PDA

View Full Version : URGENT: Can this be done?


Fraki
10-22-02, 06:02 PM
This guy's spamming my guestbook as I type this, and I want to ban him from my site, can this be done? HTACCESS? Please help!

Laurey
10-22-02, 06:08 PM
put this in your .htaccess file:

<Limit GET>
order deny,allow
deny from 123.45.6.7
</Limit>


changing the 123.45.6.7 to the spammer's IP

hth,
-L

Fraki
10-22-02, 06:10 PM
Merci
Now, to get his IP... any ideas?

Laurey
10-22-02, 06:13 PM
download your access log (if you have logging turned on).. if he was doing it in the last few minutes.. you should be able to narrow his IP down by time and pages accessed. I believe the appropriate lines should be at the bottom of the file.

Fraki
10-22-02, 06:15 PM
Awh, forgot about that... Thanks!

Fraki
10-22-02, 06:30 PM
Originally posted by Laurey
<Limit GET>
order deny,allow
deny from 123.45.6.7
</Limit>


What part do I repeat if I want to ban more than IP?

NMS
10-22-02, 06:38 PM
check this site:

http://www.javascriptkit.com/howto/htaccess5.shtml

there is something about blocking with htaccess in the help.powweb.com/tutorials as well

Laurey
10-22-02, 06:41 PM
Originally posted by Fraki


What part do I repeat if I want to ban more than IP?

the:

deny from 0.0.0.0

of course.. replacing w/the appropriate IP ;)

Fraki
10-23-02, 02:55 AM
Seems like he's masking his IP somehow... The IP that was logged traces back to radware.anonymizer.com.

He was posting 2-3messages/second, and his IP was different each time...

Can I do anything?

Ajarn
10-23-02, 08:20 AM
If the IP's were all in the same block, you might try blocking whole blocks of IP addresses.

Of course, anyone else within that block won't have access, either...

Laurey
10-23-02, 12:08 PM
It's a bit late now, but for a 'quick' fix.. you could rename the cgi that your guest book uses so he's unable to post while you look up IP's.

As Ajarn said, blocking a block of IP's is a way to go also. Find out what this randomizer does/uses.. does it relay for people? if so.. block all IP's from them. Does it spoof them? if so.. that's gonna make it harder.

From what I can see.. anonymizer relays.. get thier IP block(s) & deny them in your .htaccess :)

-L