<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="https://syndication.webwiz.net/rss_namespace/">
 <channel>
  <title>Web Wiz Support and Community Forums : Advice wanted on suspicious activity</title>
  <link>https://forums.webwiz.net/</link>
  <description><![CDATA[This is an XML content feed of; Web Wiz Support and Community Forums : Web Wiz Forums : Advice wanted on suspicious activity]]></description>
  <copyright>Copyright (c) 2006-2013 Web Wiz Forums - All Rights Reserved.</copyright>
  <pubDate>Thu, 09 Apr 2026 01:23:25 +0000</pubDate>
  <lastBuildDate>Mon, 18 Sep 2006 14:21:42 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 12.08</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://forums.webwiz.net/RSS_post_feed.asp?TID=21329</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Web Wiz Support and Community Forums]]></title>
   <url>https://forums.webwiz.net/forum_images/web_wiz_forums.png</url>
   <link>https://forums.webwiz.net/</link>
  </image>
  <item>
   <title><![CDATA[Advice wanted on suspicious activity : Topic renamed to reflect my intentions...]]></title>
   <link>https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114204.html#114204</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=20240">ToJaRo</a><br /><strong>Subject:</strong> 21329<br /><strong>Posted:</strong> 18&nbsp;September&nbsp;2006 at 2:21pm<br /><br />Topic renamed to reflect my intentions with the original post.<DIV>&nbsp;</DIV><DIV>Another tidbit of info... I run multiple websites on my servers and this particular site is the only&nbsp;one I have with&nbsp;WWF. I also have host headers&nbsp;enabled on each site and if&nbsp;it was just a bot&nbsp;port scanning just by IP it would have been directed to a honeypot I have set up.&nbsp; </DIV><DIV>&nbsp;</DIV><DIV>It&nbsp;picked this site and thread for a reason I believe... I wanted to know what others in the community thought about this particular activity.</DIV><span style="font-size:10px"><br /><br />Edited by ToJaRo - 18&nbsp;September&nbsp;2006 at 2:45pm</span>]]>
   </description>
   <pubDate>Mon, 18 Sep 2006 14:21:42 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114204.html#114204</guid>
  </item> 
  <item>
   <title><![CDATA[Advice wanted on suspicious activity : My apologies borg if that came...]]></title>
   <link>https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114202.html#114202</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=20240">ToJaRo</a><br /><strong>Subject:</strong> 21329<br /><strong>Posted:</strong> 18&nbsp;September&nbsp;2006 at 1:56pm<br /><br />My apologies borg if that came across wrong, I should have been more clear.&nbsp;&nbsp; I was in not trying to say your software is insecure.&nbsp; I would not be using it if I believed it was insecure. You have done a great job in keeping the software up to date and that is why I purchased your Forum software. My intent was to see if anyone else was having this issue or seeing something weird like this on their forum from a suspect connection.<DIV>&nbsp;</DIV><DIV>I do not have guest posting enabled and this could have potentially be a bot using a thread with a lot of pictures in it to begin a DOS attack or since it knows I have image uploads enabled it was trying to crack into that with multiple IIS exploits scanners.</DIV><DIV>&nbsp;</DIV><DIV>You're probably correct that it is just a bot trying to post some sort of SPAM...&nbsp; but why it was stuck to one thread with several images was strange to say the least. </DIV>]]>
   </description>
   <pubDate>Mon, 18 Sep 2006 13:56:47 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114202.html#114202</guid>
  </item> 
  <item>
   <title><![CDATA[Advice wanted on suspicious activity : Web Wiz Forums is probably the...]]></title>
   <link>https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114194.html#114194</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=1">WebWiz-Bruce</a><br /><strong>Subject:</strong> 21329<br /><strong>Posted:</strong> 18&nbsp;September&nbsp;2006 at 9:54am<br /><br />Web Wiz Forums is probably the most secure bulletin board system you can get.<br><br>Security web sites are constantly monitored for any reported exploits and any found are patched, so far all within 12 hours.<br><br>Many 100's of hours have been spent on researching hacking techniques and coding Web Wiz Forums to be as secure as it possibly can, which is why any exploits ever found have always been quite minor and always patched with a new version released within hours of any found.<br><br>If you look at your log files long enough you will always find strange things like you mention, this site has 100's everyday.<br><br>I would imagine that the problem in your case is that robot has got hold of the URL on your site and is scanning it periodically for things like email addresses to harvest or forms to auto file in to spam your site.<br><br>If you have Guest posting enabled I would imagine that the hits are from a bot trying to remote file in the post form to spam your site, however, the CAPTCHA security image that is displayed for Guest Posting will prevent this type of spam.<br>]]>
   </description>
   <pubDate>Mon, 18 Sep 2006 09:54:36 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114194.html#114194</guid>
  </item> 
  <item>
   <title><![CDATA[Advice wanted on suspicious activity : I have had some strange behavior...]]></title>
   <link>https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114184.html#114184</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://forums.webwiz.net/member_profile.asp?PF=20240">ToJaRo</a><br /><strong>Subject:</strong> 21329<br /><strong>Posted:</strong> 18&nbsp;September&nbsp;2006 at 3:39am<br /><br />I have had some strange behavior occur on my site over the past 24 hours that I have watched closely.&nbsp; <DIV>&nbsp;</DIV><DIV>I watch Active Users quite frequently on my site and I started to see multiple browsers with Windows XP all viewing an old topic that has several post with pictures in it.&nbsp; I noticed that a new 'guest' was hitting that particular thread every 1 minute.&nbsp; Very strange, so I watched this over the next 24 hours to see if it was just some friends that had stumbled across the site and were viewing it simultaneously.&nbsp; I constantly watched the netstat log on my computer and my Firewall and noticed that ALL of them were coming from two subnet ranges.&nbsp; 59.x.x.x, 149.135.x.x&nbsp;and 210.x.x.x. Most of which were coming from three particular IP's.&nbsp;</DIV><DIV>&nbsp;</DIV><DIV>I then did a lookup on these IP's and all of them where from the OrgName:&nbsp;&nbsp;&nbsp; Asia Pacific Network Information Centre.&nbsp;&nbsp;&nbsp;</DIV><DIV>&nbsp;</DIV><DIV>I then blocked these three subnets from my firewall and but I am wondering if they are looking for something in particular or if they were trying to exploit just my server or if it was a fluke incident, which I doubt. We are pretty much a localized forum and I dont think we have an international following.</DIV><DIV>&nbsp;</DIV><DIV>As soon as I block one another appears to replace it.</DIV><DIV>&nbsp;</DIV><DIV>I run an SQL forum on 8.04 and I have upload images enabled on my forum... any body else seeing this sorta thing? I block one IP range and a new one from the APNIC shows up looking at the same topic with multiple 'hits' to the same thread.</DIV><span style="font-size:10px"><br /><br />Edited by ToJaRo - 18&nbsp;September&nbsp;2006 at 2:20pm</span>]]>
   </description>
   <pubDate>Mon, 18 Sep 2006 03:39:41 +0000</pubDate>
   <guid isPermaLink="true">https://forums.webwiz.net/advice-wanted-on-suspicious-activity_topic21329_post114184.html#114184</guid>
  </item> 
 </channel>
</rss>