many Posts •

Offline Offline
Joined: Apr 19, 2004
Posts: 8799
Location: Netizen
PostPosted: Tue Feb 08, 2005 4:30 am
Post subject: Re: Brazilians are Reverse Engineering

in htaccess, examples,
deny from 200.11. 200.2. 200.177.

also this way,
RewriteCond %{REMOTE_ADDR} ^217.20.113.110*$ [OR]
RewriteCond %{REMOTE_ADDR} ^200.177.*$ [OR]
RewriteRule ^.*$ somefile.php [L]

_________________
DonationsPro for DragonflyCMS, SMF, MyBB, vBulletin

Phoenix's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Back to top
View user's profile Visit poster's website Photo Gallery
Display posts from previous:   
Post new topic    Reply to topic    Printer Friendly Page    Forum Index ⇒  Security
Page 1 of 1
All times are GMT



Jump to:  


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


 
   Toggle Content User Info

Welcome Anonymous

Nickname
Password
(Register)

   Toggle Content Last CVS commits
· Fixed .ico Expires header.
· Removed domain name from cookies so subdomains wont access them anymore.
· CSS and JS, case insensitives.
· CSS and JS, send correct HTTP 1.1 headers and fixed issues where themes and...
· Further security class improvements.
· 301 redirects on LEO changes
· Option to force 3xx http status codes
· Validate googlebot.com and google.com crawlers.
· CCBot
· Rss with etag and atom.

lesa meira...

   Toggle Content Community

Support for DragonflyCMS in a other languages:

Deutsch
Español

   Toggle Content X-links
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
Interactive software released under GNU GPL, Code Credits, Privacy Policy