Membership is FREE, giving all registered users unlimited access to every DNForum feature, resource, and tool! Optional membership upgrades unlock exclusive benefits like profile signatures with links, banner placements, appearances in the weekly newsletter, and much more - customized to your membership level!

Wanted: Service Stop a DOS/Script attack ?

Status
Not open for further replies.

Whois-Search

Level 9
Legacy Platinum Member
Joined
Apr 28, 2002
Messages
3,119
Reaction score
1
Other than making my site login only, keycode or phpsession

Does anyone know of a way to stop this script attack .......

I've had to shut my site down but the attack is still going.

See the 2 minutes of Log below

Every ip is a proxy ip

The guy is scripting 2 domains a second

You can't block the ips because he keeps changing it.


208.252.22.130 - - [19/Oct/2003:00:01:30 +0100] "GET /results/?query=bobsfarms.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 98)"
80.17.14.170 - - [19/Oct/2003:00:01:30 +0100] "GET /results/?query=hotsyalberta.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0; SiteCoach 1.0)"
12.254.83.68 - - [19/Oct/2003:00:01:32 +0100] "GET /results/?query=katherinetoubiandds.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
200.84.222.102 - - [19/Oct/2003:00:01:32 +0100] "GET /results/?query=barrysanders.net HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
202.103.41.2 - - [19/Oct/2003:00:01:33 +0100] "GET /results/?query=newcombart.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
195.169.25.2 - - [19/Oct/2003:00:01:35 +0100] "GET /results/?query=frogs-legs.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 98)"
213.152.93.4 - - [19/Oct/2003:00:01:36 +0100] "GET /results/?query=wwwpaddingtonstationriding.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
211.75.39.154 - - [19/Oct/2003:00:01:40 +0100] "GET /results/?query=mike-april-wedding.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
12.104.92.8 - - [19/Oct/2003:00:01:40 +0100] "GET /results/?query=freelandftmyers.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
200.47.100.7 - - [19/Oct/2003:00:01:45 +0100] "GET /results/?query=gosnakes.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
210.220.73.24 - - [19/Oct/2003:00:01:46 +0100] "GET /results/?query=hkdea.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
212.72.11.84 - - [19/Oct/2003:00:01:50 +0100] "GET /results/?query=vedicastroindia.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
211.124.28.40 - - [19/Oct/2003:00:01:51 +0100] "GET /results/?query=reartz.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
203.199.49.77 - - [19/Oct/2003:00:01:51 +0100] "GET /results/?query=sara-press.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
151.173.163.6 - - [19/Oct/2003:00:01:52 +0100] "GET /results/?query=unitedoil-indonesia.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
65.66.145.225 - - [19/Oct/2003:00:01:59 +0100] "GET /results/?query=humanityinart.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
66.255.188.131 - - [19/Oct/2003:00:02:01 +0100] "GET /results/?query=paulfranciswillmott.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
61.132.90.4 - - [19/Oct/2003:00:02:02 +0100] "GET /results/?query=clioassembly.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
67.116.155.181 - - [19/Oct/2003:00:02:08 +0100] "GET /results/?query=northeastcopy.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
200.163.190.115 - - [19/Oct/2003:00:02:08 +0100] "GET /results/?query=frontdoorflowers.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
80.191.232.80 - - [19/Oct/2003:00:02:08 +0100] "GET /results/?query=artchaoui.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
62.49.123.162 - - [19/Oct/2003:00:02:10 +0100] "GET /results/?query=katherinetoubiandds.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Q312461)"
211.250.187.129 - - [19/Oct/2003:00:02:10 +0100] "GET /results/?query=donnaflenniken.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
195.241.77.162 - - [19/Oct/2003:00:02:11 +0100] "GET /results/?query=shaysrebellion.net HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
80.58.4.44 - - [19/Oct/2003:00:02:12 +0100] "GET /results/?query=lakespeed.net HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
202.138.137.38 - - [19/Oct/2003:00:02:15 +0100] "GET /results/?query=aaaalldale.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
195.249.40.245 - - [19/Oct/2003:00:02:16 +0100] "GET /results/?query=mickmackey.net HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
195.117.55.100 - - [19/Oct/2003:00:02:17 +0100] "GET /results/?query=hotsyalberta.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
208.206.234.83 - - [19/Oct/2003:00:02:17 +0100] "GET /results/?query=madmonkproductions.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
203.89.133.250 - - [19/Oct/2003:00:02:18 +0100] "GET /results/?query=bupperts.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
67.116.155.181 - - [19/Oct/2003:00:02:18 +0100] "GET /results/?query=amrazo.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
200.30.165.138 - - [19/Oct/2003:00:02:20 +0100] "GET /results/?query=urnes-mira.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
208.29.180.114 - - [19/Oct/2003:00:02:21 +0100] "GET /results/?query=ccttrain.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90) via proxy gateway CERN-HTTPD/3.0 libwww/2.17"
80.255.41.201 - - [19/Oct/2003:00:02:22 +0100] "GET /results/?query=ruanns.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
61.88.121.4 - - [19/Oct/2003:00:02:23 +0100] "GET /results/?query=danddbakersfield.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 95; DigExt)"
217.207.42.66 - - [19/Oct/2003:00:02:26 +0100] "GET /results/?query=enerconpanels.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
202.152.77.28 - - [19/Oct/2003:00:02:28 +0100] "GET /results/?query=mahainc.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
80.58.33.235 - - [19/Oct/2003:00:02:29 +0100] "GET /results/?query=ryukyukempo.net HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
203.89.133.250 - - [19/Oct/2003:00:02:29 +0100] "GET /results/?query=atlantavelo.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
200.47.100.7 - - [19/Oct/2003:00:02:33 +0100] "GET /results/?query=hkdea.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Q312461)"
193.95.41.2 - - [19/Oct/2003:00:02:34 +0100] "GET /results/?query=auburnsprings.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)"
208.192.153.64 - - [19/Oct/2003:00:02:34 +0100] "GET /results/?query=burnabyradiator.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 95; DigExt)"
213.136.10.237 - - [19/Oct/2003:00:02:35 +0100] "GET /results/?query=davidboxton.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)"
80.58.41.44 - - [19/Oct/2003:00:02:36 +0100] "GET /results/?query=glennamanda.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
80.191.43.140 - - [19/Oct/2003:00:02:36 +0100] "GET /results/?query=kalpatarucolours.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
200.58.55.234 - - [19/Oct/2003:00:02:37 +0100] "GET /results/?query=siebelclassic.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312461)"
64.2.137.227 - - [19/Oct/2003:00:02:38 +0100] "GET /results/?query=debbiehanrahan.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
217.160.215.214 - - [19/Oct/2003:00:02:41 +0100] "GET /results/?query=jamesbuchanan.net HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
200.41.245.67 - - [19/Oct/2003:00:02:41 +0100] "GET /results/?query=hambletonrealty.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.01; Windows 98)"
210.0.186.247 - - [19/Oct/2003:00:02:43 +0100] "GET /results/?query=lbufkin.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 95; DigExt)"
200.47.100.7 - - [19/Oct/2003:00:02:45 +0100] "GET /results/?query=nancyocheltree.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
203.169.250.28 - - [19/Oct/2003:00:02:46 +0100] "GET /results/?query=trentstrucking.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
200.47.100.7 - - [19/Oct/2003:00:02:49 +0100] "GET /results/?query=walks-n-wags.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
212.224.19.162 - - [19/Oct/2003:00:02:49 +0100] "GET /results/?query=unitedoil-indonesia.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Q312461)"
212.130.71.254 - - [19/Oct/2003:00:02:49 +0100] "GET /results/?query=wwwvisitingangelsfl.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 95; DigExt)"
212.77.217.199 - - [19/Oct/2003:00:02:52 +0100] "GET /results/?query=charotarpublishinghouse.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
200.47.100.7 - - [19/Oct/2003:00:02:55 +0100] "GET /results/?query=guardian-ffa.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
203.162.41.126 - - [19/Oct/2003:00:02:57 +0100] "GET /results/?query=wwwpaddingtonstationriding.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
213.20.242.210 - - [19/Oct/2003:00:03:11 +0100] "GET /results/?query=acroixguitars.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
211.47.185.133 - - [19/Oct/2003:00:03:12 +0100] "GET /results/?query=lakespeed.net HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)"
213.30.180.163 - - [19/Oct/2003:00:03:15 +0100] "GET /results/?query=kimball-real-estate.com HTTP/1.1" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
130.94.107.164 - - [19/Oct/2003:00:03:15 +0100] "GET /results/?query=artchaoui.com HTTP/1.1" 200 686 "-" "Mozilla/4.78 (TuringOS; Turing Machine; 0.0)"
210.23.230.172 - - [19/Oct/2003:00:03:16 +0100] "GET /results/?query=evevykydal.com HTTP/1.0" 200 686 "http://www.whois-search.com/" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)"
 

bidawinner

Level 9
Legacy Exclusive Member
Joined
Jul 12, 2002
Messages
3,571
Reaction score
0
I dont know squat about these technical things who-is ..(if all else fails) but isntn there a way to forward your URL to HIS server ! ?
 

mr-x

Level 7
Legacy Exclusive Member
Joined
Oct 12, 2003
Messages
870
Reaction score
181
Set a cookie via javascript with the current time and a counter when your page loads.

You can then slow down the queries or deny them based on the counter/time combo.
 
Status
Not open for further replies.

Who has viewed this thread (Total: 1) View details

The Rule #1

Do not insult any other member. Be polite and do business. Thank you!

Premium Members

Our Mods' Businesses

*the exceptional businesses of our esteemed moderators

Top Bottom