Re: IP spoof
| From: | GaryB | Date: | Thu, 17 Aug 2000 19:28:34 +0000 |
| Subject: | Re: IP spoof | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-12333@lists.php.net to get a copy of this message | ||
Craig Vincent wrote:
> > There are no browser involved, they are Hurling. They are using
> > CGI/Perl scripts that
> > generate random Ip addresses. It is a modified version of a
> > password Hurler. You can
>
> You mean they're using random proxies to connect to the script. That's why
> my suggestion of using averages to help catch crooks...I'll admit I'm sure
> there are people who get past my detections but most don't as most don't
> think of everything...and most scriptors are lazy or script kiddies.
The way they work, you have the script in your cgi-bin. You tell the
script how
often to send a click, you have a range to choose from. The script
generates a
fake ip address and the good ones generate browser type. It is all
random even the
click amounts are change every day.
The way I learned about all this was from some clients that had
the problem on their click through. The funny part, most of the people
that
write these script also write a script to stop it. They work both sides
of the
road.
Gary