Forum Moderators: phranque

Message Too Old, No Replies

Got Hacked and need to setup a good htacess file.

Need Help!

         

charles99

2:20 am on Jul 26, 2010 (gmt 0)

10+ Year Member



We got hacked about 4 weeks ago and we are still trying to fix our system. As we are building our new site we are going the following request for files, that are no longer on our hosting company server. And when you look at the visitor file we see our own I.P. address which is another odd thing. Because we have not been logged into our hosting account since our system was hacked.

So after doing a search on the following requests below, it lead us here, and we are hoping someone in this forum can help us. We are new and we need you to take that into account.

Host: 87.111.168.205
/phpMyAdmin-2.6.1-pl1/scripts/setup.php
/phpMyAdmin-2.6.1-pl3/scripts/setup.php
/phpMyAdmin-2.6.1-rc2/scripts/setup.php
/pHpMyAdMiN/scripts/setup.php
Over 30 requests from this one I.P. Address

And these two I.P. Addresses is on our I.P. Block List and yet they are still showing up in our visitor log.

95.108.157.251
YandexBot/3.0; +http://yandex.com/bots)

220.181.7.19
Baiduspider+(+http://www.baidu.com/search/spider.htm)


We need help in the worst-est way... So please learning is not in the equation, we need to fix this headache first, then go back and learn or build on what someone in here help on.

we need two things: We would like to block everything coming out of China, Russia and Spain!

And setup the right Rewrite Statement. I am not asking anyone to do it for us, but I am asking someone to help us do it right!



These requests is coming from Spain! And others are coming from China. We did a I.P. Address block on a number of addresses but we are still finding the same names.

What has us and our hosting company confused is the requests that are coming from our own I.P.! We do not have any files on our hosting company server, we deleted everything because we didn't which file they changed other than the home page...


These request came from our own I.P. which we know we didn't make. And this system we are using know is clean. Reformatted, New Software installed, so we are at a last on how our I.P. Address is showing up? Remote access to our computer is not possible. We are building everything offline...


Coming from our own I.P. address
/nosuichfile.php
Http Code: 404Date: Jul 25 14:24:52Http Version: HTTP/1.1Size in Bytes: 777
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

/p/m/a/scripts/setup.php
Http Code: 404Date: Jul 25 14:25:40Http Version: HTTP/1.1Size in Bytes: 785
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

/dbadmin/scripts/setup.php
Http Code: 404Date: Jul 25 14:25:52Http Version: HTTP/1.1Size in Bytes: 787
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

/phpMyAdmin-2.4.1/scripts/setup.php
Http Code: 404Date: Jul 25 14:26:17Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

/phpMyAdmin-2.6.9/scripts/setup.php
Http Code: 404Date: Jul 25 14:26:41Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

/phpMyAdmin-2.7.0-pl1/scripts/setup.php
Http Code: 404Date: Jul 25 14:26:54Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8

/admin/mysql/scripts/setup.php
Http Code: 404Date: Jul 25 14:38:14Http Version: HTTP/1.1Size in Bytes: 791
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4

/favicon.ico
Http Code: 200Date: Jul 25 14:38:14Http Version: HTTP/1.1Size in Bytes: 409
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4

/PMA/scripts/setup.php
Http Code: 404Date: Jul 25 14:38:33Http Version: HTTP/1.1Size in Bytes: 783
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4

/noxdir/nosuichfile.php
Http Code: 404Date: Jul 25 14:40:51Http Version: HTTP/1.1Size in Bytes: 784
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4

/
Http Code: 404Date: Jul 25 15:36:28Http Version: HTTP/1.1Size in Bytes: 766
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4

/dir
Http Code: 404Date: Jul 25 15:36:55Http Version: HTTP/1.1Size in Bytes: 769
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/533.4 (KHTML, like Gecko) Chrome/5.0.375.99 Safari/533.4









These came from the following I.P. Address in Spain...

Host: 87.111.168.205

/admin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:50Http Version: HTTP/1.1Size in Bytes: 785
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/admin/mysql/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:49Http Version: HTTP/1.1Size in Bytes: 791
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/admin/phpmyadmin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:49Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/admin/pma/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:49Http Version: HTTP/1.1Size in Bytes: 752
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/nosuichfile.php
Http Code: 404Date: Jul 25 13:17:47Http Version: HTTP/1.1Size in Bytes: 777
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/noxdir/nosuichfile.php
Http Code: 404Date: Jul 25 13:17:48Http Version: HTTP/1.1Size in Bytes: 784
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/PMA/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:48Http Version: HTTP/1.1Size in Bytes: 783
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/PMA2005/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:48Http Version: HTTP/1.1Size in Bytes: 787
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/php-my-admin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:55Http Version: HTTP/1.1Size in Bytes: 792
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/php-myadmin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:55Http Version: HTTP/1.1Size in Bytes: 791
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/p/m/a/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:54Http Version: HTTP/1.1Size in Bytes: 785
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/pHpMy/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:54Http Version: HTTP/1.1Size in Bytes: 785
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/pHpMyAdMiN/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:54Http Version: HTTP/1.1Size in Bytes: 790
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/mysqladmin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:53Http Version: HTTP/1.1Size in Bytes: 790
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/mysqlmanager/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:53Http Version: HTTP/1.1Size in Bytes: 792
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/mysql-admin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:52Http Version: HTTP/1.1Size in Bytes: 754
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/mysql/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:52Http Version: HTTP/1.1Size in Bytes: 785
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/db/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:50Http Version: HTTP/1.1Size in Bytes: 782
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/dbadmin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:51Http Version: HTTP/1.1Size in Bytes: 787
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/myadmin/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:51Http Version: HTTP/1.1Size in Bytes: 787
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.2.3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:00Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.2.6/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:01Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.0/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:01Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.6/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:59Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.7/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:59Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.8/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:00Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.9/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:00Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.3/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:58Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.4/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:58Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.5/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:59Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.1/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:57Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.10/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:57Http Version: HTTP/1.1Size in Bytes: 798
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.11.2/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:58Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyA/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:56Http Version: HTTP/1.1Size in Bytes: 786
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmi/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:56Http Version: HTTP/1.1Size in Bytes: 789
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.10.0/scripts/setup.php
Http Code: 404Date: Jul 25 13:17:56Http Version: HTTP/1.1Size in Bytes: 797
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.9/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:05Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.0/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:06Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.8/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:05Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.6/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:04Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.7/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:04Http Version: HTTP/1.1Size in Bytes: 759
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.4/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:03Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.5/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:03Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:01Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:02Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.3.3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:02Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.9/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:11Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.0/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:11Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.7/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:10Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.8/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:10Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.6/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:09Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.5/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:09Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:08Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.4/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:08Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:07Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.4.1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:07Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.7-pl1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:16Http Version: HTTP/1.1Size in Bytes: 799
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.6-rc1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:15Http Version: HTTP/1.1Size in Bytes: 799
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.6-rc2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:15Http Version: HTTP/1.1Size in Bytes: 799
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.6/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:16Http Version: HTTP/1.1Size in Bytes: 795
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.5-rc1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:13Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.5-rc2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:14Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.5/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:14Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.4/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:13Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.5-pl1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:13Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:12Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:12Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:12Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-pl2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:20Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-pl3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:21Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-beta1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:19Http Version: HTTP/1.1Size in Bytes: 802
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-beta2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:20Http Version: HTTP/1.1Size in Bytes: 802
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-pl1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:20Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-alpha/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:18Http Version: HTTP/1.1Size in Bytes: 802
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-alpha2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:19Http Version: HTTP/1.1Size in Bytes: 803
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.8/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:18Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.9/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:18Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.5.7/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:17Http Version: HTTP/1.1Size in Bytes: 759
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:25Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.2-beta1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:26Http Version: HTTP/1.1Size in Bytes: 802
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.2-pl1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:26Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.1-rc1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:24Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.1-rc2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:25Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.1-pl2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:23Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.1-pl3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:24Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:23Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.1-pl1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:23Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-rc1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:21Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-rc2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:22Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.0-rc3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:22Http Version: HTTP/1.1Size in Bytes: 800
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.4/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:30Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.5/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:31Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.6/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:31Http Version: HTTP/1.1Size in Bytes: 796
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.4-pl4/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:30Http Version: HTTP/1.1Size in Bytes: 799
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.4-rc1/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:30Http Version: HTTP/1.1Size in Bytes: 763
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.4-pl2/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:29Http Version: HTTP/1.1Size in Bytes: 799
Referer: -
Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.6) Gecko/20100625 Firefox/3.6.6

/phpMyAdmin-2.6.4-pl3/scripts/setup.php
Http Code: 404Date: Jul 25 13:18:29Http Version: HTTP/1.1Size in Bytes: 799

SevenCubed

2:30 am on Jul 26, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It might be good to begin by reading this post --> [webmasterworld.com...]

Jim provided some excellent solutions to questions you are asking here. It will at the very least give you an idea of where to start

charles99

2:46 am on Jul 26, 2010 (gmt 0)

10+ Year Member



7C

i saw a post on here that JP help fix up and I wondering if we would be able to use it as a starting point?

charles99

2:53 am on Jul 26, 2010 (gmt 0)

10+ Year Member



We are new to this and we copied the post but still trying to see how it relates to everything thats coming at us...

Did kmonroe post the final version of his htaccess online?

SevenCubed

3:40 am on Jul 26, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



The final version would be the one posted by Jim as a suggestion for kmonroe.

When you say "we" I hope you don't mean you and I because that would be like the blind leading the blind. But I can suggest going to that solution by highlighting the terms "setup.php" and "nosuichfile.php" with your browser feature CTRL+F then search and highlight to see what was suggested as a solution.

Besides that I can't see that blocking a few single IPs are going to be effective because those bloodsuckers usually have networks of compromised PCs under their control from various places throughout the world. A good firewall configuration is a very good place to start.

What are you using for OS and/or control panel; if any?

jbgibson

7:35 pm on Jul 28, 2010 (gmt 0)

10+ Year Member



Don't be too shocked at evil traffic that looks like it's from yourself. If you get more than two spam emails a day some of them are probably "from" you -- similar situation. It's not terribly hard to spoof an IP.

I figure such traffic is somebody wanting to do something to my server... if the traffic doesn't have the real address of the sender, they're not getting responses back. A denial of service attack is one such evil intent. If it's trying to inject something through a form or query, spoofed-ip traffic could of course be trying to set my server up for somebody to later get something from it.

That's another reason why banning single IPs won't necessarily help.

The example traffic with all the phpmyadmin attempts -- that might be just background noise. If you don't have phpmyadmin reachable from the net, they're just irritants. The servers I help run get that kind of scriptkiddy tries all day long. I tend to block persistent IPs or whole subnets that have that attack signature just so I can see the sneakier stuff that it masks. The fix to ensure safety against that class of attacks is for you not to leave any default, setup, or standard material in place. If you're relying on a host, without setting up your apps yourself, that could be tough -- as you say right now you don't have time to learn all this stuff.

A danger that some hosts open customers up to, is over-broad permissions. Since you're not the owner/operator of what I assume is a multiuser server, the host (or the control panel they use) might be leaving stuff wide open to alteration by anyone who gets even a foot in the door. Since they dare not give you root access, they may wind up running apache/IIS/whatever app AS root - then you get the worst of both worlds. You can't edit some files you need to, to control your site, and an attacker can meddle with more than absolutely HAS to be left open. Maybe the control panel sets up an app for you, but it then leaves the config file open to view and or modification.

So to back up to a step before your question :-) I see log entries that are attempts - do you know it was that kind of stuff that got you hacked, or is the actual vector still a mystery?

charles99

1:31 am on Jul 29, 2010 (gmt 0)

10+ Year Member



It is still a mystery? But each IP we track either comes from China, Russia, Lativ, Poland or Japan. We think it was Alpha Points Component that gave them a way into our system... just days later we learned about a problem that was being reported or posted on the their forum and Joomla. Which didn't help us. And we did see a large number of requests for this component days earlier. Right now they are getting the error 404, because we don't have anything on our host server. we deleted everything because they made a backup copy of our system that had been hacked and reinstalled it just for these knuckleheads to do again 2 days later... Which was mind blowing, plus it told us a bit more about our host, which we have changed. the basic stuff we thought they to protect our content, they didn't...

So we are trying to piece together a good htaccess file and reaching out to other website owners. Our goal is to create or build a network around our system... 90% of the website owners on the internet are never going to make any real money but our system will allow us to make a ton! So we intend to start taping into their tech power in order to build a better gateway, and in return direct traffic plus create a unique revenue channel for them.

A couple million a year partnership... We thought we would have time to get 5 million to 10 million paying consumers into our system before hackers found us. Within this time our goal was to build a Support Team; throwing cash options and stuff... When we made money they would make money is our motto.

We really don't need Google or any of the S.E. because we know we will end up competing with them down the road. facebook is our target as far as members go, but Youtube is the way consumers will use our system if we could get the time to do 3 to 4 offline events. We know our system is going to take facebook members. They are at 500 million...

We think it will take us about 3 and half years to break them. So like I said in the other post keep these post because one day it will be worth millions...

The days when we didn't know how to create a htacess file! Now thats funny, and we are laughing at ourselves. But we also intend to laugh all the way to the bank, with cash in one hand and Facebook members in the other! We have placed my pride on he chair and sat on it, and hitting every forum, in order to build a reasonable shield around our system.



This is what we put together so far. Still trying to place everything in the right order... And if this is the worst that can happen god help Facebook and YouTube... Because we are going to kill them. But take a look and tell what we need to change or adjust... And I would like to think everyone thats helping us. My partner and I, we don't want that blind situation 7C mention above...



RewriteEngine on
Options +FollowSymLinks All -Indexes

#
# mod_rewrite in use

Order Deny,Allow
Deny from all
Allow from (our iP)


<Files .htaccess>
order allow,deny
deny from all
</Files>


<FilesMatch "configuration.php">
Order allow,deny
Deny from all
</FilesMatch>

<Files ~ "\.xml$">
Order allow,deny
Deny from all
Satisfy all
</Files>


<Files 403.shtml>
order allow,deny
allow from all
</Files>



RewriteRule setup\.php$ - [F]

RewriteBase /
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(www\.)?mysite.com/.*$ [NC]
RewriteRule \.(gif|jpg|swf|flv|png)$ /feed/ [R=302,L]


# block pre-fetch requests with X-moz headers
RewriteCond %{ENV:no_access} yes
RewriteRule .* - [F,L]

#REQUEST METHOD
RewriteCond %{REQUEST_METHOD} ^(delete|head|trace|track) [NC]
RewriteRule ^(.*)$ - [F,L]

RewriteCond %{HTTP_COOKIE} ^.*(<|>|'|%0A|%0D|%27|%3C|%3E|%00).* [NC]
RewriteRule ^(.*)$ - [F,L]

RewriteCond %{HTTP_REFERER} ^(.*)(<|>|'|%0A|%0D|%27|%3C|%3E|%00).* [NC,OR]
RewriteCond %{HTTP_REFERER} ^http://(www\.)?.*(-|.)?adult(-|.).*$ [NC,OR]
RewriteCond %{HTTP_REFERER} ^http://(www\.)?.*(-|.)?poker(-|.).*$ [NC,OR]
RewriteCond %{HTTP_REFERER} ^http://(www\.)?.*(-|.)?drugs(-|.).*$ [NC]
RewriteRule ^(.*)$ - [F,L]


RewriteCond %{TIME_HOUR} ^24$
RewriteRule ^.*$ - [F,L]


RewriteCond %{THE_REQUEST} ^.*(\\r|\\n|%0A|%0D).* [NC]
RewriteRule ^(.*)$ - [F,L]


RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|\%3D) [OR]
# Block out any script trying to base64_encode crap to send via URL
RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [OR]
# Block out any script that includes a <script> tag in URL
RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
# Send all blocked request to homepage with 403 Forbidden error!
RewriteRule ^(.*)$ index.php [F,L]
#
########## End - Rewrite rules to block out some common exploits

# Uncomment following line if your webserver's URL
# is not directly related to physical file paths.
# Update Your Joomla! Directory (just / for root)

# RewriteBase /

########## Begin - Joomla! core SEF Section
#
RewriteRule ^ - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
#
RewriteCond %{REQUEST_URI} !^/index\.php$
RewriteCond %{REQUEST_URI} (/[^.]*|\.(php|html?|feed|pdf|raw))$ [NC]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.php [L]
#
########## End - Joomla! core SEF Section



RewriteCond %{HTTP_REFERER} !^(http://(www\.)?mysite\.com.*)?$ [NC]
RewriteRule \. - [F]


RewriteRule ^/phpMyAdmin.*$ /index.php

AddHandler application/x-httpd-php52 .php .php3 .php4 .php5 .phtml


SetEnvIfNoCase User-Agent "windows 95" ban
SetEnvIfNoCase User-Agent "windows 98" ban
SetEnvIfNoCase User-Agent "windows NT" ban
SetEnvIfNoCase Referer "\.cn" ban
SetEnvIfNoCase Referer "\.ro" ban
SetEnvIfNoCase Referer "\.ru" ban
SetEnvIfNoCase Referer "\.es" ban
SetEnvIfNoCase Referer "\.id" ban
SetEnvIfNoCase Referer "\.in" ban
SetEnvIf Request_URI "\.php" ban
SetEnvIf Request_URI "(robots\.txt)$" pass


SetEnvIfNoCase X-Forwarded-For .+ proxy=yes
SetEnvIfNoCase X-moz prefetch no_access=yes


SetEnvIfNoCase User-Agent libwww-perl bad_bots
order deny,allow
deny from env=bad_bots


<FilesMatch "\.(cgi|pl|py|txt)">
Deny from all
</FilesMatch>

<FilesMatch robots.txt>
Allow from all
</FilesMatch>

charles99

9:57 pm on Aug 1, 2010 (gmt 0)

10+ Year Member



Hey I need a bit help figuring this one out. After adjust my htaccess file I am get the following error:

Moved Permanently
The document has moved here.

Additionally, a 400 Bad Request error was encountered while trying to use an ErrorDocument to handle the request.


SetEnvIfNoCase User-Agent "windows 95" ban
SetEnvIfNoCase User-Agent "windows 98" ban
SetEnvIfNoCase Referer "\.cn" ban
SetEnvIfNoCase Referer "\.ro" ban
SetEnvIfNoCase Referer "\.ru" ban
SetEnvIfNoCase Referer "\.lv" ban
SetEnvIfNoCase Referer "\.jp" ban
SetEnvIfNoCase Referer "\.su" ban
SetEnvIfNoCase Referer "\.in" ban
SetEnvIfNoCase Referer "\.id" ban
SetEnvIfNoCase Referer "\.pl" ban
SetEnvIfNoCase Referer "\.si" ban
SetEnvIfNoCase Referer "\.tr" ban
SetEnvIfNoCase Referer "\.hk" ban
SetEnvIfNoCase Referer "\.ua" ban
SetEnvIfNoCase Referer "\.ir" ban
SetEnvIfNoCase Referer "\.cz" ban
SetEnvIfNoCase Referer "\.bd" ban
SetEnvIfNoCase Referer "\.hr" ban
SetEnvIfNoCase Referer "\.es" ban
SetEnvIf Request_URI "\.php" ban
SetEnvIf Request_URI "(robots\.txt)$" pass


SetEnvIfNoCase X-Forwarded-For .+ proxy=yes
SetEnvIfNoCase X-moz prefetch no_access=yes


SetEnvIfNoCase User-Agent libwww-perl bad_bots
order deny,allow
deny from env=bad_bots

jdMorgan

1:57 pm on Aug 2, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I suggest that you stop adding code until you get the basic stuff working. Comment-out all of the access-control rules, and then un-comment them one block at a time to isolate the problem. "When you find yourself in a hole, the first thing to do is to stop digging."

Also, you are posting so much stuiff here that you are limiting your audience; Not many are willing to read such long posts...

Your redirect (with the [R=302] flag) is missing the protocol and the hostname. Specify a full URL path in every rule that performs an external redirect, as in http://www.example.com/feed/ [R=302,L]

Order your rule like this:
  • All access-control code (rules with [F] flags)
  • All external redirects (rules specifying [R=30x] or containing a protocol and full URL in the substitution)
  • All internal rewrites, with the Joomla rewrite rules last.

    Within each of these three sets, you want the rules ordered from most-specific patterns and conditions (one or only a few URLs affected) to least-specific patterns and conditions (many URLs affected).

    The 400-Invalid Request error points to a problem with your ErrorDocument directives. I don't see them in any of the code you've posted, so these could have been defined in your "control Panel." Either way, the defintion is likely incorrect. The code --either typed in directly, or generated by the Control Panel-- should look like this:
     ErrorDocument 403 /local-path-to-custom-403-error-page.html 


    That is, the path should be relative to your "home page" directory, and must be given as a filepath, not as a URL.

    Jim
  • charles99

    3:51 pm on Aug 2, 2010 (gmt 0)

    10+ Year Member



    We fixed the error... Redirect www. and non www was the problem...

    ErrorDocument 400 /errorpage.php
    ErrorDocument 401 /errorpage.php
    ErrorDocument 403 /errorpage.php
    ErrorDocument 404 /errorpage.php
    ErrorDocument 500 /errorpage.php

    these are the files we have in our root now...

    http://www.example.com/feed/ [R=302,L]

    we have changed all of our 301 and 302 to

    [mysite.com...] [R=302,L]

    and thank J and everyone else... We are still trying to figure all this out as we go and what we learn is what we will pass out on, so keep in mind you are not just help us, but everyone we help and everyone they help...


    SetEnvIf Request_URI "\.php" ban
    SetEnvIf Request_URI "(robots\.txt)$" pass

    is this correct or do we need to place our url in here? Also can I send you a final copy of our htaccess by email or sticky to check before we post it. Would like to know we made all the changes everyone threw at us...