Hackers and Script Kiddies - should I worry? Hackers and Script Kiddies - should I worry?
 

News:

cpg1.5.48 Security release - upgrade mandatory!
The Coppermine development team is releasing a security update for Coppermine in order to counter a recently discovered vulnerability. It is important that all users who run version cpg1.5.46 or older update to this latest version as soon as possible.
[more]

Main Menu

Hackers and Script Kiddies - should I worry?

Started by wanglese, March 31, 2011, 03:28:33 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

wanglese

G'day, apologies if this isn't where I should ask.

For the last 3 months or so I've been getting this in my logs:
"•Mar 31, 2011 at 11:10 AM - Denied privileged access to register.php by user Guest at <IP Adress> "
Of course, the IP addresses vary from time to time.

Captcha is working fine, Akismet is working fine, and I have set "comments from guests" need approval by admin.
Registration also needs Admin approval.

However, every day I get between 60 to 100 entries "Captcha authentication for comment failed for user Guest <IP Address>" and about a dozen failed logins (obviously from spammers using various names). Then there are about a dozen of the above "priveleged access" messages every two days or so.

I set Akismet to "Drop comment that fails to validate, and tell author that it was rejected" instead of the option of awaiting approval to stop the emails coming to my inbox.

So should I worry, or should I go through my logs every so often and ban IP addresses (for a period of time) that keep cropping up?

Or are there other measures I need to take, or any suggestions?

Gallery Website is:
http://illawarraastronomicalsociety.hostoi.com/Coppermine/  and I'm at cpg1.5.12




Αndré

The security mechanisms seem to work. So what's your actual question?

wanglese

Yeah, I know the current security measures are working, I was wondering if there was anythng else I need to do, eg:


"Should I go through my logs every so often and ban IP addresses (for a period of time) that keep cropping up?



Also, I was surprised to see just how much of this stuff (hacking photogalleries) goes on.
I knew people tried to hack into blogs, forum boards and discussion groups, just this surprised me.

Αndré

If you'll sleep better you can ban IP addresses, but that's not necessary imo.