Forum Moderators: open

Message Too Old, No Replies

Maroc Telecom

         

w3bmastine

6:50 am on May 18, 2016 (gmt 0)

10+ Year Member




System: The following message was cut out of thread at: https://www.webmasterworld.com/search_engine_spiders/4784479.htm [webmasterworld.com] by keyplyr - 11:45 pm on May 17, 2016 (UTC -8)


Host: Maroc Telecom SA
NetRange: 41.140.0.0 - 41.143.255.255
CIDR: 41.140.0.0/14

Multiple Wordpress hacking attempts.

keyplyr

7:59 am on May 18, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



@w3bmastine - Maroc Telecom is the main telecommunication company in Morocco (an ISP.) It is not a Server Farm so I moved your post here to its own thread.

Likely the hits came from an infected account.

w3bmastine

4:43 pm on May 18, 2016 (gmt 0)

10+ Year Member



I understand. How can I differentiate between ISP and Server Farm? Do you have any advice?

lucy24

6:46 pm on May 18, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



How can I differentiate between ISP and Server Farm?

Look them up individually. But if the name involves "Telecom" it's pretty safe to assume it's an ISP of some sort ;)

I assume Morocco is yet another of those places where a lot of people use pirated system software, so they're exceptionally prone to infection. There just don't happen to be as many computer users in Morocco as in, say, Ukraine.

Conversely, there's a short list of words that practically never show up except in the names of server farms: "rack" is the first one that comes to mind. And of course descriptors such as "server", "host", "colocation". If the IP lives in North America, a contact address involving "hostmaster" is another dead giveaway, but in other parts of the world this term may be used generically, so it doesn't necessarily mean anything.

aristotle

7:39 pm on May 18, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Small hosting companies are another place where you find this

keyplyr

8:53 pm on May 18, 2016 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Multiple Wordpress hacking attempts
As mentioned in other threads, most often these hits come from infected user accounts at ISPs. A user, just like you or I, gets their account infected with a virus by opening an infected email, visiting an infected web site or downloading an infected file. The virus (script) then uses that account to send out probes to see what web sites are vulnerable to infect or spam or hack in some way.

Sometimes these hits do come from infected servers at hosting companies, colocation services, data centers, VPN, Cloud Computing (e.g. Server Farms.)

In either case, the infection is usually detected within a few days and fixed. It helps to send the admins (abuse@example.com) a report of the activity by including a raw log snippet, your domain name and the IP address of your server. Too many of us don't report it. Holding the server admins accountable is the best way to affect change.

Since these infected sources are almost always temporary, rather than block the IP range, it is more effective to block the behavior. If you do use Word Press, make sure to quickly install the security updates when they become available. If you do not use WP, just block the request for these files and live with the 403s. I get several hundred every day.

w3bmastine

10:01 pm on May 18, 2016 (gmt 0)

10+ Year Member



Thanks for your advice everyone.