Forum Moderators: open

Message Too Old, No Replies

Identifying These IP's

Totally Skewed my Log Report

         

JanCounselor

5:57 pm on May 28, 2002 (gmt 0)



I'm a newbie at lots of this. Last week's log report showed these two IP addresses and numbers of hits on my home page:

218.15.52.32 2,349
218.15.53.174 2,011

Since they both appear to be from the same block, I'm guessing it's the same spider.

I've printed off the search engine lists and blocks of IP addresses. Is there a reverse look-up of IP numbers type service?

Anyone identify? I'm researching how to avoid whatever it is they're doing. Reading some posts here to learn... Thanks.

PsychoTekk

6:20 pm on May 28, 2002 (gmt 0)

10+ Year Member



all IPs belong to the chinese telecom (an ISP)
it's unlikely that a spider hit your pages

many people block chinese/asian access since
a lot of attacks come from there.

JanCounselor

6:39 pm on May 28, 2002 (gmt 0)



Thank you PsychoTekk. I'll have to read up on how to do that. Not interested in having this continue!

Computers can be great; the internet can be great; but they both certainly come with a lot of hassles!!! ;^(

Jan

PsychoTekk

7:30 pm on May 28, 2002 (gmt 0)

10+ Year Member



if you search for terms like 'block' and 'rewrite'
you will find lots of neat stuff... mod_rewrite code,
lists of IPs to block (somewhere around here there even
was a special list to block chinese access)
have fun ;)

JamesR

7:36 pm on May 28, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Blocking Access from China [webmasterworld.com]

JanCounselor

8:42 pm on May 28, 2002 (gmt 0)



Thank you, guys! That's helpful, and I'll search on the other. Maybe one of you can give me a fast response that tells me if it is now necessary to write what I'll be writing into all of my web pages??!!?? Yike! Or just the home page? And where it goes...

Jan

PsychoTekk

8:52 pm on May 28, 2002 (gmt 0)

10+ Year Member



well if your stuff is hosted on a machine running apache
you have to create the file ".htaccess" in the root-dir.
there you put all the deny-access and rewrite code in...
for example

order allow,deny
allow from all
deny from 123.123.123.123

where 123.123.123.123 is the IP number you want to block
(of course you can block several numbers, too)

JanCounselor

9:29 pm on May 28, 2002 (gmt 0)



Ah, but my tech support at the host server tells me that Apache is for Unix/Linux (he pronounces it Lennox), sorry I don't know the spelling -- and I'm keeping my pages on an NT Server, because Unix won't handle the .asp that I'm attempting to convert to. (So I can use #include files for all my side and bottom linke, thus to make changes sooo much easier.)

So please start from there. He has no idea how/where I write this to, in that case.

Thank you, whoever can answer this for me.

I'm a do-it-yourselfer, and must ask all you smart people out there how to do what I need to do! ;-)

Jan

PsychoTekk

10:00 pm on May 28, 2002 (gmt 0)

10+ Year Member



hmmm, .htaccess won't work on NT machines, but there are apache
releases for NT ;)
no really, you might try to find some option in your IIS Manager
<added>
i once had IIS installed, i think the manager is in the control panel

JanCounselor

11:57 pm on May 28, 2002 (gmt 0)



I'm unfamiliar with an IIS Manager; and the only Control Panel with which I'm familiar is in my Windows 98 "My Computer", where I do not find any such...

More info, please...

wilderness

4:13 am on May 29, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Here's an old thread on IIS
[webmasterworld.com...]

JanCounselor

6:05 am on May 29, 2002 (gmt 0)



Thanks, Wildnerness. I'll check that out.

Jan

JanCounselor

4:11 pm on May 29, 2002 (gmt 0)



Okay. Thank you all. What I've learned is this: (And most of you are probably running your own servers, so you/I didn't realize the difference in the answers I needed.) I'm just an individual with a web site, on a separate (E-Access) web host's NT servers. I do not run my own server.

These two IP addresses (and maybe a 3rd that is likely in the same block) are not trying to hack my web site, but the web host's server, and failing, because there are no longer any vulnerabilities there!

The web host is the one who must put these numbers into their system (probably IIS). This is not something that is done at my end, since I'm not running a server.

Now, with all of the pieces of the puzzle in place, I post this information on the forum, so that others don't have to spend a day and a half trying to figure it all out and asking repeated questions...

The place to research IP addresses is at www.arin.net, on their IP address look-up utility.

Thank you, all. There is nothing else to do after I research these numbers, and give them to my web host to block.

Jan

PsychoTekk

5:04 pm on May 29, 2002 (gmt 0)

10+ Year Member



The place to research IP addresses is at www.arin.net, on their IP address look-up utility.

for america (the whole continent) it's ARIN.net
(American Registry for Internet Numbers),
for europe and some parts of africa it's RIPE.net
(Réseaux IP Européens (RIPE NCC) Network Coordination Centre)
and for the asian/pacific area APNIC.net
(Asia Pacific Network Information Center).

these are the three RIRs but there are also many other LocalIRs which sometimes
provide more detailed info on companies/persons:

whois.NIC.gov; US Government-Wide Registration Service
whois.NIC.mil; US Department of Defense Network Information Center (DoD NIC)
whois.NIC.uk; UK Internet Names Organisation
whois.NIC.fr; Association Française pour le Nommage Internet en Coopération (AFNIC)
whois.NIC.ch
whois.NIC.it; Italian Network Information Center
whois.NIC.mx; Network Information Center México
whois.NIC.ad.jp; Japan Network Information Center (JPNIC)
whois.NIC.nu
whois.ISI.edu; Information Sciences Institute
whois.InterNIC.net
whois.DENIC.de; German Network Information Center
whois.CIRA.ca; Canadian Internet Registration Authority
whois.NORID.no
whois.NetworkSolutions.com
whois.NIC-SE.se; Network Information Center Sweden
whois.domain-registry.nl; Stichting Internet Domeinregistratie Nederland (SIDN)
whois.NRL.Navy.mil; US Navy Naval Research Laboratory
whois.RIPN.net; Russian Institute for Public Networks
whois.DomaiNZ.net.nz; New Zealand Internet Registry LTD
whois.NIC.or.kr; Korea Internet Information Center (KRNIC)
whois.auNIC.net; .au Registration Services
whois.isNIC.is; Iceland Network Information Center
whois.toNIC.to; .to Domain Name Registry
whois.NIC.biz; .biz Network Information Center
whois.NIC.info; .info Network Information Center
whois.AUNIC.net; AUNIC Registration Services
whois.METU.edu.tr; Middle East Technical University (METU)
whois.CentralNIC.com; CentralNIC

just to name some of them.
most of those LIRs do not provide queries on IPs but
on hostnames, mostly to use without the www.-prefix,
while the RIRs also have a lot of other useful query possibilities

volatilegx

5:58 pm on May 29, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



AllWhois.com [allwhois.com] will do a search of all the whois databases from one interface. Quite handy.

JanCounselor

6:23 pm on May 29, 2002 (gmt 0)



Thanks, All. I've made note of these.

Jan