Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 01-23-2010, 09:11 AM   #1
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
Abusive Hits Per Day

I've been noticing some really high hits from certain ips over the last few weeks.

Mainly from Germany, Russia, and China... in 24hrs I had two ips hit 74,181 and 18,696 hits.

I've writen an app before which will block IPs based on hits in a certain timeframe, but not for adult.

What would you consider excessive hits from one IP in a 24hr period?
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 09:31 AM   #2
RayBonga
too cool for highschool
 
RayBonga's Avatar
 
Join Date: Nov 2005
Location: East side, West side, Worldwide!
Posts: 12,164
any idea why this is happening?
RayBonga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 09:32 AM   #3
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
Quote:
Originally Posted by RayBonga View Post
any idea why this is happening?
No idea... I noticed a 20mbps increase in bandwidth... I knew something was up.
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 09:49 AM   #4
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
isolate what they are hitting first.
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 10:15 AM   #5
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
At that level of hits it doesn't matter to me. If it's not a search engine spider nothing needs to hit the site near that many times.

If a valid surfer is blocked, I'll redirect blocked IPs to a friendly error page with contact info if they think they've been blocked by mistake.
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 10:19 AM   #6
EdgeXXX
Confirmed User
 
EdgeXXX's Avatar
 
Join Date: Nov 2005
Location: Secretely plotting a hostile takeover
Posts: 5,816
Normally I would say they are trying to run U:P lists against your site, but seeing as you have free registration that wouldn't make a whole lot of sense.
__________________
.
.
.
.

I have a sig
EdgeXXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 10:23 AM   #7
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
I have a lot of buffer in terms of bandwidth, so that's not a problem yet... mainly it's just wasted bw and it's slowing my page down. After speeding a few weeks on page speed that's pretty annoying :/
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 10:25 AM   #8
DateDoc
Outside looking in.
 
DateDoc's Avatar
 
Industry Role:
Join Date: Feb 2005
Location: To Hell You Ride
Posts: 14,243
If you host any of the videos on your site see which ones are being hotlinked.
__________________
DateDoc is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 10:35 AM   #9
1200mics
Confirmed User
 
1200mics's Avatar
 
Join Date: Sep 2005
Location: ICQ : 297-476-738
Posts: 5,131
Why would they do that ?
__________________
1200mics is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 10:44 AM   #10
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
Here's a few of the IPs I've noticed hammering the site the last few days:
61.145.136.114
77.88.26.27
79.203.75.91
88.64.52.20
125.85.15.25
221.174.16.60
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 12:29 PM   #11
woj
<&(©¿©)&>
 
woj's Avatar
 
Industry Role:
Join Date: Jul 2002
Location: Chicago
Posts: 47,882
like smokey said you need to figure out what they are hitting first, look in the log files..
__________________
Custom Software Development, email: woj#at#wojfun#.#com to discuss details or skype: wojl2000 or gchat: wojfun or telegram: wojl2000
Affiliate program tools: Hosted Galleries Manager Banner Manager Video Manager
Wordpress Affiliate Plugin Pic/Movie of the Day Fansign Generator Zip Manager
woj is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 01:33 PM   #12
mkx
Confirmed User
 
Industry Role:
Join Date: Nov 2003
Location: Toronto
Posts: 4,001
they are probably jacking your website content to make their own
mkx is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 03:00 PM   #13
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
Quote:
Originally Posted by woj View Post
like smokey said you need to figure out what they are hitting first, look in the log files..
Looks like web scrapers... pulling a bunch of .aspx and .html pages without any content on them.

Then all of a sudden there will be a bunch of thumbs with no page opened...
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 05:13 PM   #14
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
Wrote an app to discourage abuse and block IPs... I'm just not sure if I'm being too liberal or too strict. I guess I'll find out soon enough.

Here's a graph of where my bandwidth was spiking 15-30mbps over the last week or so:
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 05:17 PM   #15
SmellyNose
Confirmed User
 
SmellyNose's Avatar
 
Industry Role:
Join Date: Aug 2009
Location: me at smellynose.com
Posts: 206
What language? Is it a cronjob to check your access log sort of like:

Code:
cat /var/log/apache2/access.log | awk '{print $1}' | wc -l
I will be looking at implementing something similar soon so would be interested in your thoughts on your current setup.
SmellyNose is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-23-2010, 05:20 PM   #16
barelist
Confirmed User
 
barelist's Avatar
 
Join Date: Jan 2009
Location: Texas
Posts: 523
Quote:
Originally Posted by AdultStoriesNow View Post
What language? Is it a cronjob to check your access log sort of like:

Code:
cat /var/log/apache2/access.log | awk '{print $1}' | wc -l
I will be looking at implementing something similar soon so would be interested in your thoughts on your current setup.
.net

I'm grabbing low level ip hits (no client needed) over all my sites and if hits exceed a certain number over a set interval it's flagged as abuse and the app blocks the IP in IIS.

Had my wife and myself browse the site pretty heavy, but stopping like a surfer would, then figured out a number of hits to start with. I'll probably look over the blocked ips for the next week and see if I'm blocking any legit looking IPs. I'll also see how the bandwidth changes.

They are then directed to a 403 page with contact information if they feel they were blocked in error

Last edited by barelist; 01-23-2010 at 05:21 PM..
barelist is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 01-24-2010, 07:59 PM   #17
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
For Throttlebox we graphed the derivative of IP versus hits.
The knee in the graph clearly shows normal versus abusive behaviour.
Alternatively, slight less accurate is to graph to top X IPs where
X is high enough to show the knee. Here's an example of that from
Throttlebox:

https://bettercgi.com/throttlebox/ma...oosing_limits/

You see in the graph that the second highest, third highest etc. are roughly
linear with a near horizontal slope. That's indicative of normal usage. In the
case of the graph illustrated, only the #1 top user is far from being linear with
the others - that's the abusive one.

For another example, let's say the graph looked like this:

Code:
20 #
19 #
18 ##
17 ###
16 ###
15 ###
14 ####
13 ##### 
12 #####
11 #####
10 #####
9  ######
8  ######
7  ########
6  #########
5  ############
4  ##############
3  #####################################################
2  #################################################################
1  ####################################################################
In this ASCII graph, the top three are way out of line from the others, which is
indicative of abuse.

That will tell you where the cut off line should be, but that's the easy part.
There are much more difficult issues to work out before you have something
truly effective.

You have to be careful since you're working with IPv4 addresses.
You should expect that AOLs proxies and DTAGs proxies, for example, are going to
have a LOT more hits than any normal IP, on a site with a broad user base.
If the site has 12 AOL users on at different times of the same day, six of those
users may show up as the same IP.

On the other side, an cracker going through a zombie web server may use all sixteen
IPs on that server, so you really want to look at ranges of IPs as well.

I know I'm throwing a lot out there at you, but only because there are a lot of things
to consider.
We've been working on "detect and stop abuse" for a decade and half and still need
to do updates all the time in order to remain optimally effective.
__________________
For historical display only. This information is not current:
support&#64;bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.