Advanced search  

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Pages: [1]   Go Down

Author Topic: Bot attacks loading server  (Read 2369 times)

0 Members and 1 Guest are viewing this topic.

whats_up_skip

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Posts: 52
Bot attacks loading server
« on: May 16, 2006, 06:21:50 am »

I am having lots of bots attacking my site unsuccessfully. They keep hitting the login.php file.

Is there any solution?

Does simply removing the link on the site to login.php fix it? I would have though the bots still know the file is there.

I am running 1.4.3. I thought that while I am upgrading I might implement some other fixes.
Logged

Joachim Müller

  • Dev Team member
  • Coppermine addict
  • ****
  • Offline Offline
  • Gender: Male
  • Posts: 47843
  • aka "GauGau"
    • gaugau.de
Re: Bot attacks loading server
« Reply #1 on: May 16, 2006, 07:05:26 am »

1) Upgrade to the most recent stable (currently cpg1.4.5) first - it's the most important security fix
2) Make sure your password is at least 8 chars long, contains upper and lower case and both letters and numbers. It mustn't be in a dictionary. Strong passwords are harder (or quite impossible) to guess - only a brute force-attack can break them, which is not a likely thing to happen.
3) Removing the login link will help, as well as renaming the file "login.php" to something random (e.g. "kjfsghdfskdf.php"), if the bots you refer to have been designed to attack coppermine installs

What kind of bots hit your login page? If they're wanted bots (like search engine spiders), you can keep them from accessing the login page by denying them access to it in robots.txt
Logged

whats_up_skip

  • Coppermine regular visitor
  • **
  • Offline Offline
  • Posts: 52
Re: Bot attacks loading server
« Reply #2 on: May 16, 2006, 07:56:01 am »

Thanks for the ideas.

I tried renaming the login.php file, but then I could not log in. Is there something more to it than that?

The password is strong as they are not breaking it. It is just the load on the server.

I have the robot.txt file set up ok and the bots are normally coming from Russia and Eastern Europe or someones machine that is infected.
Logged
Pages: [1]   Go Up
 

Page created in 0.016 seconds with 19 queries.