LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-18-2011, 10:55 AM   #16
rhbegin
Member
 
Registered: Oct 2003
Location: Arkansas, NWA
Distribution: Fedora/CentOS/SL6
Posts: 381

Rep: Reputation: 23

Quote:
Originally Posted by baldur2630 View Post
If at some stage you've tried to hack into it or post rubbish, you may well have been banned forever. If you give me your IP address I can check
I have never accessed this site before today, 69.4.xx.xx

Last edited by rhbegin; 05-19-2011 at 10:27 AM.
 
Old 05-18-2011, 11:04 AM   #17
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Original Poster
Rep: Reputation: 22
69.4.192.252 is not on my firewall, you are not in my DenyHosts block list and you aren't on my Fail2Ban list.

We get so many idiots trying to post garbage on the site that I have installed just about everything known to man.

This morning I installed SMF Web Firewall and Bad Behavior for good measure. I just switched them both off. Try now and see if you can Register. If not I'll investigate further.

Thanks for telling me or I might never have known.
 
Old 05-18-2011, 01:14 PM   #18
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
I tried this morning too and got an access denied message, claiming that I either had a virus or trojan (not very likely) or that I was engaged in some form of access-bypass (don't think so). I was able to go to the main site: http://techsup.corp.networkingtechnology.org, but as soon as I clicked the forum tab, I received the forbidden message. I too had never been to the site.
 
Old 05-18-2011, 01:31 PM   #19
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Original Poster
Rep: Reputation: 22
I looked in the logs and according to the log there have been 137 Bypass Attempts today. It would seem to me that the SMF add-ons, Forum Firewall and Bad Behaviour are causing all the problems.

I have now switched them both completely OFF, so if you try again now, you SHOULD be able to login.

It's very difficult, because we are basically offering FREE help on quite a number of topics, but we have blocked over 10,000 IP addresses thanks to fail2ban and DenyHosts. We have Captcha, stop spammers the lot, but I still get 10 or more emails telling me that a new Registration needs approving and they are 100% known spammers. I've now added questions to try to stop the scripts and it seems to have worked, because now I'm down to 2 or 3 a week, always spammers, that's why I tried these two SMF add-ons.

The only other option will be to close the Forum completely, I'm just sick and tired of processing these morons. Computers have gone from being a help and a pleasure to a daily chore and an absolute pain in the butt.

Don't be surprised if the Forum disappears in the near future. I'm sick to death of all the work it causes me.
 
Old 05-19-2011, 10:22 AM   #20
rhbegin
Member
 
Registered: Oct 2003
Location: Arkansas, NWA
Distribution: Fedora/CentOS/SL6
Posts: 381

Rep: Reputation: 23
Quote:
Originally Posted by rhbegin View Post
I have never accessed this site before today, 69.4.xx.xx
It works great, thanks!!


Last edited by rhbegin; 05-19-2011 at 10:27 AM.
 
Old 05-19-2011, 10:28 AM   #21
rhbegin
Member
 
Registered: Oct 2003
Location: Arkansas, NWA
Distribution: Fedora/CentOS/SL6
Posts: 381

Rep: Reputation: 23
I registered on your site, thank you for allowing me access, I want to be rid of the woot/woot messages and such.

thank you again

 
Old 05-20-2011, 04:21 AM   #22
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
I too was able to access the site fine, now.

I am sorry to hear that you are, or were, having such trouble with spammers. You said you have it down to 2-3 per week now? If you are still having trouble, I am sure that LQ-Security can help you come up with a solution. I would hate for you to give up on the venture because of the idiot spammers. I run a small (soon to be) ecommerce site for my wife's business and it has reached the point of attracting a lot of spam too, mostly by email. Some of it has been a real challenge to try and stop. I would often ask myself why are they bothering with this and I think your statement about turning from a pleasure to a pain is part of the answer.

Your site looks quite interesting, especially in that you have a decent amount of traffic and information on less common subjects like Groupwise and Zen, which are still in use in some places.
 
Old 05-23-2011, 07:40 AM   #23
rhbegin
Member
 
Registered: Oct 2003
Location: Arkansas, NWA
Distribution: Fedora/CentOS/SL6
Posts: 381

Rep: Reputation: 23
The info sections were very informative, like the above post it is sad that people cannot post information sharing without others trying to disrupt it.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Fail2ban regex help please wvroger Linux - Security 1 05-23-2010 07:30 PM
fail2ban error k_oudom Linux - Server 1 02-16-2010 09:36 AM
I need help with fail2ban... trist007 Linux - Newbie 15 12-14-2009 03:22 AM
Fail2ban and Slack Biggen Slackware 10 06-20-2009 08:30 AM
Need help with fail2ban regex jakev383 Linux - Security 6 12-07-2008 09:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration