Re: IP spoof

From: Date: Thu, 17 Aug 2000 19:28:34 +0000
Subject: Re: IP spoof
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-12333@lists.php.net to get a copy of this message
Craig Vincent wrote: > > There are no browser involved, they are Hurling. They are using > > CGI/Perl scripts that > > generate random Ip addresses. It is a modified version of a > > password Hurler. You can > > You mean they're using random proxies to connect to the script. That's why > my suggestion of using averages to help catch crooks...I'll admit I'm sure > there are people who get past my detections but most don't as most don't > think of everything...and most scriptors are lazy or script kiddies. The way they work, you have the script in your cgi-bin. You tell the script how often to send a click, you have a range to choose from. The script generates a fake ip address and the good ones generate browser type. It is all random even the click amounts are change every day. The way I learned about all this was from some clients that had the problem on their click through. The funny part, most of the people that write these script also write a script to stop it. They work both sides of the road. Gary

« previous php.general (#12333) next »