• Follow us on Twitter @buckeyeplanet and @bp_recruiting, like us on Facebook! Enjoy a post or article, recommend it to others! BP is only as strong as its community, and we only promote by word of mouth, so share away!
  • Consider registering! Fewer and higher quality ads, no emails you don't want, access to all the forums, download game torrents, private messages, polls, Sportsbook, etc. Even if you just want to lurk, there are a lot of good reasons to register!
FUN! :yow1:

That's going to be hugely helpful, OC.

I bought the list, here:

2div38k.com
80211support.com
Accesoriosdecoches.com
Addisonphotog.com
Adrenalineadv.com
Alcora.com
Alicanterural.com
Alklein.com
Allenstjohn.com
Alterations-plus.com
Annaunsonprice.com
Arielway.com
Arquitectodeinformacion.com
Arspublica.org
Artpilipinas.com
Atelierduvent.com
Audever.com
Avusturalyalilar.com
Balearesrural.com
Baytlothan.org
Bcdockanddeck.com
Beadsnpieces.com
Biglars.net
Booandco.com
Bphomeowners.com
Bufetesdeabogados.com
Burgan-family.com
Businesstactics.net
Cablehogar.com
Cafeads.com
Californialocalconservationcorps.org
Camsysco.com
Canariass.com
Carlucimillinery.com
Carnetpuntos.com
Carolcochran.com
Chariotconstruction.com
Charlton-hayes.info
Charltonhayes.info
Charternautico.com
Chesapeakeindustrial.com
Cibernetia.com
Classyandsassyboutique.com
Clothencounters.com
Cocoabutterlove.com
Cocogelato.com
Comedytopcop.com
Consolasvideojuegos.com
Consolavideojuego.com
Court1.net
Cta1.com
Cursoenfermeria.com
Dannyoberti.com
Darrencall.us
Davidsteinmetz.com
Davidsteinmetz.net
Davidsteinmetz.org
Dbspainting.com
Dbsxmediainc.com
Deherdesign.com
Designwiz.com
Dickandhyman.com
Disenyoarts.net
Disenyoarts.org
Dodgeandassociates.com
Dokulan.net
Donnajones.net
Drdphotoimage.com
Drrchomes.com
Dunhemfamily.com
Duvent.com
Ecodigerati.com
Elmedi.net
Enerjuicer.com
Enfermera.org
Enfermeria.org
Exoframing.com
Experienceveritas.org
Factorydirectdesign.com
Fayasel.net
Felipecuevas.com
Ffxicooking.com
Fieldthorn.com
Filnari.org
Finest-florida-homes.com
Firebirdv6.com
Fireflyestates.com
Floridafishandgamefinder.com
Frederickepistola.com
Freehits2000.com
Freespeechbooks.com
Furnimaxx.com
Geebz.com
Gitano.com
Goldanddiamondbyoberti.com
Goldanddiamondoberti.com
Goldndiamondbyoberti.com
Goldndiamondoberti.com
Gommeren.org
Gourmetproduct.org
Granitefallsprcarodeo.com
Graphicsministry.com
Guiadeciudades.com
Hamptongardens-ph.com
Hayden-engineers.com
Helpdesk-ins.com
Hess-art.com
Hillcroftcrescentfarm.com
Hitindustry.com
Holcomblake.com
Hubareahackers.com
Huelvarural.com
Ielro.com
Ikhealing.org
Indigenousrightswatch.org
Internalprojections.com
Inverdominio.com
Inverdominios.com
Iriaflavia.net
Isaydavidsecasanporfin.com
It-ins.com
Jameskatz.com
Janinadizon.com
Jleyewear.com
Joncarver.com
Juldizon.com
Julesblainedavis.com
Karinmanske.com
Kylejeromethompson.com
Labelconcept.com
Lagayvolleyball.com
Lastwest.com
Lastwestentertainment.com
Lauralengthorn.com
Lesdivas.com
Lincolndental.net
Linkachurch.com
Liquorboxes.com
Lotusapartments.com
Luiscorbete.com
Lynnyarringtondesign.com
Macomanila.com
Maderatratadagallega.com
Mail-ins.com
Mansonimages.com
Marialuisahomes.com
Marialuisaproperties.com
Marlenemarionseft.com
Mdb.com
Mdbcapital.com
Mediapixnz.com
Medictia.com
Medrepairs.com
Micahsjewel.com
Mickwood.com
Microcrest.com
Midtowngallery.com
Mikesneatstuff.com
Mililanibuckeye.net
Millionpoundvision.org
Mimitchi.com
Mistycleaning.com
Mistycleaningservices.com
Modentdental.com
Modentdentallab.com
Modentinc.com
Modentlaboratory.com
Montecilloandassociates.com
Mopdah.com
Mvnz.org
Mws-playofcolors2007.com
Mysteries.net
Naccocapital.com
Naccogroup.com
Nelsonclan.net
Neweraprint.com
Nonnyjames.com
Norwalksigns.com
Notheydo.com
Notnuke.com
Obertieyewear.com
Obertisunglasses.com
Obol.org
Ocpanteras.com
Otakus-asturianos.com
Oxyoldegirls.com
Pablofa.com
Palberti.com
Pcconsultor.com
Pe-marketing.com
Pendlevale.net
Pendlevale.org
Perceptions-uk.com
Petsintheweb.com
Plataforma-asp.com
Pottymagic.com
Prowebnow.com
Qualitive.com
Ranchopalomar.com
Raulcarrasco.com
Raulcarrascochicago.com
Recambiosycajas.com
Reflectionz.org
Reservass.com
Reuther-net.com
Ripcity.net
Santiagofelip.com
Schererjardin.com
Scihair.com
Scottsyankeefarmer.net
Semillaestelar.com
Seoulunionchurch.org
Shutterbudds.com
Skinnybonesonair.com
Solvisual.com
Sootheursoul.com
Soultherapy.net
Soundinglight.com
Southwoodpharm.com
Spanishqualityproperties.org
Sstargroup.com
Sstarside.com
Stannesbaptist.org
Stannesfishrestaurant.com
Sterlingviewhomes.com
Suddendemos.com
Suddendesigns.com
Sunamber.com
Sunsetprogramming.com
Sunvalleycomputing.com
Support-ins.com
Sushibarguild.com
Tabarca.org
Tcgsupport.com
Tcgsystems.com
Techjud.com
Tekkenforce.net
Tempotrade.com
The-phyrst.com
Thelastwest.com
Thermusmechanical.com
Threestarinvestments.com
Tiaraattheabbey.com
Tivotool.com
Trevidam.com
Uksquashonline.com
Unite4youth.org
Viajeamsterdam.com
Viajeitalia.com
Viajelondres.com
Viajepraga.com
Viajeroma.com
Victoriacusi.com
Villani-addison.com
Vinaroz.com
Visionpacific.com
Vocablog.com
Volakas.com
Wakeforge.org
Wanrevenue.com
Web4cu.com
Webhostbranding.com
Wireless-ins.com
Woodlandhouse.net
Xn--azalia-eva.com
Xn--jvea-5na.org
Xn--pornogrficas-ibb.com
Xn--tahit-3sa.com
Yogacenter.net
Yourgreatoutdoor.com
Yourorra.org
Youthwithoutbarriers.org
Zeebracomercial.com
Lauralengthorn-massaro.com
Kriptia.com
 
Upvote 0
Above and beyond, OCB. Many thanks. I'm downloading all of our physical files to my local machine now, intending to search each of them. I'll also try and balance the list you gave against what's in our linkback records.

I'd love to know what triggered this.

Would also love to know who the hell is at the following IP, they'd make the list for Vick's new and improved Bad Newz Sleazebag-fighting league.

Sep 13 01:54:00 labounty sshd[11838]: Invalid user ed from 60.28.206.110
Sep 13 01:54:03 labounty sshd[11840]: Invalid user ed from 60.28.206.110
Sep 13 01:54:06 labounty sshd[11842]: Invalid user game from 60.28.206.110
Sep 13 01:54:09 labounty sshd[11844]: Invalid user cvs from 60.28.206.110
Sep 13 01:54:11 labounty sshd[11846]: Invalid user cvs from 60.28.206.110
Sep 13 01:54:14 labounty sshd[11848]: Invalid user upload from 60.28.206.110
Sep 13 01:54:17 labounty sshd[11850]: Invalid user upload from 60.28.206.110
Sep 13 01:54:19 labounty sshd[11852]: Invalid user benahmed from 60.28.206.110
Sep 13 01:54:22 labounty sshd[11854]: Invalid user benahmed from 60.28.206.110
Sep 13 01:54:25 labounty sshd[11856]: Invalid user rachafi from 60.28.206.110
Sep 13 01:54:27 labounty sshd[11858]: Invalid user rachafi from 60.28.206.110
Sep 13 01:54:30 labounty sshd[11860]: Invalid user ramamurthy from 60.28.206.110
Sep 13 01:54:33 labounty sshd[11862]: Invalid user ramamurthy from 60.28.206.110

That goes on and on for like three days. They'll never be successful, I'm a stickler about ridiculous account names and passwords (I think the one for root is 63 characters long, for example) -- but if it's the thought that counts, then they have a shiv and garbage can lid with their name written on it.
 
Upvote 0
No worries, really. A day where only one person tries to break in seems to be a relatively slow one -- and this one is particularly uncreative with what seems to be a good old fashioned brute force type of effort.

So A for malicious intent, F for execution, and D- for potential.

Still, if you find anything good about them, like a name and address, we can mail that info off to Michael.
 
Upvote 0
Okay, we're fixed.

First and foremost, I would have been at this much much much longer without the efforts of Deety and OCBucksFan. So take a sec, and send them some greenies, a kind PM -- or if you're OCBW, perhaps something more involved (like a pat on the back or something).

Secondly, this was not the direct result of a malicious attack. There are a variety of reasons it seemed to be. For one, the site we were connecting to is a documented spam pit. As demonstrated by the multitude of domains OCB rattled off above, it has both legitimate users (mili) and illegitimate users. BP is constantly under a sort of low-threat-level attack. Indeed, as I type this, some mooch is trying password after password against known logins, trying to get into the machine. Normal stuff. We're regularly scanned and searched for known security holes -- in the OS, in the software behind the site, in other pieces of software that run on the machine, in vBulletin, and even in the modifications we run on vB. I try to stay on top of all of that as best I can, but as demonstrated by the redirect fun we had last year, the tools sometimes get the word before the good guys do.

The problem itself was caused by a single line of code, that existed only as a single cell in the database. The code itself was something I created, months ago, to be called whenever a flag I'd place in one or more of our templates was identified as a PHP script was run. Which is to say, I'd put this flag in a template, and when one of us would load the page with that template, this code would run.

Thing is, the template it was going to go into was never active, and the flag itself, never used. So clearly, something somewhere isn't working properly. It remains to be seen if this is a problem with the core vBulletin code, or if it's related to a properly functioning modification, or an improperly functioning or otherwise compromised mod (such as the plaza).

So, as I said in another post, "I found the culprit, and he is me." At least in the sense that I wrote the code.

I believe the actual slowdown only started once the poor site on the other end actually firewalled against us. That caused time outs, the time outs bogged PHP down since nothing over here said "well hell, this isn't working, I should just stop, at least for a while," and the bog boggled me.

The "what" has been answered. The line of code. Now set ablaze, stomped upon, verbally abused, and otherwise maligned.

The "why" and/or "how" remains a bit of a puzzle, but I'll continue to poke around there as possible. I do feel confident the horrific load times won't return (at least not as a result of the same series of problems). Even if the potential is still there somewhere, the 'tool' it used (that code) is dead.

Again, thanks to Deety and OCB.

Finally, I blame NOTREDAMECHIEF for all of this -- add to that the Steve Erkel look and GAWDDDD! Not for any good reason -- just because it's good to have someone to point towards when rousing rabbles. With his 0-3 touchdown-less start to the season, he's probably in too deep a peach margarita-induced stupor to care.
 
Last edited:
Upvote 0
Back
Top