Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
iPhone 5 rumor rollup for the week ending Feb. 10
Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid
Apple passes HP as largest tech company
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Much of Western U.S. is a 3G wasteland, says FCC
How the Phoenix Suns basketball team takes on social media attacks
Microsoft details Windows 8 for ARM devices
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Macs take on the enterprise
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
/

Compendium /

Weird Web hacking nonsense from China

Related linksToday's breaking news
Send to a friendFeedback


Network World Fusion 09/01/04

When I go home at night, I usually spend some time working on a non-networking related Web site (so, yes, I have no life - I work all day on a Web site, then for fun I work on another site). Last week, I noticed bandwidth consumption had jumped dramatically, from maybe 500 megabytes a day to 2.2 gigabytes a day.

"Cool!" I thought. But ad banner impressions hadn't gone up at all. And when I looked at the Analog reports, I saw something weird: The logo banner that appears on every page was getting zillions of requests, but the actual HTML pages? No increase. Huh? Why would somebody just be downloading the banner? And why were page requests from hosts in China going through the roof?

Looking at the raw server logs, I noticed that not only was somebody downloading the banner repeatedly - and from one specific domain (I have three domains off the same box), they were using the site to make requests to all sorts of pay-per-click ad-banner networks. For those of you who live for log analysis, here's one example:

www.universalhub.com 221.232.79.8 - - [01/Sep/2004:00:31:21 -0400] "GET http://www.xmlrevenue.com/s.php?keywords=DSL&username=infome
nl HTTP/1.0" 200 39857 "http://www.gbahome.com/ads/xmlrevenue.htm" "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.1)"

In .htaccess, I blocked off the offending IP numbers. Like the Borg, they adapted. They switched to other numbers and kept coming. So I blocked off whole ranges of IP numbers. They switched to new ranges. I changed the name of the banner. They noticed and started downloading the new file. I *think* I finally have all the IP ranges blocked off (and with them, much of China, I guess), but I have no doubt they have more up their sleeves.

Have any of you noticed any similar activity? If so, did you do anything beyond blocking IP numbers? The one thing that does concern me a bit is the GET command in the logs - are they somehow exploiting a hole in the software I'm using (Drupal)? Any suggestions gratefully accepted!

Back to Compendium

Comments

Post a comment

Name:


E-mail address:


URL:


Comments:


Remember info?




NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.