{"id":20283,"date":"2012-07-24T13:52:26","date_gmt":"2012-07-24T19:52:26","guid":{"rendered":"http:\/\/rankexploits.com\/musings\/?p=20283"},"modified":"2012-07-24T13:52:26","modified_gmt":"2012-07-24T19:52:26","slug":"protecting-the-blackboard-from-unauthorized-access","status":"publish","type":"post","link":"https:\/\/rankexploits.com\/musings\/2012\/protecting-the-blackboard-from-unauthorized-access\/","title":{"rendered":"Protecting The Blackboard from &#8220;unauthorized access&#8221;."},"content":{"rendered":"<p>The police announcement about closing the Climategate investigation turned my mind back to hack\/spam protection. A few of you will have noticed I&#8217;ve been fiddling with the hack protection.  I apologize to any who were presented the &#8220;scary page&#8221;, especially the person using a proxy. <\/p>\n<p>Just in case my new rules are bad I like to let you know about the recent batch:<\/p>\n<ol>\n<li>I tweaked so ZB Block now checks with a list of TOR exit  nodes when people comment.  This should bounce people who are commenting using TOR exit nodes. If you don&#8217;t know what these are, you are almost certainly not using one. (TOR is popular with virulent trolls.)<\/li>\n<li>For roughly 30 minutes, I tried blocking everything with the word &#8216;proxy&#8217; in the host <i>unless<\/i> it also contained &#8216;.googlebot.com&#8217; in the host.  I quickly learned why this is a very, very, very bad idea.\n<p>Those wondering why I would even consider such a move can learn my motivation by scanning can visit <a href=\"http:\/\/bannasties.com\/BanNastiesScripts\/ShowDetailsHosts.php?Host=proxy\">this page<\/a> which shows <i>quite often<\/i>, hackers, bots etc. hide behind hosts with the word &#8220;proxy&#8221; in the title.  Everything on that page got caught for violating some rule <em>other than<\/em> containing the word &#8220;proxy&#8221; in the title, so I thought I&#8217;d give blocking &#8216;proxy&#8217; a shot. <\/p>\n<p>I knew this was iffy. So I added the rule and checked the kill_log.txt file every 5 minutes. Unfortunately, I quickly also saw that hosts like &#8220;proxy.a.perfectly.valid.business.com&#8221; in the killed logs. I&#8217;m sure that was a human. Not only human, but a human who was smart enough not to reload the page 3 times&#8211; so they didn&#8217;t get themselves banned!  If you saw that&#8230; sorry. I won&#8217;t be blocking you and your coworkers for using a  &#8220;proxy.a.perfectly.valid.business.com&#8221; in future and you should be able to come back.  <\/li>\n<li>I added a rule that notices when someone makes a direct call to a &#8216;theme&#8217; that does not exist at my site and bans that IP. (The theme is what makes the blog look as it does.)  All blog visitors call the theme but <I>no<\/i> blog visitor should ever even think of trying to call a theme <em>directly<\/em> and they certainly shouldn&#8217;t call a theme I don&#8217;t even use. But bots rather frequently call non-existent themes associated with WordPress vulnerabilities especially the ones associated with the &#8220;timthumb.php&#8221; or the &#8220;uploadify.php&#8221; exploit. I&#8217;m now catching and banning these very early on. <\/li>\n<li>I added a rule that notices when someone tries to call a <i>non-existent<\/i> &#8216;plugin&#8217; directly and bans them. Plugins add functionality to WordPress- for example, one plugin lets you edit comments; another fishes out the recent comments for the sidebar and so on.  But people shouldn&#8217;t be calling plugins I don&#8217;t use at this blog.\n<p>This rule makes me a little nervous so I&#8217;m watching to see if it affects any humans. So far, it hasn&#8217;t. If you see the &#8220;scary&#8221; page, I apologize in advance. Send me an email and I can fix it. (I think you won&#8217;t see the page by accidentally violating a badly written rule but sometimes I only recognize the flaws in the implementation after I implement a rule.) <\/li>\n<li>Sometime last week, I got sick and tired of my killed_log.txt file filling with Brazilian&#8217;s pretending to be googlebot and banned Brazil at Cloudflare. This means people in Brazil will be required to fill out a Captcha.  People in China are also required to fill out a Captcha. (To see how constant the Brazilian Googlebot spoofing was, visit <a href=\"http:\/\/bannasties.com\/BanNastiesScripts\/ShowDetailsWhy.php?Why=googlebot\">googlebot spoofers<\/a>; the letters &#8220;BR&#8221; stand for Brazil.  If you are planning a trip to Brazil, let me know and I can probably whitelist your hotel&#8217;s IP.  <\/li>\n<li>I created pages to permit me to search my spam logs for IPs, hosts, and various search terms. I&#8217;ll be displaying some of these from time to time in blog posts at the most boring blog ever, <a href=\"http:\/\/blog.bannasties.com\/\">Ban Nasties.<\/a> <\/li>\n<li>I&#8217;ve been adding large blocks of IPs from troublesome sites to the range of IPs blocked at Cloudflare. The trouble spots are generally associated with hosting services and cloud networks. Most people surf the web using ISPs; so blocking the more troublesome servers should affect a small fraction of potential visitors.  But if you use a VPN you might have a difficulty. If you do, let me know. I some cases, I might whitelist your IP even if the IP you present is associated by a company from which lots of hackage emanates. In somecases, I might suggest you switch IPs (as some VPN hosts permit.)  <\/li>\n<\/ol>\n<p>I should be back to climate blogging tomorrow or Thursday. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The police announcement about closing the Climategate investigation turned my mind back to hack\/spam protection. A few of you will have noticed I&#8217;ve been fiddling with the hack protection. I apologize to any who were presented the &#8220;scary page&#8221;, especially the person using a proxy. Just in case my new rules are bad I like &hellip; <a href=\"https:\/\/rankexploits.com\/musings\/2012\/protecting-the-blackboard-from-unauthorized-access\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Protecting The Blackboard from &#8220;unauthorized access&#8221;.<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[72],"tags":[],"class_list":["post-20283","post","type-post","status-publish","format-standard","hentry","category-random"],"_links":{"self":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts\/20283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/comments?post=20283"}],"version-history":[{"count":0,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts\/20283\/revisions"}],"wp:attachment":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/media?parent=20283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/categories?post=20283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/tags?post=20283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}