|
|
|
||||
|
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() |
|
|||||||
| Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
|
Thread Tools |
|
|
#1 |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
PLEASE help asap, cheater question!
Okay, heres the situation, I'm going mad, guys are taking my site, using the following object tag and placing it on high traffic sites. I need to know asap how I can prevent this from happening, and prevent that counting as that page loading. Theres got to be some way to do this or to detect if the object tag is being used, I know if anyone will know you guys will know...
OBJECT data="http://www.yourwebsite.com/" HEIGHT=1 WIDTH=1 VSPACE=1 HSPACE=1> /OBJECT> Thanks so much guys, i'm going crazy, C. |
|
|
|
|
|
#2 |
|
GFY HALL OF FAME DAMMIT!!!
Join Date: Jan 2002
Location: that 504
Posts: 60,840
|
uh oh.
__________________
![]() Want an Android App for your tube, membership, or free site? Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - |
|
|
|
|
|
#3 |
|
Guest
Posts: n/a
|
Patrick?
![]() |
|
|
|
#4 | |
|
Confirmed User
Join Date: Jul 2001
Location: See sig
Posts: 6,989
|
Quote:
|
|
|
|
|
|
|
#5 |
|
Confirmed User
Join Date: Jul 2001
Location: See sig
Posts: 6,989
|
Never mind how to stop it - we want to know why they're doing it. We need the drama!
|
|
|
|
|
|
#6 |
|
GFY HALL OF FAME DAMMIT!!!
Join Date: Jan 2002
Location: that 504
Posts: 60,840
|
why are they doing it?
hehe ![]()
__________________
![]() Want an Android App for your tube, membership, or free site? Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - |
|
|
|
|
|
#7 |
|
GFY HALL OF FAME DAMMIT!!!
Join Date: Jan 2002
Location: that 504
Posts: 60,840
|
better yet, <i>who</i> is doing it?
heheh
__________________
![]() Want an Android App for your tube, membership, or free site? Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - |
|
|
|
|
|
#8 |
|
Confirmed User
Join Date: Jul 2001
Location: See sig
Posts: 6,989
|
And are they bigger than you. Better still is their dad bigger than your dad. We need details!
|
|
|
|
|
|
#9 |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
It's one of my mainstream sites, not adult, huge site, tons of people love it, a few people hate it (as always), jealous people, assholes, what have you. So just recently this new object code starts being used and its the most annoying thing I've seen yet, and I cant figure out for the life of me a way to fix this but it's being used by a LOT of people.
If I'm fucked and theres nothing I can do about it, be straight forward about it and just give me the bad news, but if anyone knows of anything at all, please help me out here. C. |
|
|
|
|
|
#10 |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
bump...
|
|
|
|
|
|
#11 |
|
Guest
Posts: n/a
|
Contact his host, and tell them to shut him down for illegal activity.
That's about the only thing I can think of. |
|
|
|
#12 | |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
Quote:
i'm dying here... C. |
|
|
|
|
|
|
#13 |
|
Show Yer Tits!
Industry Role:
Join Date: Feb 2002
Location: Somewhere Out there...
Posts: 25,792
|
So tell us what did you do to piss off so many. What's the URL?
__________________
![]() Scammer Alert: acer19 acer [email protected] [email protected] Money stolen using PayPal
|
|
|
|
|
|
#14 | |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
Quote:
![]() |
|
|
|
|
|
|
#15 | |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
Quote:
|
|
|
|
|
|
|
#16 |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
bump, is there no answer on this or way of dealing with this?
|
|
|
|
|
|
#17 |
|
HAL 9000
Industry Role:
Join Date: May 2001
Posts: 34,515
|
your enemies sound dedicated on what they do....Maybe some of the admins that post here will be able to help.
|
|
|
|
|
|
#18 |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
what im more concerned about, and maybe this will help you guys comeup with an answer... i'm not concerned that much with them using the code and pulling my site. all i really want to know is how to tell that its a real visitor hitting the page, and not a user on a page with an "object" tag embeded into it. i know a way must exist, especially with hitbot prevention and things like that...
anyone??? |
|
|
|
|
|
#19 |
|
The O is for Oohhh
Join Date: Feb 2003
Location: AUSTIN TEJAS
Posts: 10,861
|
One thing that you could do that won't neccessarily make it go away, but it would reduce bandwidth is change the exact page that they are loading to something else.
So if your site is index.html, make the index.html as small as possible with an ENTER button to a renamed page with your site on it. Then you can keep changing the target page real easy and each time, they would have to change all their OBJECT tags and hopefully get sick of doing it. As far as detecting if it's a surfer or a pulled OBJECT tag, there might be a way to query the CGI.HTTP type shit. If you run a HTTP-REFER, you could tell where the surfers are coming from, and you could match it against a list of offending sites. I don't really know that much... just kinda "typing outloud". |
|
|
|
|
|
#20 |
|
Confirmed User
Join Date: Jan 2002
Location: Mountains of Western North Carolina.
Posts: 4,027
|
It's called being image sourced.
You won't find much help on this board to prevent it because it will attract cheaters like cockroaches. Most mainstream admins won't know how to prevent it because they have probably never seen it before. My advice: Stop pissing people off so that they won't image source you. and 2: Hire an admin that can keep you out of trouble if you can't keep yourself out of trouble. Good Luck |
|
|
|
|
|
#21 |
|
Too lazy to set a custom title
Join Date: Jan 2002
Location: Holland
Posts: 9,870
|
Its easy but im not gonna tell you because you wont tell us where and why
__________________
Don't let greediness blur your vision | You gotta let some shit slide icq - 441-456-888 |
|
|
|
|
|
#22 |
|
So Fucking Banned
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
|
1. I cant see why hundrads of site would do that to you if they were not hosted by the same guys.
2. EVEN if hundrads of sites do that to you, probably most of them do not have traffic. So it shouldn't hurt you and therefore not a problem. 3. IF hundrads of site with a lot of traffic do that to you that means you pissed alot of different people cause its not probable that one person with hundrads of sites which all are big is attacking you like that. 4. If 3 is indeed the case, take action against this person. Alot of time, if its one person, the different sites are all hosted in the same place, or few different places. IN ANY CASE, redirect the hit back to the referrer from all the sites that do that to you. You can do that with mod_rewrite and RewriteMap. WARNING: Make sure that the sites (the hundrads you list there) are indeed hitting you, so you don't hit back on innocent sites. Recommendtion: start from the bigger ones so your immediate problem is fixed fast. |
|
|
|
|
|
#23 |
|
Fuck Checks, CASH only!
Join Date: May 2002
Location: New York City
Posts: 19,422
|
What type of site, whats the URL im nosey
__________________
![]() Spanking, Medical Fetish, Sleeping, Strap-on Anal Lesbians, Girls Fucking Guys, Handjob site REAL HOT, Shemales, Anal and Ass Licking sites 100% Real EXCLUSIVE with amazing retention, ccbill payouts, lots of content FREE FTP HOSTING Promote the largest and oldest member paid escort site, Converts 10 times better then any dating site, CCBill payouts ICQ# 158802076 |
|
|
|
|
|
#24 | |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
Quote:
I will tell you though that its not us, or our sites "pissing off" people, what happens is we find cheaters, or hackers, or spammers, and we ban them from our network, and they retaliate by doing things like this as well as constant DOS attacks and things of that nature. Which, we have measures in place to take care of just about anything but the object code is new news to us and we're just now trying to figure out how to deal with it. The site gets a around 50,000 + signups a day and we ban quite a few guys everyday, so we've built up quite a good group of guys that have nothing better to do than try and hack and take down our network. Grumpy - If you actually genuinely have a clue as to how to help me on this and it is that "easy" then please email me and I will gladly speak with you if you'd be willing to help me out and I would certainly owe you. Night guys, C. |
|
|
|
|
|
|
#25 | |
|
Registered User
Join Date: Feb 2003
Location: minnesota
Posts: 83
|
if you're using apache, and if i remember right....
put this into an .htaccess file in the root SetEnvIfNoCase Referer "^http://offending\.domain\.com/" bad_ref=1 Order Deny,Allow Deny from env=bad_ref replace offending.domaim.com with the domain hosting the object tag in their page. make sure you notate dots as \. and preserve the ^ this will block any hits with them as the referer. hope that works for you. `lb ps. apache people does that sound right? Quote:
__________________
cube life got me down icq# 21315507 |
|
|
|
|
|
|
#26 |
|
Confirmed User
Join Date: Sep 2001
Location: Kentucky USA
Posts: 689
|
well you could just take the page they are hitting and remove all the html but a link to an alternate page then use
< script src="site url" language=something></script if you only have a small page and it creates a loop (not sure if it will but it might) then both sites get hit hard with hits but you use less bandwidth. Nbritt |
|
|
|
|
|
#27 | |
|
So Fucking Banned
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
|
Quote:
See what I suggested above and what greedinc wrote. He has hundrads of attacking domains (which sounds strange to me but anyway).. therefore what you wrote wont help him. greedinc: I don't know why I am helping you with this since you are "saying" you are attacked by bad guys BUT you are not willing to say which URLs the attackers use and which URLs of yours they attack. I don't understand what you have to hide it you claim to be a legit player. Can you explain? Are you doing CP or other illegal stuff?? Well, I guess I am helping you because you MIGHT be telling the truth in a way and for the chance that this is the case - I am willing to help. If you have 100s of domains attacking do this... Create a map file with pairs of the attacking domains and the word NWJ (acronyms of "No Way Jose") ;) like that... http://www.attacker1.com NWJ http://www.attacker2.com NWJ etc.. Enable mod_rewrite it its not yet enabled on your webserver. Set a "RewriteMap NWJMap txt:/path/to/NWJ.dat" break down the %{HTTP_REFERER} with a REGEXP rewrite condition and get the first part up to the THIRD backslash (Not including) leaving you with the http://......com in $1 Do a "RewriteCond ${NWJMap:$1} ^NWJ$" Do a rewrite rule to http:// so that the client will show 404 for the onject. I redraw from my prior suggestion. do NOT, I repeat - NOT, send the hit back to the attacker. For 3 reasons: 1. The attacker/s can redirect the rediretion BACK to you and so you will be damaged once again 2. It is illegal - even when he attacks you 3. The attacker/s might be using a third party system or a free host - in that case you will be attacking that system and you will damage innocent people. Do NOT redirect traffic back to the attackers!! Hope it helps |
|
|
|
|
|
|
#28 | |
|
So Fucking Banned
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
|
Quote:
The problem with the attack is hardly the BW or the size of the page. Its the process Apache creates for the serving of the page. Your solution will not help at all for that problem. saying the truth, my solution will not solve everything as well, but just half of the problem Also - call to the server from an OBJECT does NOT run the JS and will not create a loop no matter what - so I dont see what you mean. A solution to the httpd process creation is using a reverse proxy. That will expedite the creation of the responder by using threads instead of processes. Using something like Squid in a rev-proxy/web-accelerator is a good choice |
|
|
|
|
|
|
#29 |
|
So Fucking Banned
Join Date: Mar 2002
Location: Far out in the uncharted backwaters of the unfashionable end of the Western Spiral arm of the Galaxy
Posts: 893
|
BTW - greedinc
It seems strange to me... Your attackers are amateurs and newbies. They are hardly hackers. If they were smart they would be using spoofed IPs through loose source routing and fake packet parameters as well as manipulated protocol parameters and fake referer. Since no newbie know what that means - its not really dangerous to say what I just did DIE CHEATERS DIE ![]() |
|
|
|
|
|
#30 | |
|
Confirmed User
Join Date: Oct 2002
Posts: 245
|
Quote:
Take it easy, and thanks again, C. |
|
|
|
|
|
|
#31 | |
|
Confirmed User
Join Date: Sep 2001
Location: Kentucky USA
Posts: 689
|
Quote:
Nbritt |
|
|
|
|