slope 2 The Xtreme - Chronicles of Quizorthia Logo endicon

Account

Anonymous Avatar
Good morning, Guest


 ► Register
 ► Member List

Username:

Pass Word/Phrase:

Remember Me for



Whos Online
Active over the last 15 minutes

Currently Online:
• Members: 0
• Ghosts: 0
• Guests: 4
• Bots: 0
• Total: 4

Members/Bots Online:
None

OpenRPG Server
Our OpenRPG Traipse server
2 The Xtreme is
Offline
Stats
The News page has been viewed
16,767 times.
We received
2,399,056
page views since
June 09, 2002


  Security Update      
Posted by: GM-Alex on Feb 25, 2017 @ 20:19 EST
Last Edited: Feb 26, 2017 @ 11:34 EST

Been getting lots of bot searching for database dumps in many kinds of formats.

Update:
Its getting out of hand. ALL of the exploit searching now results in the entire block getting server side banned. They are also commented in the lists so I know not to remove them.

Oh let me count the ways why all 106 or 206 attempts WILL fail:
• Full database backups are NOT stored in /public_html. Actually database backups are downloaded to my machine. The only backups I have on the server is "default settings", and RPG Manager backups. This way I can factory reset the CMS if needed. And that backup has a salted password hash that the system forces me to reset on restore.
• The requested filenames are all wrong too. Not even close.

Nice try, but here's your YOU FAIL award.

The next CMS update will have an anti-hammering system in place so these excessive requests will get rejected by the CMS. Completely. Right now I have to do them by hand. Also during the next update all block-lists from my sites will be merged, and I will chop as many class B & C addresses as possible to eliminate an excessive lists. This will become an automated function as well after the next security update.

Comments are disabled for this story

     

This page was generated in 0.01467 seconds using 16 queries.
This page consumed 6.9 MiB of memory during its creation.

2 The Xtreme - Chronicles of Quizorthia
Copyright © 1992-2006, 2008-2012, 2015-2017, 2020, 2021 (GM-Alex) Alex Jackson
ALL RIGHTS RESERVED

Powered by SimpleCMS
Best Viewed with any standards compliant browser.