1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

awstats shows authenticated user "mrbean"

Discussion in 'Traffic Analysis' started by tpn87, Jun 12, 2006.

  1. #1
    While checking my awstats on one of my sites I saw two instances of authenticated users that I did not recognize. One was for mrbean and the other was just "".

    I contacted support at my hosting company and they said these are failed attempts to authenticate by people trying to brute force .htaccess protected directories. Should I have any concerns? Has anyone here at DP ever seen this?
     
    tpn87, Jun 12, 2006 IP
  2. infin8

    infin8 Peon

    Messages:
    42
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #2
    You shouldn't have to worry too much as long as your passwords are strong (numbers and leters, uppercase and lowercase.. and a special character for good measure). Most sites won't get the attention of bruteforcers, unless you got some adult sites.

    BTW Mr Bean's real name is Rowan Atkinson if it might help you catch the culprit :D
     
    infin8, Jun 12, 2006 IP
    angelfire likes this.
  3. tpn87

    tpn87 Well-Known Member

    Messages:
    522
    Likes Received:
    26
    Best Answers:
    0
    Trophy Points:
    100
    #3
    I dont have any adult sites... it's a fitness related site. I think I am going to revamp my htaccess passwords right now and make them even stronger.

    thanks for the advice infin8
     
    tpn87, Jun 12, 2006 IP
    angelfire likes this.
  4. infin8

    infin8 Peon

    Messages:
    42
    Likes Received:
    2
    Best Answers:
    0
    Trophy Points:
    0
    #4
    That's a good idea... Also, If you notice the bruteforce attempts to increase and become a problem, you can add security code that will block an IP address after a number of unsuccessful attempts. You should only have to block for a few minutes to discourage bruteforce bots. However, only having 2 unrecognized usernames, you're probably not under attack, because bots use thousands of combinations. It was most likely just one curious person typing in some random names.

    Good luck with it all, hope your site does well for you now and in the future. ;)
     
    infin8, Jun 13, 2006 IP
  5. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,333
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #5
    Your web logs will log it even if it was a page that didn't require authentication if the HTTP request sends it anyway.

    For example (depending on your browser), this would do it... http://mrbean@www.digitalpoint.com
     
    digitalpoint, Jun 13, 2006 IP
  6. hsaleem

    hsaleem Rocket!

    Messages:
    1,109
    Likes Received:
    282
    Best Answers:
    0
    Trophy Points:
    203
    #6
    I have had the same problem and someone has browsed the pages of my directory as well...

    Authenticated users : 3 Pages Hits Bandwidth Last visit sreedhar_reddy_m 6306 6306 57.77 MB 28 Jun 2007 - 11:55 "" 7 7 118.70 KB 27 Jun 2007 - 13:44 1 1 14.29 KB 04 Jun 2007 - 01:18 Other logins (and/or anonymous users) 218678 394298 2.22 GB
     
    hsaleem, Jun 28, 2007 IP
  7. d tea

    d tea Peon

    Messages:
    436
    Likes Received:
    6
    Best Answers:
    0
    Trophy Points:
    0
    #7
    I am getting this aswell. Would really to like to know where it is coming from.
     
    d tea, Dec 9, 2007 IP