hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Spam attacks via web FROM google??
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Spam attacks via web FROM google??

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 08-15-2006, 10:30 AM
turnkeyinternet turnkeyinternet is offline
Corporate Member
 
Join Date: Feb 2006
Location: New York
Posts: 589

Spam attacks via web FROM google??


This morning one of our client's servers had the common 'old forum software, easy to hijack' situation exploited. Not that big a deal, our traffic monitors catch it in a minute or 2, a tech has it shut down before any real damage.

What made this morning's incident unique is the attack came from Google's webcrawler bot. This I have not seen before, usualy the ip's track back outside the US to the end user or a proxy gateway of sorts somewhere - but the attack was coming in (the attack was generating about 15,000 spam's in the mail queue within 30 minutes simply by loading forum topic web pages) simply by accessing a specific page in the forum:

The apache-status on the server showed:

66.249.65.13
name = crawl-66-249-65-13.googlebot.com.

-0 3994 0/41/41 _ 2.25 6 103 0.0 0.42 0.42 66.249.65.13 **DOMAINNAME*** GET /Forum/viewtopic.php?p=1638&sid=dbbacc1bc506cbb62e57e58292d

1-0 3995 0/26/26 _ 0.84 35 99 0.0 0.44 0.44 66.249.65.13 **DOMAINNAME*** GET /Forum/viewtopic.php?p=1961&sid=0d6e0772e2ccf8004c8da269b71

and about 8 more total of the same thing (pointing at different topic numbers) but all coming in from the same remote ip.

netstat confired the sockets, it wasn't some spoof- and tracerouts confirmed the 18 ms ping/traceroute to the datacenter at above.net where google host's this 'bot server' to crawl the net.

Now my question - has anyone seen this before? Clearly the forum must of been modified previously (hacked to send spam when certain pages get loaded). The hacker then waited some time and tricked google into loading the pages and thus generating the spam(s) - with their remote ip attached to the situation (clever).

Anyone else seen something like this before? It's a first for me - never seen a hacker care enough to try and frame someone like that - no doubt google didn't do anything here except crawl the site - but the hacker no doubt tricked google into doing it so they could remain hidden. The actual 'hack' in the logs came from a proxy server about 24 hours earlier but no spams then were triggered.

It's a first for me hopefully a last.

__________________
TurnKey Internet, Inc : phone 1.518.618.0999 and 1.877.539.4638 | Contact Us
Cloud Servers | Dedicated Servers | Colocation | VPS | Mail Services | Reseller hosting
New York / East Coast Green Datacenter

Reply With Quote


Sponsored Links
Reply

Related posts from TheWhir.com
Title Type Date Posted
Spammy Hosting Clients Won't Affect Your Site Ranking: Google Blog 2013-04-10 13:36:07
Spamhaus Blames Cyberbunker for the Largest Public DDoS Attack Ever Web Hosting News 2013-03-27 14:11:35
eleven August Email Security Report Sees Highest Spam Growth Rate in Two Years Web Hosting News 2012-08-08 13:22:20
eleven Survey Lists Spam as Greatest Email Security Threat in Ten Years Web Hosting News 2011-12-02 21:50:09
Email Security Firm eleven Expects Obselecense of Blacklist Anti-Spam Solutions Web Hosting News 2011-09-15 17:03:15


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?