SAIX Proxies being banned...

kbman

New Member
Joined
Feb 7, 2006
Messages
2
Reaction score
0
Hi,

I've been going through a terrible experience the last couple of weeks, where some US ISP's are banning 198.54.202.210.

There seems to be alot of hacker/script kiddie attacks going on lately, and they just ban these IP's resulting in gateway timeouts when you try to access their sites.

This is really worrying, because you can actually bring down the whole South-African internet just by writing a virus that hacks US ISP's from South Africa.

Is there alternatives for DSL that possibly makes use of UUNET for their international traffic or does every DSL service end up running via SAIX ?

I've got a server (which I setup as a proxy) on the UUNET network, and the speed via this server to the US is amazing - I get the full 512 speed benefit for local access + then 2Meg from the server to the US (and this is during the day)

Thanks
Kbman
 
I get this constantly - and it annoys the hell out of me. AFAIK, ip checkers can distinguish between the original user and the proxy - for example, dynalias.com will recognise your own ip - not that of the proxy.

So, in fairness, it is the site owner that is at fault for not checking the IP correctly.

Still p1sses me off though.

(
dnsstuff.org used to do this
gamespot.com had this problem last time I checked as well
)
 
You've got a webserver, and suddenly according to the logs you're being hammered by 198.54.202.210. There is no way for you as the webhost to find out who exactly on that IP is hammering you. Services like Dynalias works because it can query your machine directly to find the IP. The webhost doesn't have that luxury and the weblogs only show the proxied traffic.

http://www.whatismyip.com/ for instance gives the proxy address. I couldn't get dynalias to work, but I think you have to log into DynDns to get it to work.

Next thing is: On ADSL we work with dynamic IP's, so if a site bans your current actual IP, you disconnect, wait 5 min and reconnect again - Brand new IP for you to cause distruction.
 
kbman said:
the weblogs only show the proxied traffic.
You should configure apache to log the X-Forwarded-For header. something like:
Code:
LogFormat "%h %{X-Forwarded-For}i %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
 
kbman said:
Next thing is: On ADSL we work with dynamic IP's, so if a site bans your current actual IP, you disconnect, wait 5 min and reconnect again - Brand new IP for you to cause distruction.

yup, thats usually why they do it!
 
Moederloos said:
I plan to find one good thing to say about the T boys this year - so far, no luck.
)

Have you seen how snazzy the inside of those Telkom bakkies are Moederloos? Complete office with chair, workshop and all. Feel proud that you contributed to such an outsanding setup. :)
 
Top
Sign up to the MyBroadband newsletter
X