Web Hosting Forum | Lunarpages


*
Welcome, Guest. Please login or register.
Did you miss your activation email?



Login with username, password and session length
May 25, 2012, 11:05:08 AM

Pages: [1]   Go Down
  Print  
Author Topic: automatically ban ip for searches with special characters  (Read 679 times)
durangod
Galactic Royalty
*****
Offline Offline

Posts: 203


« on: June 12, 2011, 05:35:18 PM »

Hi i have been being hit pretty bad for over a month now, every day someone tries to hack my stuff using special url searches to try to inject or run an install someplace.  They have yet to get in but still i want to try something.

It is such a pain every day to add the deny ip to the list. So what i am wondering is there a way to automatically deny any ip that does a search url that containts a "+" or the word "script" on the server side.

could a php script do this and update the htaccess every day?   But im thinking thats pretty dangerious.

When someone does these searchs i would rather see the message "denied by configuration" then i would "file does not exist in my error log" so atleast i feel better. at least if i see denied by configuration i know i stopped them for sure.
Logged
Malin Cenusa
Support
Pong! (the videogame) Master
*****
Offline Offline

Posts: 21


WWW
« Reply #1 on: June 18, 2011, 03:15:18 PM »

in order to accomplish this you`d need to hardcode your search.php and have it insert deny rules inside .htaccess whenever a certain search is performed.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: