Hackers and Script Kiddies - should I worry? Hackers and Script Kiddies - should I worry?
 

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Main Menu

Hackers and Script Kiddies - should I worry?

Started by wanglese, March 31, 2011, 03:28:33 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

wanglese

G'day, apologies if this isn't where I should ask.

For the last 3 months or so I've been getting this in my logs:
"•Mar 31, 2011 at 11:10 AM - Denied privileged access to register.php by user Guest at <IP Adress> "
Of course, the IP addresses vary from time to time.

Captcha is working fine, Akismet is working fine, and I have set "comments from guests" need approval by admin.
Registration also needs Admin approval.

However, every day I get between 60 to 100 entries "Captcha authentication for comment failed for user Guest <IP Address>" and about a dozen failed logins (obviously from spammers using various names). Then there are about a dozen of the above "priveleged access" messages every two days or so.

I set Akismet to "Drop comment that fails to validate, and tell author that it was rejected" instead of the option of awaiting approval to stop the emails coming to my inbox.

So should I worry, or should I go through my logs every so often and ban IP addresses (for a period of time) that keep cropping up?

Or are there other measures I need to take, or any suggestions?

Gallery Website is:
http://illawarraastronomicalsociety.hostoi.com/Coppermine/  and I'm at cpg1.5.12




Αndré

The security mechanisms seem to work. So what's your actual question?

wanglese

Yeah, I know the current security measures are working, I was wondering if there was anythng else I need to do, eg:


"Should I go through my logs every so often and ban IP addresses (for a period of time) that keep cropping up?



Also, I was surprised to see just how much of this stuff (hacking photogalleries) goes on.
I knew people tried to hack into blogs, forum boards and discussion groups, just this surprised me.

Αndré

If you'll sleep better you can ban IP addresses, but that's not necessary imo.