Invision Community 4: SEO, prepare for v5 and dormant account notifications By Matt Monday at 02:04 PM
Dmacleo Posted December 6, 2012 Posted December 6, 2012 there a way to set a mod security rule to automatically and silently block all requests to that file? if the files not there seems it has to be an external link driving traffic to it right?
Owdy Posted December 6, 2012 Author Posted December 6, 2012 there a way to set a mod security rule to automatically and silently block all requests to that file? if the files not there seems it has to be an external link driving traffic to it right? Please tell me how to do that :)
Dmacleo Posted December 6, 2012 Posted December 6, 2012 was afraid you would ask that :P I honestly cannot remember, I'll do some googling :)
Rhett Posted December 6, 2012 Posted December 6, 2012 <p>Let's go back to that error then, is it still showing up or just old errors? What is the date of the error? and have you triple checked the file doesn't exist?</p> <p> </p> <p>Please paste the full text of the error for clarification. </p>
Owdy Posted December 6, 2012 Author Posted December 6, 2012 Yes, still showing up. Latest 3 errors [Thu Dec 06 22:00:46 2012] [error] [client 195.42.142.18] client denied by server configuration: /home/hoitajat/public_html/foorumi/cache/df.php [Thu Dec 06 22:02:24 2012] [error] [client 91.203.133.236] client denied by server configuration: /home/hoitajat/public_html/foorumi/cache/df.php [Thu Dec 06 22:04:38 2012] [error] [client 85.128.214.2] client denied by server configuration: /home/hoitajat/public_html/foorumi/cache/df.php File isnt there:
Owdy Posted December 6, 2012 Author Posted December 6, 2012 Weird, those erros came in every couple of minutes, now allmost one hour of silence.
Rhett Posted December 6, 2012 Posted December 6, 2012 Hello those are someone from those IP's trying to access that file on your site, which is being blocked by your server config, I would double check it doesn't exist and ban those ip's as well, they are looking for exploited sites to execute the code left behind. You should be good.
Owdy Posted December 6, 2012 Author Posted December 6, 2012 Okay, thanks. There are such many ip's. Seems "attac" is over for now, all day errors, no allmost 1,5 hours nothing.
Owdy Posted December 6, 2012 Author Posted December 6, 2012 It would be nice, if i could ban automatically everyone whos trying to acces that file.
bfarber Posted December 7, 2012 Posted December 7, 2012 It would be nice, if i could ban automatically everyone whos trying to acces that file. Your host may be able to do that. It's also worth noting, if you use the "deny" command in .htaccess and the IP addresses trying to access those files are being denied, that would also account for the error logs. Your host may have even banned the IP addresses at the server level.
Owdy Posted December 7, 2012 Author Posted December 7, 2012 That must been some kind sniffing attack or something. Errors totally stopped yesterday. Before silence, many hits per hour. It's also worth noting, if you use the "deny" command in .htaccess Those are IPB generated htacces files :)
sijad Posted December 8, 2012 Posted December 8, 2012 Hello those are someone from those IP's trying to access that file on your site, which is being blocked by your server config, I would double check it doesn't exist and ban those ip's as well, they are looking for exploited sites to execute the code left behind. You should be good. yes i guess, i think your Php Type now is mod_php? you should change it to suphp in your Webserver Config
Owdy Posted December 8, 2012 Author Posted December 8, 2012 yes i guess, i think your Php Type now is mod_php? you should change it to suphp in your Webserver Config Can i use it with APC?
Owdy Posted December 8, 2012 Author Posted December 8, 2012 Then i wont use it . APC is php accelator.
Recommended Posts
Archived
This topic is now archived and is closed to further replies.