Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Forged IP address
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Forged IP address

 Post Reply Post Reply
Author
Vapor View Drop Down
Newbie
Newbie


Joined: 02 November 2004
Location: United States
Status: Offline
Points: 10
Post Options Post Options   Thanks (0) Thanks(0)   Quote Vapor Quote  Post ReplyReply Direct Link To This Post Topic: Forged IP address
    Posted: 17 November 2004 at 2:04pm

Today, I had a user post a message from my IP address.  I'm on a cable connection which gives users a unique IP Address.  I run a hardware firewall, a software firewall, Norton AV, and I don't open attachments.  I scan routinely, including today.

I consider it unlikely that I have been "hacked", but I'll take what precautions I can to ensure that I have not.

It is my assumption currently that the posting IP address was forged, by a "bot"

The "user" set up a message on my board, then spammed Yahoo Finance to direct people to my board.  From there, they hoped to direct traffic to their site - there was a link in the message.

It's my assumption that this was an automated process.

Here is one Yahoo Finance link

Here is another

Here is a third

I'm sure there are more.  I've been using version 7.9 of the forum for approximately 1-2 weeks.  My IP address is the most prolific on the board with approx 3000 posts.  If any crawler is able to crawl the board with appropriate permissions, then this would be the most frequent IP address used within the last week.

The IP address that the person registered from is:  24.244.141.102

I track "latest IP address" and "registration IP address" silently in a seperate table.

That address has been banned, of course.

This is all that I can provide at this point as far as the anatomy of the attack goes. 

My forum admin name and password was changed, of course, and the version I am using is SQL Server.   

Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Post Options Post Options   Thanks (0) Thanks(0)   Quote dj air Quote  Post ReplyReply Direct Link To This Post Posted: 17 November 2004 at 2:47pm
someone probbabbly fakes the Ip address. is easy to do.
Back to Top
xeerex View Drop Down
Senior Member
Senior Member


Joined: 19 November 2002
Location: United States
Status: Offline
Points: 601
Post Options Post Options   Thanks (0) Thanks(0)   Quote xeerex Quote  Post ReplyReply Direct Link To This Post Posted: 17 November 2004 at 2:56pm
/agree with dj air

Spoofing IP addresses isn't difficult at all. Heck, you can even spoof the MAC address of your NIC if you want..

Originally posted by wrote:

If any crawler is able to crawl the board with appropriate permissions


I've actually mod'ed one of my forums so that the IP tracking is on but only admins have permissions to view it. This is mainly because they freak out even if it's just a message of "your ip is logged." /shakes his head.

Remember, that bots can only crawl the same HTML code that the browser renders. This is why search bots can index a forum but not if you have group or password protected content.
Back to Top
delirium View Drop Down
Newbie
Newbie


Joined: 19 November 2004
Status: Offline
Points: 1
Post Options Post Options   Thanks (0) Thanks(0)   Quote delirium Quote  Post ReplyReply Direct Link To This Post Posted: 19 November 2004 at 12:09am

Would someone be able to tell me how to hide the IP addresses from everybody, including moderators, on web wiz forum. I would lke to set it up in such way that only admiistrator can view it.

Thank you

Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Post Options Post Options   Thanks (0) Thanks(0)   Quote dj air Quote  Post ReplyReply Direct Link To This Post Posted: 19 November 2004 at 5:20am
change lines 756 to 761 on the forum_posts.asp file from


 'If the user is the admin or moderatir then display the authors IP
If (blnAdmin OR blnModerator) AND strAuthorIP <> "" Then
Response.Write(" | " & strTxtIP & " <a href=""javascript:openWin('pop_up_IP_blocking.asp?IP= " & strAuthorIP & "&TID=" & lngTopicID & "','move','toolbar=0,location=0,status=0,menubar=0,sc rollbars=1,resizable=1,width=425,height=425')"" class=""smL ink"">" & strAuthorIP & "</a>")
      Else
          Response.Write(" | " & strTxtIPLogged)
            End If


to



   'If the user is the admin or moderatir then display the authors IP
    If (blnAdmin) AND strAuthorIP <> "" Then
Response.Write(" | " & strTxtIP & " <a href=""javascript:openWin('pop_up_IP_blocking.asp?IP= " & strAuthorIP & "&TID=" & lngTopicID & "','move','toolbar=0,location=0,status=0,menubar=0,sc rollbars=1,resizable=1,width=425,height=425')"" class=""smL ink"">" & strAuthorIP & "</a>")

     Else
        Response.Write(" | " & strTxtIPLogged)
            End If




Edited by dj air
Back to Top
bims View Drop Down
Groupie
Groupie
Avatar

Joined: 03 May 2004
Location: United Kingdom
Status: Offline
Points: 115
Post Options Post Options   Thanks (0) Thanks(0)   Quote bims Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2004 at 6:30am

Quote
Would someone be able to tell me how to hide the IP addresses from everybody

Isn't this the default in 7.9? Can ordinary users see all IP addresses? I thought they just see an 'IP logged' notification?

Back to Top
dj air View Drop Down
Senior Member
Senior Member
Avatar

Joined: 05 April 2002
Location: United Kingdom
Status: Offline
Points: 3627
Post Options Post Options   Thanks (0) Thanks(0)   Quote dj air Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2004 at 7:04am
only admin/Moderators are able to see Ip Addresses,
no one else can they see IP logged
Back to Top
xeerex View Drop Down
Senior Member
Senior Member


Joined: 19 November 2002
Location: United States
Status: Offline
Points: 601
Post Options Post Options   Thanks (0) Thanks(0)   Quote xeerex Quote  Post ReplyReply Direct Link To This Post Posted: 20 November 2004 at 5:23pm
Originally posted by wrote:

I thought they just see an 'IP logged' notification?


That is all they see, which tends to freak them out many times.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.