|
|
|
Anyone heard of these? I hadn't, until -
A few weeks back someone tried to deface my website by posting rather lurid personal comments - totally unrelated to the website - in the guestbook. I looked at the logs but found that the access had been via an Open Proxy Server, so no chance of tracing the culprit. Ah well, I thought, never mind.
Imagine my surprise when I received an email today with a complete log of the transaction, including details of the originating IP address. Apparently the Open Proxy Server used is a "Honeypot", specifically designed to trap this sort of abuse. Triggered by certain words in the transaction the SysAdmin followed this up and emailed me via the address on my web site.
So now I know that the abuse originated from a Sky Broadband user, and I have the IP address and exact time of the transaction. Just trying to decide whether I should lodge a complaint with Sky or just forget it. Should one just accept abuse of your web site as a given?
I've just Googled "honeypot proxy" and it seems there are quite a few of these. So, before you think you can do anything naughty via a proxy - think again!
|
|
|
|
I'd report it. Imagine the look on the cowards face when they find out that they weren't so anonymous after all. More seriously, it may stop them causing someone more sensitive than you some severe torment in the future.
|
|
|
|
Got to admit that if it was a simple matter of someone posting rude comments I really wouldn't care, but when they start to get devious and use a proxy it's a different matter. Fairly harmless this time, but who knows what they might try next time or, as you say, who else they might try it with.
I'm not convinced that Sky will take much notice of a single complaint but, on the other hand, I've nothing to lose by complaining. I've certainly managed to get spammers' mail accounts suspended and software pirates investigated by Microsoft in the past, so it may be worth it.
|
|
Register (or login) on our website and you will not see this ad.
|
|
|
Personally I would report it. Don't know where you live but Essex Police have a seperate department, sounds grand but I think there are five people in it!
They are certainly very responsive when it comes to this sort of thing and have some very active and pleasant officers there.
I agree with SC, it is worth reporting, maybe not police level, that is up to you, but certainly to the ISP without a doubt.
For all you know he/she could be just practising before going after someone who would really have difficulties following an attack...... Not that it didn't cause you hassle but I think these people need to know they are NOT anonymous all the time !
Regards,
Trevor
2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.
Edited by TrevorSP (Thu 01-Oct-09 17:41:01)
|
|
|
Report them. At best they may be a clueless user with a bot installed, at worst they are a malevolent little wotsit. I thought gaining access to a system you didn't have authority on is now a criminal offence??? Somewhere in the computer misuse act I think. Assuming that it is the most up to date name. May have been superseded by a EU act probably called something much longer and more complicated
|
|
|
|
Strictly speaking not access to a system that they didn't have authority to. My guestbook is open for users to add comments if they wish (although obviously intended for comments about the web site rather than an obscene rant from someone that I have upset on one of the very few forums that I post on). The (unsuccessful) attempt to hide behind a proxy in posting such material does make it (to my mind) a possible breach of an acceptable use policy, depending upon the ISP.
|
|
|
Anyone heard of these? I hadn't, until -
A few weeks back someone tried to deface my website by posting rather lurid personal comments - totally unrelated to the website - in the guestbook. I looked at the logs but found that the access had been via an Open Proxy Server, so no chance of tracing the culprit. Ah well, I thought, never mind.
Imagine my surprise when I received an email today with a complete log of the transaction, including details of the originating IP address. Apparently the Open Proxy Server used is a "Honeypot", specifically designed to trap this sort of abuse. Triggered by certain words in the transaction the SysAdmin followed this up and emailed me via the address on my web site.
So now I know that the abuse originated from a Sky Broadband user, and I have the IP address and exact time of the transaction. Just trying to decide whether I should lodge a complaint with Sky or just forget it. Should one just accept abuse of your web site as a given?
I've just Googled "honeypot proxy" and it seems there are quite a few of these. So, before you think you can do anything naughty via a proxy - think again! Something like that it is most unlikely that an ISP will do anything about it.
Personally I wouldn't even bother wasting my time reporting it.
Plus you can't block that particular IP either - as Sky users IPs (even on LLU) are dynamic.
If it keeps happening though - then firing off details to Sky might get some action, but also very unlikley IMO.
|
|
|
|
If you reverse trace the IP, if LLU, you should see the exchange name in the last, or second to last hop.
That'll allow you to possibly see the area this person was located in.
Matt
|
|
|
|
You are quite right, an ISP wouldn't take any action - other than to make a note of the offender perhaps - over such an incident.
I was more interested in this example of "a little learning". The average surfer probably know nothing about proxy servers. The know-it-alls will know about and use open proxies, thinking that they are covering the traces. The truth is that on the Internet you never know who is looking over your shoulder.
|
|
|
If you reverse trace the IP, if LLU, you should see the exchange name in the last, or second to last hop.
That'll allow you to possibly see the area this person was located in.
Matt Yes you could but that is only of any use really on a personal level if you have suspicions as to who might have done it and that will just give you a bit more 'evidence' to confirm the suspicions.
The point is that no ISP will probably do anything about it in a case like this.
|
|
|
|
I agree.. however, the OP might know someone in that exact area (if not in their local vicinity)
Matt
|
|
|
I frequent so few forums that I have a pretty shrewd idea of where online I must have met the person concerned.
|
|
|
I frequent so few forums that I have a pretty shrewd idea of where online I must have met the person concerned. If it is just a one off he/she did out of 'red mist' then is nothing you can really do.
If they hit your site again though and they are using the same proxy or a proxy within an easily identified range and they aren't too bright then you can 'play' with them just for a giggle using .htaccess.
My favorite on some sites is just redirecting the ip to another page set to fullscreen with menubar, toolbar, scrollbars and resizable values set to 0 - then putting whatever I feel is rather annoying at the time. Things like loud sounds going 'boo' which then redirects quickly to an identical page and back again.
This can backfire as it has a tendency to somewhat annoy morons like that.
Edited by deleted (Tue 27-Oct-09 13:55:41)
|