iEntry 10th Anniversary Forum Rules Search
WebProWorld
Register FAQ Calendar Mark Forums Read
Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

Share Thread: & Tags

Share Thread:

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-30-2004, 04:22 PM
minstrel's Avatar
WebProWorld 1,000+ Club
 
Join Date: Jul 2003
Location: Ottawa, Canada
Posts: 2,554
minstrel RepRank 2minstrel RepRank 2
Default New variants of Santy worm hitting forums

WPW may be one of the victims:

Quote:
In total there are 461 users online :: 6 Registered, 2 Hidden and 453 Guests
[ Administrator ] [ Moderator ]
Most users ever online was 549 on Thu Dec 30, 2004 9:51 AM
There are reports at phpbb.com of new variants that don't contain "lwp*" in the user-agent string. Many forums used that method of blocking the worms in .htaccess but that's no longer going to work, evidently.

Methods that look for telltale sequences in the GET string so far still seem to work.
Reply With Quote
  #2 (permalink)  
Old 12-30-2004, 04:27 PM
mike's Avatar
Administrator
 
Join Date: Jun 2003
Location: In the back, off the side and far away
Posts: 1,615
mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11
Default

Yep, he's pounding away... but he can't get in. We're the little piggies in the brick house.
__________________
WebProNews Videos
Reply With Quote
  #3 (permalink)  
Old 12-30-2004, 04:34 PM
minstrel's Avatar
WebProWorld 1,000+ Club
 
Join Date: Jul 2003
Location: Ottawa, Canada
Posts: 2,554
minstrel RepRank 2minstrel RepRank 2
Default

Yes but forums not on larger dedicated servers may not be as resilient.

Would you object if I just moved my forums to your server? I could promise you a site-wide text link to sweeten the deal... ;o)
Reply With Quote
  #4 (permalink)  
Old 12-30-2004, 04:48 PM
mike's Avatar
Administrator
 
Join Date: Jun 2003
Location: In the back, off the side and far away
Posts: 1,615
mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11
Default

The current config on this forum could handle 50 times what santy is throwing at me before I'd even bat an eye (2 weeks ago would have been another story).


Huff and puff away santy.

Incidentally, I have tried a few of the currently circulating 'fixes' for santy.

Some were working for a while but unfortunately he seems to be changing his game quite rapidly and is starting to bleed through the workarounds.

I wish I had some words of wisdom for those of you impacted negatively by santy, but I couldn't stop him either...

Fortunately for WebProWorld our new configuration just lets us take his best shot with little/no impact to our services (to this point -- knocking on wood).
__________________
WebProNews Videos
Reply With Quote
  #5 (permalink)  
Old 12-30-2004, 04:52 PM
minstrel's Avatar
WebProWorld 1,000+ Club
 
Join Date: Jul 2003
Location: Ottawa, Canada
Posts: 2,554
minstrel RepRank 2minstrel RepRank 2
Default

So (I'm just double checking here)...

You're saying no to moving my forums?
Reply With Quote
  #6 (permalink)  
Old 12-30-2004, 05:05 PM
mike's Avatar
Administrator
 
Join Date: Jun 2003
Location: In the back, off the side and far away
Posts: 1,615
mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11mike RepRank 11
Default

Sorry, but no, I can't swing that.
__________________
WebProNews Videos
Reply With Quote
  #7 (permalink)  
Old 12-30-2004, 05:13 PM
minstrel's Avatar
WebProWorld 1,000+ Club
 
Join Date: Jul 2003
Location: Ottawa, Canada
Posts: 2,554
minstrel RepRank 2minstrel RepRank 2
Default

DANG!
Reply With Quote
  #8 (permalink)  
Old 12-30-2004, 08:44 PM
WebProWorld 1,000+ Club
 
Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 1,527
mikmik RepRank 2mikmik RepRank 2
Default

I just read about the new stonehaven dual opteron 250. It can handle 16,700 requests per second.

Hey, Mike, how about a wee loan? I'll link to you on the main page, using your image as the link :O)
Reply With Quote
  #9 (permalink)  
Old 12-31-2004, 12:30 AM
Deep13's Avatar
WebProWorld Veteran
 
Join Date: Dec 2003
Location: India
Posts: 304
Deep13 RepRank 0
Default

this santy is creating major problems for the servers around...

currently also i see around 400 visitors online

Quote:
In total there are 407 users online :: 6 Registered, 1 Hidden and 400 Guests
but as mike said server is capable to this load then it shouldnt be a problem but the thing is people will have to find proper solution for this...

Deep
Reply With Quote
  #10 (permalink)  
Old 01-04-2005, 03:44 AM
WebProWorld Member
 
Join Date: Mar 2004
Location: Bangkok Thailand
Posts: 44
DannyS RepRank 0
Default

The worm started requesting pages from us on Christmas Day. We were shut down for almost 24 hours on the 26th. of December for going over our bandwidth limit. We couldn't even buy more bandwidth until the host's billing department showed on Monday morning and we aren't even a board, we have an Oscommerce cart! We tried banning IPs but couldn't keep up, (we even managed to ban our own shared ssl server which took a week to figure out;-(

What we did that helped was add mod_rewrite rules that returned a 403 error page to worm requests instead of the whole page requested. This saved bandwidth. Afterwards the techs at Jumpline.com did something upstream of us which has blocked them totally, but I don't know what they did. I’m guessing it was some rules added to the firewall.

Danny
__________________
DannyS
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -4. The time now is 11:09 AM.



Search Engine Optimization by vBSEO 3.3.0