Protecting sites using other than HTaccess

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • FreeNetPass Steve
    Confirmed User
    • Nov 2001
    • 442

    #1

    Protecting sites using other than HTaccess

    Is there an alternative way to htaccess to protect a members are of a site? I saw a script once and it used some other code. Maybe it was an .htaccess but used different code other than the mod rewrite.

    Any ideas?
    SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60.
  • Terenzo
    Confirmed User
    • Jan 2002
    • 971

    #2
    i dont know if this is a smart thing, but what we are doing is serving the shit out of a root dir, protecting with php-session-management.... whenever some fraud is done, we use a dynamic .htaccess file for blocking and redirecting the ip.... i really don't know, though.

    i am interessed in other alternatives, too.


    why dont you want to use .htaccess? aol problems?
    Signature Spot - USD 5000 / month

    Comment

    • pr0
      rockin tha trailerpark
      • May 2001
      • 23088

      #3
      this information & more will be available at http://www.pr0.net in the next few months, so be looking out for it
      __________
      Loadedca$h - get sum! - Revengebucks - mmm rebills! - webair (gotz sErVrz)

      Comment

      • zip
        Confirmed User
        • Jul 2001
        • 567

        #4
        Try this, is a combo between htaccess and php


        PHP Code:
        <?php 
        $leechpage = ""; 
        
        refferers urls ook toegestaan (zonder [url]http://[/url]) 
            $domein["0"] = "localhost"; 
            $domein["1"] = "127.0.0.1"; 
        
            $folder["0"] = "down/loads"; 
        
        idl=mijnfolder&idf=filevoorjou.exe">file voor jou</a> 
        
        // THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESSED OR IMPLIED 
        // WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 
        // OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE 
        // DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR 
        // ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 
        // SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT 
        // LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF 
        // USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND 
        // ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, 
        // OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT 
        // OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 
        // SUCH DAMAGE. 
        // 
        
        $versienumm = "<center style=\"font-family:arial\"><b>FW-ANTILEECH</b><br>Build:  1.32 "; 
        <p><b>FILE REQUEST DENIED</b></p></center>"; 
            if (!isset($HTTP_REFERER)) { 
                if (!empty($HTTP_SERVER_VARS) && isset($HTTP_SERVER_VARS['HTTP_REFERER'])) { 
                    $HTTP_REFERER = $HTTP_SERVER_VARS['HTTP_REFERER']; } } 
            if (!isset($idf)) { if (isset($HTTP_GET_VARS['idf'])) { $idf = $HTTP_GET_VARS['idf']; } } 
        
            if (isset($idf)) { $idf = stripslashes($idf); $idf = urldecode($idf); htmlentities($idf, ENT_QUOTES); 
                $idf = preg_replace('/([;\:,`\'\\\|"* !+=?~#%&<>^\/\(\)\[\]\{\}\$\n\r])/',"", $idf); $idf = ereg_replace('\.\.', '', $idf); }     
            if (!isset($idl)) { if (isset($HTTP_GET_VARS['idl'])) { $idl = $HTTP_GET_VARS['idl']; } } 
        
        
            if (isset($idl)) { $idl = stripslashes($idl); $idl = urldecode($idl); htmlentities($idl, ENT_QUOTES); 
                $idl = preg_replace('/([;\:,.`\'\\\|"* !+=?~#%&<>^\/\(\)\[\]\{\}\$\n\r])/',"", $idl); $idl = ereg_replace('\.\.', '', $idl); } 
            if (!empty($domein) && isset($HTTP_REFERER) && isset($idf)) { 
                if (ereg("//",$HTTP_REFERER)) { list($begone1,$refoke) = split('//', $HTTP_REFERER, 2); } 
                else { $refoke = $HTTP_REFERER; } 
                if (ereg("/",$domein[0])) { list($domain,$begone2) = split('/', $domein[0], 2); } 
                else { $domain = $domein[0]; } 
                $a = count($domein); 
                for ($i = 0; $i < $a; $i++) { 
        
        
                    if (eregi($domein[$i],$refoke)) { 
        
                        if (isset($idl) && isset($folder[$idl])) { 
                            if (ereg("//",$folder[$idl])) { 
                                list($begone3,$domwww) = split('//', $folder[$idl], 2); 
                                list($domain,$defolds) = split('/', $domwww, 2); $fileonweb = $defolds."/".$idf; } 
                            else { $fileonweb = $folder[$idl]."/".$idf; } } 
                        else { $fileonweb = $folder["0"]."/".$idf; } 
                        $fileow = "http://".$domain."/".$fileonweb; 
        // open http on loop 
                        $id_wi = fsockopen($domain,80); 
                        fputs($id_wi,"GET /$fileonweb HTTP/1.0\r\nHost: $domain\r\n\r\n");         
                        $buff = fgets($id_wi, 1024); 
                        fclose($id_wi); 
        // on file oke open file 
                        if (ereg("HTTP/1.1 200 OK", $buff)) { 
                            $id_wi = fopen($fileow, "r"); 
                            if ($id_wi) { 
        
        
                                if (eregi(".htm", $idf)) { $welktype = "text/html"; } 
                                else if (eregi(".html", $idf)) { $welktype = "text/html"; } 
                                else if (eregi(".txt", $idf)) { $welktype = "text/plain"; } 
                                else if (eregi(".jpg", $idf)) { $welktype = "image/jpg"; } 
                                else if (eregi(".gif", $idf)) { $welktype = "image/gif"; } 
                                else if (eregi(".mpeg", $idf)) { $welktype = "audio/mpeg"; } 
                                else if (eregi(".mp3", $idf)) { $welktype = "audio/mpeg"; } 
                                else if (eregi(".doc", $idf)) { $welktype = "application/msword"; } 
                                else if (eregi(".rtf", $idf)) { $welktype = "application/msword"; } 
                                else if (eregi(".zip", $idf)) { $welktype = "application/x-zip-compressed"; } 
                                else if (eregi(".exe", $idf)) { $welktype = "application/x-msdownload"; } 
                                else if (eregi(".pdf", $idf)) { $welktype = "application/pdf"; } 
                                else { $welktype = "application/octet-stream"; } 
                                Header("Content-Type: $welktype"); 
                                Header("Accept-Ranges: bytes"); 
                                Header("Content-Disposition: ; Filename=$idf"); 
                               readfile($fileow); 
                                fclose($id_wi); 
                                exit; 
                            } 
                        } break; 
                    } 
                } 
                if ($leechpage != "") { header("Location: $leechpage"); exit; } 
                echo "$versienumm"; exit; } 
        // geen referer url - exit of naar antileech.html 
            else { if ($leechpage != "") { header("Location: $leechpage"); } } 
            echo "$versienumm"; exit; 
        ?> 
        
        -------------------- 
        htaccess file in dir. 
        -------------------- 
        ErrorDocument 403 /down/leech.html 
        order deny,allow 
        deny from all 
        allow from 127.0.0.1 
        allow from .localhost 
        <Files .htaccess> 
        order allow,deny 
        deny from all 
        </Files> 
        IndexIgnore *

        Comment

        • Paolo
          Confirmed User
          • Jan 2002
          • 491

          #5
          Here is the big problem with protecting you site.
          Most programs give a 403 to the ip that brute forcing you password file.

          They love to use ip's that AOL has, because AOL's system is a pile of shit and is easy to abuse

          So 403's are fine in most cases except that AOL stores these 403's on there servers and prevents aol users sharing the same ip from visiting your site.

          So now come the complaints from an AOL subscriber that he can not get in your membership area because his ip is blocked and he did nothing wrong " Except for using AOL in the first place" : )

          What we did is give the brute forcer a 202 ok and redirect to a fake url.
          That really seemed to help out

          I hate those brute force programs they are a pain in the ass for everyone and any idiot can use them.

          Hope that helps a little
          [

          Comment

          • mike503
            Confirmed User
            • May 2002
            • 2243

            #6
            simply put, you don't need htaccess at all. you can do a variety of other methods, either using normal HTTP authentication or using cookie-based authentication. if you have questions, hit me up on icq.
            php/mysql guru. hosting, coding, all that jazz.

            Comment

            • Naughty
              Confirmed User
              • Jul 2001
              • 6485

              #7
              Interesting stuff.

              I'll be reading your stuff soon pr0
              seks.ai for sale - ping me

              Comment

              • BadBoyBill4281
                Confirmed User
                • May 2002
                • 616

                #8
                goto hotscripts and search in php only you'll find everything you need complete programs to add, change, mod, any password for any of your sites that you wish very easy to understand if you know php and mySQL
                ICQ#128496425

                www.swinginglocal.com

                Comment

                • Terenzo
                  Confirmed User
                  • Jan 2002
                  • 971

                  #9
                  Originally posted by Paolo
                  Here is the big problem with protecting you site.
                  Most programs give a 403 to the ip that brute forcing you password file.

                  They love to use ip's that AOL has, because AOL's system is a pile of shit and is easy to abuse

                  So 403's are fine in most cases except that AOL stores these 403's on there servers and prevents aol users sharing the same ip from visiting your site.

                  So now come the complaints from an AOL subscriber that he can not get in your membership area because his ip is blocked and he did nothing wrong " Except for using AOL in the first place" : )

                  What we did is give the brute forcer a 202 ok and redirect to a fake url.
                  That really seemed to help out

                  I hate those brute force programs they are a pain in the ass for everyone and any idiot can use them.

                  Hope that helps a little

                  Great info, we will change this!! thanx paolo!
                  Signature Spot - USD 5000 / month

                  Comment

                  • Terenzo
                    Confirmed User
                    • Jan 2002
                    • 971

                    #10
                    Originally posted by pr0
                    this information & more will be available at http://www.pr0.net in the next few months, so be looking out for it


                    ... next few months... ;)) get it done sooner!!!!
                    Signature Spot - USD 5000 / month

                    Comment

                    • Sleepy
                      Confirmed User
                      • Nov 2001
                      • 679

                      #11
                      http://www.danubetech.com/news/07_12_02.htm
                      ( ProxyPass )

                      The software blocks open proxies and shared passwords. Its written in C just like Iprotect and features a realtime admin. I had it installed and that was the end of the bullshit with those proxy hackers.

                      Iprotect/Pennywize/StopThatHacker - just dont work.
                      Lets say you have Pennywize set to block a user after 5 bad auths. These hackers use 1000's of proxies to attack you and get 5 guesses on each one. If the hacker has 8000 proxies to use, he gets 40,000 guesses all total. Whats the point in even blocking ?

                      Comment

                      • foe
                        Confirmed User
                        • May 2002
                        • 5246

                        #12
                        yeh PHP can protect your site nicely

                        Comment

                        • FreeNetPass Steve
                          Confirmed User
                          • Nov 2001
                          • 442

                          #13
                          Thanks for all the tips and links!
                          SIG TOO BIG! Maximum 120x60 button and no more than 3 text lines of DEFAULT SIZE and COLOR. Unless your sig is for a GFY top banner sponsor, then you may use a 624x80 instead of a 120x60.

                          Comment

                          Working...