9.1.1 Security Feature - About Flood Protection:
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexExplain Please
Author Message
norbie
Silver Supporter


Joined: Jun 29, 2004
Posts: 737
Location: Norbie's World

PostPost subject: 9.1.1 Security Feature - About Flood Protection:
Posted: Mon Jan 08, 2007 10:10 am
Reply with quote

Is there any documentation for this?
I had a look but couldn't find anything.

I've had a few members saying they're getting banned by the flood protection system, how does this system work and can I configure any part of it?

_________________
Norbie

www.norbiesworld.co.uk

norbie's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / Apache Custom Version / 4.0.26-standard (client: 5.0.15) / 4.4.4 / 9.1.1
Back to top
View user's profile Send e-mail Visit poster's website MSN Messenger
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3677
Location: Melbourne, AU

PostPost subject: Re: 9.1.1 Security Feature
Posted: Mon Jan 08, 2007 10:43 am
Reply with quote

the flooding security system will warn them with FULL PAGE telling them what to do, it will show the full page warning 3 times before they get banned for 24 hours.

they are allowed to do 2 click within 2 seconds ... the 3rd click within 2 seconds will display the first warning.

you can however delete their ip manually from admin => security => flooding.

.... 3 times a full page warning ....

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
norbie
Silver Supporter


Joined: Jun 29, 2004
Posts: 737
Location: Norbie's World

PostPost subject: Re: 9.1.1 Security Feature
Posted: Mon Jan 08, 2007 10:49 am
Reply with quote

Thankyou.

Could I also ask about the Unknown User-Agents part as well please. When I click on details it does not open up another page. If this section blocks Unknown User-Agents I presume it has a database of all known user-agents including browsers?

_________________
Norbie

www.norbiesworld.co.uk

norbie's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / Apache Custom Version / 4.0.26-standard (client: 5.0.15) / 4.4.4 / 9.1.1
Back to top
View user's profile Send e-mail Visit poster's website MSN Messenger
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3677
Location: Melbourne, AU

PostPost subject: Re: 9.1.1 Security Feature
Posted: Mon Jan 08, 2007 10:54 am
Reply with quote

not fully implemented yet this is why the link doesn't take you anywhere.
_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
RedRincon650
Nice poster


Joined: Mar 09, 2006
Posts: 118
Location: Winnipeg Manitoba

PostPost subject: Re: 9.1.1 Security Feature
Posted: Mon Jan 08, 2007 8:07 pm
Reply with quote

hrmm.. I did as you mentioned above, and Im not able to clear these IP's

RedRincon650's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache-2/MySQL-4/PHP-4/CMS-9.1RC2
Back to top
View user's profile Visit poster's website
norbie
Silver Supporter


Joined: Jun 29, 2004
Posts: 737
Location: Norbie's World

PostPost subject: Re: 9.1.1 Security Feature
Posted: Mon Jan 08, 2007 8:11 pm
Reply with quote

Same, delete them in the database.
_________________
Norbie

www.norbiesworld.co.uk

norbie's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux / Apache Custom Version / 4.0.26-standard (client: 5.0.15) / 4.4.4 / 9.1.1
Back to top
View user's profile Send e-mail Visit poster's website MSN Messenger
RedRincon650
Nice poster


Joined: Mar 09, 2006
Posts: 118
Location: Winnipeg Manitoba

PostPost subject: Re: 9.1.1 Security Feature
Posted: Mon Jan 08, 2007 8:15 pm
Reply with quote

done...cms_security

odd tho, the IP address was NULL where would the IP have been stored ?


RedRincon650's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/Apache-2/MySQL-4/PHP-4/CMS-9.1RC2
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3677
Location: Melbourne, AU

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Mon Jan 08, 2007 9:36 pm
Reply with quote

you are both missing files ... 9.1.1 move flooding ip in "Flooding" no in "IPs" ... just to be sure if you click on "details" do you see "flooding detected by yser agent ...." if so then this is not 9.1.1
_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
insaner
Dragonfly addicted


Joined: Jan 06, 2005
Posts: 308

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 1:31 am
Reply with quote

I've got a couple users complaining that the flood protection is blocking their IP as well, and that if they click on a link one time they get the warning page (not actually flooding).

Any ideas?


insaner's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian Linux/apache 1.3/4.0.23_Debian-1-log/4.3.10-2/9.0.6.1
Back to top
View user's profile Visit poster's website
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3677
Location: Melbourne, AU

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 8:30 am
Reply with quote

3 clicks with 2 seconds: warning, wait 8 seconds
one more click after the warning but before the 8 seconds expire: warning, wait 10 seconds more
one more click after the waring but before 10 seconds expire: warning wait 12 seconds.
on more click you get banned for 24 hours: admin might remove single IPs at any time or select to remove 24H old bans.

Many security systems counts how many requests within a determinated time (2 seconds) this can lead attackers to send thousands of requests within 2 seconds. Our security system works in a different way, user should need to get use to it and webmasters too.

insaner if they get a waring its just a warning and since they are waiting a determinated time of seconds they will not get anymore warnings or getting banned until the system register 3 clicks within 2 seconds.

_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
BrokenCrust
500+ Posts Club


Joined: Sep 06, 2004
Posts: 503

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 10:18 am
Reply with quote

Can you define a "click"? A javascript or CSS menu might easily be clicked 3 times in 2 seconds. And navigation (to a article in a content module for example) might so be done with 3 clicks on html links.

Whilst I don't want to be flooded, I don't want a system that requires users to navigate slowly. People will not put up with it and go elsewhere.

To give 3 clicks in 2 seconds is possible by good users and it would be nice to be able to set the number of clicks higher to suit a faster user group.

Maybe I don't understand fully since I can't actually get a warning on my test system however fast I click.


BrokenCrust's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.17/5.0.91/5.2.16/9.2.1
Back to top
View user's profile
NanoCaiordo
Developer


Joined: Jun 29, 2004
Posts: 3677
Location: Melbourne, AU

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 10:20 am
Reply with quote

because you are logged in as admin?
_________________
.:: I met php the 03 December 2003 :: Unforgettable day! ::.

NanoCaiordo's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
MySQL 5.1 / PHP 5.3 / NextGen()
Back to top
View user's profile Visit poster's website
insaner
Dragonfly addicted


Joined: Jan 06, 2005
Posts: 308

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 4:09 pm
Reply with quote

NanoCaiordo wrote:
3 clicks with 2 seconds: warning, wait 8 seconds
one more click after the warning but before the 8 seconds expire: warning, wait 10 seconds more
one more click after the waring but before 10 seconds expire: warning wait 12 seconds.
on more click you get banned for 24 hours: admin might remove single IPs at any time or select to remove 24H old bans.

Many security systems counts how many requests within a determinated time (2 seconds) this can lead attackers to send thousands of requests within 2 seconds. Our security system works in a different way, user should need to get use to it and webmasters too.

insaner if they get a waring its just a warning and since they are waiting a determinated time of seconds they will not get anymore warnings or getting banned until the system register 3 clicks within 2 seconds.

Thanks Nano, but it turns out it isn't my user's browsing habits. At first I thought it was just the fact they are clicking too fast, but it turns out they are getting the warning after immediately visiting the site and clicking a single link:

www.cpgnuke.com/Forums...18074.html

Has to do with Google Web Accelerator (or similiar products). I believe this is something that is a serious issue, as anyone out there in the world could have this installed and it would nearly immediatly ban them if they are using it.


insaner's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Debian Linux/apache 1.3/4.0.23_Debian-1-log/4.3.10-2/9.0.6.1
Back to top
View user's profile Visit poster's website
BrokenCrust
500+ Posts Club


Joined: Sep 06, 2004
Posts: 503

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 5:32 pm
Reply with quote

Quote:
because you are logged in as admin?

No I logged in as a test user. I click like mad and nothing happens.


BrokenCrust's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Linux/2.2.17/5.0.91/5.2.16/9.2.1
Back to top
View user's profile
DJ Maze
Developer


Joined: Apr 19, 2004
Posts: 5668
Location: http://tinyurl.com/5z8dmv

PostPost subject: Re: 9.1.1 Security Feature - About Flood Protection:
Posted: Wed Jan 10, 2007 6:39 pm
Reply with quote

BrokenCrust wrote:
Quote:
because you are logged in as admin?

No I logged in as a test user. I click like mad and nothing happens.

Here neither since it's hard to achieve the flooding. I've only seen it happen while there were iframe's on a page that all accessed index.php (which kicks in cmsinit.inc securtiy::check())

Keep in that a flooder does more simultanious requests (like the iframes do)


DJ Maze's server specs (Server OS / Apache / MySQL / PHP / DragonflyCMS)
Fedora 12 / 2.2.15 / 5.1.47 / 5.3.3 / CVS
Back to top
View user's profile Visit poster's website Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic   Printer Friendly Page     Forum IndexExplain Please All times are GMT
Go to page 1, 2  Next
Page 1 of 2


Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum

Dedicated Server & Bandwidth Sponsored by DedicatedNOW
User Info [x]

Welcome Anonymous

Nickname
Password
(Register)

Last CVS commits [x]

Languages [x]

Community [x]

Support for DragonflyCMS in a other languages:

Deutsch
Español

X-links [x]
UltraEdit Browse Happy logo Firefox MySQL PostgreSQL Valid CSS! Valid XHTML 1.0! Unicode Encoded Badge NukeBiz Resources Raven DragonflyCMS Dedicated Now InsideSupport Lampe Berger

Preview theme [x]
Each user can view the site with a different theme.
Themes marked with a * also change the forum look.


You are seeing squares or questionmarks on this page?

All content of this website is copyrighted by the Creative Commons NC-SA
The logos and trademarks used on this site are the property of their respective owners
We are not responsible for comments posted by our users, as they are the property of the poster.
Our server runs on a P3 1.2GHz with 512MB RAM with no accelerators
Support GoPHP5.org
This page generated in 0.8752 seconds with 19 DB Queries in 0.318 seconds
Memory Usage: 3.03 MB
Interactive software released under GNU GPL, Code Credits, Privacy Policy