Technical Discussion
  >> Web Design / HTML / Web hosting Forum


Register (or login) on our website and you will not see this ad.


These posts have been archived and can no longer be replied to or modified.
Pages in this thread: 1 | 2 | (show all)   Print Thread
Standard User deleted
(deleted) Thu 01-Oct-09 17:02:48
Print Post

Open Proxy Honeypots


[link to this post]
 
Anyone heard of these? I hadn't, until -

A few weeks back someone tried to deface my website by posting rather lurid personal comments - totally unrelated to the website - in the guestbook. I looked at the logs but found that the access had been via an Open Proxy Server, so no chance of tracing the culprit. Ah well, I thought, never mind.

Imagine my surprise when I received an email today with a complete log of the transaction, including details of the originating IP address. Apparently the Open Proxy Server used is a "Honeypot", specifically designed to trap this sort of abuse. Triggered by certain words in the transaction the SysAdmin followed this up and emailed me via the address on my web site.

So now I know that the abuse originated from a Sky Broadband user, and I have the IP address and exact time of the transaction. Just trying to decide whether I should lodge a complaint with Sky or just forget it. Should one just accept abuse of your web site as a given?

I've just Googled "honeypot proxy" and it seems there are quite a few of these. So, before you think you can do anything naughty via a proxy - think again!
Standard User deleted
(deleted) Thu 01-Oct-09 17:22:23
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
I'd report it. Imagine the look on the cowards face when they find out that they weren't so anonymous after all. More seriously, it may stop them causing someone more sensitive than you some severe torment in the future.
Standard User deleted
(deleted) Thu 01-Oct-09 17:37:26
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
Got to admit that if it was a simple matter of someone posting rude comments I really wouldn't care, but when they start to get devious and use a proxy it's a different matter. Fairly harmless this time, but who knows what they might try next time or, as you say, who else they might try it with.

I'm not convinced that Sky will take much notice of a single complaint but, on the other hand, I've nothing to lose by complaining. I've certainly managed to get spammers' mail accounts suspended and software pirates investigated by Microsoft in the past, so it may be worth it.


Register (or login) on our website and you will not see this ad.

Standard User TrevorSP
(knowledge is power) Thu 01-Oct-09 17:40:03
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
Personally I would report it. Don't know where you live but Essex Police have a seperate department, sounds grand but I think there are five people in it!
They are certainly very responsive when it comes to this sort of thing and have some very active and pleasant officers there.

I agree with SC, it is worth reporting, maybe not police level, that is up to you, but certainly to the ISP without a doubt.

For all you know he/she could be just practising before going after someone who would really have difficulties following an attack...... Not that it didn't cause you hassle but I think these people need to know they are NOT anonymous all the time !

Regards,
Trevor

2 x F2S 8mb lines, current speeds a rock solid 6.4mbps on each one.(hiding behind DG834PN & DGN2000 routers) on: a Win7 32 (RTM) Laptop, Win7 64 (RTM) ) PC & WinVista Ultimate Laptop.

Edited by TrevorSP (Thu 01-Oct-09 17:41:01)

Standard User deleted
(deleted) Mon 05-Oct-09 17:28:37
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
Report them. At best they may be a clueless user with a bot installed, at worst they are a malevolent little wotsit. I thought gaining access to a system you didn't have authority on is now a criminal offence??? Somewhere in the computer misuse act I think. Assuming that it is the most up to date name. May have been superseded by a EU act probably called something much longer and more complicated smile
Standard User deleted
(deleted) Mon 05-Oct-09 17:36:37
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
Strictly speaking not access to a system that they didn't have authority to. My guestbook is open for users to add comments if they wish (although obviously intended for comments about the web site rather than an obscene rant from someone that I have upset on one of the very few forums that I post on). The (unsuccessful) attempt to hide behind a proxy in posting such material does make it (to my mind) a possible breach of an acceptable use policy, depending upon the ISP.
Standard User deleted
(deleted) Tue 27-Oct-09 01:44:59
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
In reply to a post by AnotherExPipex:
Anyone heard of these? I hadn't, until -

A few weeks back someone tried to deface my website by posting rather lurid personal comments - totally unrelated to the website - in the guestbook. I looked at the logs but found that the access had been via an Open Proxy Server, so no chance of tracing the culprit. Ah well, I thought, never mind.

Imagine my surprise when I received an email today with a complete log of the transaction, including details of the originating IP address. Apparently the Open Proxy Server used is a "Honeypot", specifically designed to trap this sort of abuse. Triggered by certain words in the transaction the SysAdmin followed this up and emailed me via the address on my web site.

So now I know that the abuse originated from a Sky Broadband user, and I have the IP address and exact time of the transaction. Just trying to decide whether I should lodge a complaint with Sky or just forget it. Should one just accept abuse of your web site as a given?

I've just Googled "honeypot proxy" and it seems there are quite a few of these. So, before you think you can do anything naughty via a proxy - think again!
Something like that it is most unlikely that an ISP will do anything about it.

Personally I wouldn't even bother wasting my time reporting it.

Plus you can't block that particular IP either - as Sky users IPs (even on LLU) are dynamic.

If it keeps happening though - then firing off details to Sky might get some action, but also very unlikley IMO.
Standard User deleted
(deleted) Tue 27-Oct-09 02:00:44
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
If you reverse trace the IP, if LLU, you should see the exchange name in the last, or second to last hop.

That'll allow you to possibly see the area this person was located in.

Matt
Standard User deleted
(deleted) Tue 27-Oct-09 07:19:19
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
You are quite right, an ISP wouldn't take any action - other than to make a note of the offender perhaps - over such an incident.

I was more interested in this example of "a little learning". The average surfer probably know nothing about proxy servers. The know-it-alls will know about and use open proxies, thinking that they are covering the traces. The truth is that on the Internet you never know who is looking over your shoulder.
Standard User deleted
(deleted) Tue 27-Oct-09 13:14:02
Print Post

Re: Open Proxy Honeypots


[re: deleted] [link to this post]
 
In reply to a post by xilonet:
If you reverse trace the IP, if LLU, you should see the exchange name in the last, or second to last hop.

That'll allow you to possibly see the area this person was located in.

Matt
Yes you could but that is only of any use really on a personal level if you have suspicions as to who might have done it and that will just give you a bit more 'evidence' to confirm the suspicions.

The point is that no ISP will probably do anything about it in a case like this.
Pages in this thread: 1 | 2 | (show all)   Print Thread

Jump to