General Discussions

Security Alert! – Tallbill

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
For those of you who run websites (and actually pay attention to your log files ), there are a whole bunch of sites claiming to be the MJ12 Bot (Majestic-12 is a group trying to built the world's largest distributed search engine), but who are not what they claim to be. I don't have the web address with me at work, but when I get home, I can update this to link to the site where they maintain an incomplete list of such fake IPs as well as giving you a rundown of how to uncover these fakes. For example, if it claims to be version 1.08 it is a fake.

Again, I will update as soon as I am able.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”

Briant

Member

Posts: 742
From: Stony Plain, Alberta, Canada
Registered: 01-20-2001
But what's the security concern? Why does it matter?

------------------
Brian

"OOP programmers have a lot of class"

Check out this webhost! Fantastic prices, features and support!

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
Here is the page with all the information, including a link to a blog entry on another site that tells how to use apache to block the fake bots.

As to what the security concern is, if they are masquerading under someone else’s ID, surely you don’t think they are trying to do good, do you? Think of all the havoc they could be reeking. If you use your site (as I do) to provide content for download, they could be grabbing your legit stuff, infecting it deliberately, then re-offering the infected versions themselves, with one result being that your reputation takes the hit, to say nothing of all of the damage done to others by the infected files. This is just one example of the harm they could do—your only defense being to keep them out in the first place.

I call that a major security concern.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
QUICK UPDATE:

The linked-in solution provided through Majestic-12 does not seem to work on my server, but causes an internal server error. I tried it in my htaccess file. As soon as I tried to view my page with their solution in place, I could not access my web site. As soon as I commented the solution out, my web site returned.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”

Briant

Member

Posts: 742
From: Stony Plain, Alberta, Canada
Registered: 01-20-2001
quote:
Originally posted by Tallbill:
As to what the security concern is, if they are masquerading under someone else’s ID, surely you don’t think they are trying to do good, do you? Think of all the havoc they could be reeking. If you use your site (as I do) to provide content for download, they could be grabbing your legit stuff, infecting it deliberately, then re-offering the infected versions themselves, with one result being that your reputation takes the hit, to say nothing of all of the damage done to others by the infected files. This is just one example of the harm they could do—your only defense being to keep them out in the first place.

Sorry, but I really don't get it. I have several websites with lots of downloadable content. Sure, people can download and infect/alter/whatever all they want, but they can't make their altered versions available from *my* websites - they'd have to put them on their own websites somewhere. And this can happen bot or no bot. The only way to prevent this from happening is to not have any content or even a website in the first place.

Don't worry about it. You'll sleep better.

------------------
Brian

"OOP programmers have a lot of class"

Check out this webhost! Fantastic prices, features and support!

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
As Christians we are to be good stewards of what He has granted us. How is your advice in this a mark of good stewardship? I will prevent what I can prevent, and of all the people here—some of whom run websites, and perhaps even own providers—some of them know how to prevent it.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”

Briant

Member

Posts: 742
From: Stony Plain, Alberta, Canada
Registered: 01-20-2001
quote:
Originally posted by Tallbill:
As Christians we are to be good stewards of what He has granted us. How is your advice in this a mark of good stewardship?

Easy - time is one of the things we're to be good stewards of.

quote:

I will prevent what I can prevent

But again, why does it matter? What are you really accomplishing?

------------------
Brian

"OOP programmers have a lot of class"

Check out this webhost! Fantastic prices, features and support!

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
Do you want Christians to be known as spammers?

Because if you do nothing to stop such a thing, that is what their victims will think: they will think they are being spammed by Christians. And what does that do to the reputation of Christ? Some things you need to spend time on.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”

Briant

Member

Posts: 742
From: Stony Plain, Alberta, Canada
Registered: 01-20-2001
Ah, I think I get it - preventing bots means reducing the chances of your email address being scraped of your pages for the spammers to use. Yes, that's a good reason, thanks.

------------------
Brian

"OOP programmers have a lot of class"

Check out this webhost! Fantastic prices, features and support!

buddboy

Member

Posts: 2220
From: New Albany, Indiana, U.S.
Registered: 10-08-2004
I don't think that's what he means. I think he's still on the whole software thing.

BrianT I agree, how is someone going to masquerade your program as theirs when it won't be on your website, and they don't need to pretend to be Majestic-12 to do so. If someone is stealing your stuff, you could just put a note in that says if you didn't download it at your website, then it isn't real so don't use it. And apparently the fix can cause problems.

------------------
that post was really cool ^
|
[|=D) <---|| me

CPUFreak91

Member

Posts: 2337
From:
Registered: 02-01-2005
It doesn't sound like a threat to me. MJ12 Bot sounds just as "bad" as Google Bot. They're spiders. They crawl the web and find everything they can get their hands on to index it and store it in a database. If spammers are pretending to be MJ12 bot, block their IPs. It's no big deal

------------------
All Your Base Are Belong To Us!!! chown -r us ./base
"After three days without programming, life becomes meaningless.'' -- Tao of Programming Book 2

"Oh, bother," said the Borg. "We've assimilated Pooh."

Any fool can know, the point is to understand. -- Albert Einstein

My Programming and Hacker/Geek related Blog

jestermax

Member

Posts: 1064
From: Ontario, Canada
Registered: 06-21-2006
With Google's bot though you can use the robot file to thwart it off. I'll admit i don't know much about spiders, but I'm guessing other bots aren't so accommodating.

------------------
Visit my portfolio (and check out my projects):
www.JestermaxStudios.com

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
Any legitimate bot will obey the robots.txt file. That includes the real MJ12 Bot. On the other hand, anyone who is trying to hide behind a false ID is doing so for a reason, and that reason ain't good (if you recall John 3, those who are doing good come into the light so that it can be seen that what they do is of God; but those who do evil will not come into the light for fear that their evil deeds will be revealed). So, those doing good do not hide. This means that those who hide are not doing good.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”

spade89

Member

Posts: 561
From: houston,tx
Registered: 11-28-2006
hey bill aren't you taking it a bit too far??i mean maybe what the so called "spammers" did was wrong but i don't see how it is a security alert?? are they the only ones that do this??
it's not like they are trying to hack your server or penetrate any form of security you have put place.

------------------
John 14:6

Jesus answered, "I am the way and the truth and the life. No one comes to the Father except through me.

jestermax

Member

Posts: 1064
From: Ontario, Canada
Registered: 06-21-2006
quote:
Originally posted by Tallbill:
So, those doing good do not hide. This means that those who hide are not doing good.

Maybe I'm misunderstanding something, but that's somewhat of a strong statement that I think is being mistakenly supported by scripture...
I am however open to discussion on that.

------------------
Visit my portfolio (and check out my projects):
www.JestermaxStudios.com

TallBill

Member

Posts: 298
From: St. Louis, MO
Registered: 11-22-2002
Don't take it beyond the context of the events that are the subject of this thread, and think about it some more.

------------------
Never Forget to Pray!

“...prayer itself is an art which only the Holy Ghost can teach us. He is the giver of all prayer. Pray for prayer—pray till you can pray; pray to be helped to pray, and give not up praying because you cannot pray, for it is when you think you cannot pray that you are most praying. Sometimes when you have no sort of comfort in your supplications, it is then that your heart—all broken and cast down—is really wrestling and truly prevailing with the Most High.”
Charles Haddon Spurgeon, from the pamphlet, “Effective Prayer”