Forum

Ban on Flooding issue

Rainer Ernst
8 August 2013, 02:13
Hi, I wrote you accidently first directly (at contact page). For any reason I oversaw the forum. I'm very sorry for that!

BTT:
My issue is about Ban of Flooding feature. It's not working for me as it should if I can trust the logfiles.

This is set in the config file:
BanOnFlooding = 6/3:10

But when I take a look in my log-file it's not working:
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET /muieblackcat HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //admin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //admin/pma/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //admin/phpmyadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //db/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //dbadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //myadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //mysql/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //mysqladmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //typo3/phpmyadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpMyAdmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpmyadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpmyadmin1/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpmyadmin2/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //pma/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //web/phpMyAdmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //xampp/phpmyadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //web/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //php-my-admin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //websql/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpmyadmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:06 +0200|404|238||GET //phpMyAdmin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //phpMyAdmin-2/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //php-my-admin/scripts/setup.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //phpMyAdmin-2.5.5/index.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //phpMyAdmin-2.5.5-pl1/index.php HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //phpMyAdmin/ HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //phpmyadmin/ HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close
85.25.152.44|Sat 27 Jul 2013 08:34:07 +0200|404|238||GET //mysqladmin/ HTTP/1.1|Accept: */*|Accept-Language: en-us|Accept-Encoding: gzip, deflate|Host: 84.118.11.44|Connection: close

There was more than 6 requests in just one second. If I try the ban feature myself (hitting F5 on a page) it works perfectly. I can actually not really reproduce the problem on my own. I tried that: When I open 10 tabs in my browser and press "reload all tabs" then it's apparently not working very well since all requests come at exactly the same moment (he loads all 10 tabs, although treshhold is at 6). If I press a second later again "reload all tabs" then he don't load all (I'm banned) but still some.

Hiawatha version: Hiawatha v9.2, cache, IPv6, reverse proxy, SSL (1.2.8), URL toolkit, XSLT
Operating System: Server 2003 SP2

Still great program! =)
Greetings from germany.
Hugo Leisink
9 August 2013, 01:08
I'll take a look at it.
This topic has been closed.