Dynadot Premium User Auctions, September 8 to 16. Great domains with first bid credit.

Hacking probes everywhere....

Namecheap AuctionsNamecheap Auctions
Namecheap AuctionsNamecheap Auctions
NamecheapNamecheap
Watch

alien51

Take Me To Your LeaderTop Member
Impact
1,344
For several weeks now, my Cpanel logs are getting flooded by probing attacks from apparent hackers who seem to be searching if you have wordpress or joomla installed on your domains.

And they come from all sorts of countries. My banned ip address list on my htaccess is so long already. It's eating up too much of my time just checking the logs each day for all my domains. I sometimes wonder whether these are zombie machines (users who had no idea their computers are infected and being used for probing attacks).
 
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
GoDaddyGoDaddy
speaking of htaccess what is some good restriction setting to use?
 
0
•••
Glad you asked. We use many lines in our htaccess like:

deny from 1.
deny from 2.
deny from 109.
deny from 110.
deny from 111.
deny from 112.
deny from 113.
deny from 114.
deny from 115.
deny from 116.
deny from 117.21.
deny from 117.22.
deny from 117.23.
deny from 117.24.
deny from 117.25.
etc.

I will attach what we use in case someone else would like to block most non-US traffic to their site. This file has been built by hand over the past couple of years. When I get a spam or attack I check the IP whois and if it is non-us or a hosting company I add the IP range that contains what was used. [Caution: I cannot guarantee that some US ISP IPs won't be included. Use at your own risk or use it as a model to make your own list.]

We don't care about non-US traffic so we can just block large IP ranges that for sure not assigned to the US. We also block a lot of hosting company IP ranges. We do this on sites, but we also do this at the sever level for some accounts. We had CSF installed and block the same ranges, but with notation like "109.0.0.0/8".

When a country can't access your server or use it to relay spam, it really helps.
 
Last edited:
0
•••
When I get a spam or attack I check the IP whois and if it is non-us or a hosting company I add the IP range that contains what was used....... We don't care about non-US traffic so we can just block large IP ranges that for sure not assigned to the US.
I sometimes do the same thing, example for the past 3 years almost all of the spam and hack bots i see on my logs come from Ukraine.

There are also the Adsense-click-friendly countries to block.

Sometimes, however, i wonder if this is some kind of racial discrimination. lol

BY THE WAY......

My domains are being hammered repeatedly by this:

"/shop/admin/banner_manager.php/login.php?action=insert"

Any of you seeing this often as well??????

It's a good thing most of my domains are just 1-page plain HTML "for sale" pages. lol
 
0
•••
Olitt — high-converting AI websites, only from $1/moOlitt — high-converting AI websites, only from $1/mo

We're social

Escrow.com
Spaceship
Escrowly
CryptoExchange.com
Domain Recover
URLs.com
  • The sidebar remains visible by scrolling at a speed relative to the page’s height.
Back