Web Wiz - Green Windows Web Hosting

  New Posts New Posts RSS Feed - Hacker Tracker
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Hacker Tracker

 Post Reply Post Reply Page  12>
Author
pedalcars View Drop Down
Senior Member
Senior Member


Joined: 12 August 2002
Location: United Kingdom
Status: Offline
Points: 268
Post Options Post Options   Thanks (0) Thanks(0)   Quote pedalcars Quote  Post ReplyReply Direct Link To This Post Topic: Hacker Tracker
    Posted: 04 June 2003 at 5:35pm
I've just implemented a hacker tracker (200+ password guesses from an Algerian source the other day!).

When anyone puts in a wrong username / password combo into a login page that's tied in, it writes the date/time, source IP and hostname, page attacked, username and password tried to a DB. You can then log in and see if your login page has been attacked, which can then allow you to ban the source IP address from your site or report it to your host so they can, etc.

Just wondered if anyone else would be potentially interested in this; if so I would consider making it available.
www.pedalcars.info

The most fun on four wheels

Back to Top
the boss View Drop Down
Senior Member
Senior Member
Avatar

Joined: 19 January 2003
Location: Saudi Arabia
Status: Offline
Points: 1727
Post Options Post Options   Thanks (0) Thanks(0)   Quote the boss Quote  Post ReplyReply Direct Link To This Post Posted: 04 June 2003 at 5:45pm
MEEEEEEEEEEEEEE
Back to Top
Mart View Drop Down
Senior Member
Senior Member
Avatar

Joined: 30 November 2002
Status: Offline
Points: 2304
Post Options Post Options   Thanks (0) Thanks(0)   Quote Mart Quote  Post ReplyReply Direct Link To This Post Posted: 05 June 2003 at 9:12am
yea that sounds pretty good...
Back to Top
MorningZ View Drop Down
Senior Member
Senior Member
Avatar

Joined: 06 May 2002
Location: United States
Status: Offline
Points: 1793
Post Options Post Options   Thanks (0) Thanks(0)   Quote MorningZ Quote  Post ReplyReply Direct Link To This Post Posted: 05 June 2003 at 2:38pm

another step to take is track the number of attemps in a session variable... incrementing each invalid attempt

after three, just flat out kill the page

like wrap the whole login form in:
<if Not Session("LogInAttempts") > 3 then show form>

if you want to take a step and protect against simply closing the window and reopening it (to clear session), use a cookie instead

 

Contribute to the working anarchy we fondly call the Internet
Back to Top
the boss View Drop Down
Senior Member
Senior Member
Avatar

Joined: 19 January 2003
Location: Saudi Arabia
Status: Offline
Points: 1727
Post Options Post Options   Thanks (0) Thanks(0)   Quote the boss Quote  Post ReplyReply Direct Link To This Post Posted: 06 June 2003 at 12:22am
 awsome
Back to Top
pedalcars View Drop Down
Senior Member
Senior Member


Joined: 12 August 2002
Location: United Kingdom
Status: Offline
Points: 268
Post Options Post Options   Thanks (0) Thanks(0)   Quote pedalcars Quote  Post ReplyReply Direct Link To This Post Posted: 06 June 2003 at 4:23am
That's not such a bad idea. Could set a cookie with maybe a 30 minute timeout, so 3 wrong attempts and you have to wait another half hour before you can try again.

As there seems to be some interest, I'll set about de-integrating it to turn it into a relatively simple bolt-on. No promises about timescales, mind!!
www.pedalcars.info

The most fun on four wheels

Back to Top
fernan82 View Drop Down
Mod Builder Group
Mod Builder Group
Avatar

Joined: 17 November 2002
Location: United States
Status: Offline
Points: 362
Post Options Post Options   Thanks (0) Thanks(0)   Quote fernan82 Quote  Post ReplyReply Direct Link To This Post Posted: 07 June 2003 at 4:59pm

i think one of the best ways to prevent your logins from being hacked is to track the session id on the form as -Borg- recently implemented on wwf (see the examples on the forums code) ...

the above are good suggestions but with some programming knowledge anyone can make a bot and try thousands of passwords in no time and get around cookies and all that, and by the time you read them logs the damage will be done already and the info in the logs will be useless as mostlikely all you'll have is an anonymous proxy IP and will never be able to get the hacker's IP

<edit> in simple words it's about impossible to track down a hacker, what you can do is try to keep them away...



Edited by fernan82
FeRnAN
Back to Top
neilcarter View Drop Down
Newbie
Newbie


Joined: 25 August 2002
Location: United Kingdom
Status: Offline
Points: 10
Post Options Post Options   Thanks (0) Thanks(0)   Quote neilcarter Quote  Post ReplyReply Direct Link To This Post Posted: 07 June 2003 at 7:07pm
Originally posted by fernan82 fernan82 wrote:

you'll have is an anonymous proxy IP and will never be able to get the hacker's IP

<edit> in simple words it's about impossible to track down a hacker, what you can do is try to keep them away...

In my experience ( 56GB Bandwidth of hacking attempts in the last week ) most attempts come from comprimised machines, mainly on broadband, rather than ananymous proxys. Logging the ips allows the offending machines isp to shut the connection down.

Neil

Back to Top
 Post Reply Post Reply Page  12>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.