bloginfo('name');

bloginfo('description');

.htaccess zum Schutz gegen BKA Terror-Bot

Juni 19th, 2007 by Blu:RayNe

Nach des Bespitzelung dieses Blogs habe ich mal ein paar Sicherheitsvorkehrungen getroffen, um mich vor dem Missbrauch von Datenkracken zu schützen:

# Block BKA Terror-Bot
RewriteEngine on
Options +FollowSymlinks
RewriteCond %{HTTP_REFERER} bka [NC,OR]
RewriteCond %{HTTP_USER_AGENT} bka [NC,OR]
RewriteCond %{REMOTE_HOST} bka [NC,OR]
RewriteCond %{REMOTE_ADDR} 208\.69\.32\.130 [OR]
RewriteCond %{REMOTE_ADDR} 62\.156\.153\.38 [OR]
RewriteCond %{REMOTE_ADDR} 217\.7\.176\.2[4-7]
# Hier (in rot) sollte etwas von eurem Host stehen, damit ihr BKA im Seitentitel haben könnte
RewriteCond %{HTTP_REFERER} !<font color="#ff0000">evolution515</font>
RewriteRule ^.*$ http://www.google.de/search?hl=de&q=anti+terror [R=301,L]

Und für alle, die jetzt nicht wissen, was das bedeutet hier nochmal die Apache Dokumentation zu mod_rewrite.

Es wäre schön vielleicht von dem ein oder anderen noch ein paar IPs oder Netmasks für die BKA- und Europol-Server zu bekommen:

Order Allow,Deny
Deny from 72.30.0.0/255.255.0.0 # 72.30.0.0 - 72.30.255.255
Deny from 68.0.0.0/255.255.32.0 # 68.142.192.0 - 68.142.255.255
Deny from 68.0.0.0/255.255.0.0 # 68.142.192.0 - 68.142.255.255
Allow from all

  

Hier die Erweiterung der Rewrite-Rules für die gängigsten E-Mail-Harvester und Spambots:

# Block E-Mail Harvester
RewriteEngine on
ReWriteCond %{HTTP_USER_AGENT} Alexibot                [OR]
ReWriteCond %{HTTP_USER_AGENT} asterias                [OR]
ReWriteCond %{HTTP_USER_AGENT} BackDoorBot             [OR]
ReWriteCond %{HTTP_USER_AGENT} Black.Hole              [OR]
ReWriteCond %{HTTP_USER_AGENT} BlackWidow              [OR]
ReWriteCond %{HTTP_USER_AGENT} BlowFish                [OR]
ReWriteCond %{HTTP_USER_AGENT} BotALot                 [OR]
ReWriteCond %{HTTP_USER_AGENT} BuiltBotTough           [OR]
ReWriteCond %{HTTP_USER_AGENT} Bullseye                [OR]
ReWriteCond %{HTTP_USER_AGENT} BunnySlippers           [OR]
ReWriteCond %{HTTP_USER_AGENT} Cegbfeieh               [OR]
ReWriteCond %{HTTP_USER_AGENT} CheeseBot               [OR]
ReWriteCond %{HTTP_USER_AGENT} CherryPicker            [OR]
ReWriteCond %{HTTP_USER_AGENT} ChinaClaw               [OR]
ReWriteCond %{HTTP_USER_AGENT} CopyRightCheck          [OR]
ReWriteCond %{HTTP_USER_AGENT} cosmos                  [OR]
ReWriteCond %{HTTP_USER_AGENT} Crescent                [OR]
ReWriteCond %{HTTP_USER_AGENT} Custo                   [OR]
ReWriteCond %{HTTP_USER_AGENT} DISCo                   [OR]
ReWriteCond %{HTTP_USER_AGENT} DittoSpyder             [OR]
ReWriteCond %{HTTP_USER_AGENT} Download\ Demon         [OR]
ReWriteCond %{HTTP_USER_AGENT} eCatch                  [OR]
ReWriteCond %{HTTP_USER_AGENT} EirGrabber              [OR]
ReWriteCond %{HTTP_USER_AGENT} EmailCollector          [OR]
ReWriteCond %{HTTP_USER_AGENT} EmailSiphon             [OR]
ReWriteCond %{HTTP_USER_AGENT} EmailWolf               [OR]
ReWriteCond %{HTTP_USER_AGENT} EroCrawler              [OR]
ReWriteCond %{HTTP_USER_AGENT} Express\ WebPictures    [OR]
ReWriteCond %{HTTP_USER_AGENT} ExtractorPro            [OR]
ReWriteCond %{HTTP_USER_AGENT} EyeNetIE                [OR]
ReWriteCond %{HTTP_USER_AGENT} FlashGet                [OR]
ReWriteCond %{HTTP_USER_AGENT} Foobot                  [OR]
ReWriteCond %{HTTP_USER_AGENT} FrontPage               [NC,OR]
ReWriteCond %{HTTP_USER_AGENT} GetRight                [OR]
ReWriteCond %{HTTP_USER_AGENT} GetWeb!                 [OR]
ReWriteCond %{HTTP_USER_AGENT} Go-Ahead-Got-It         [OR]
ReWriteCond %{HTTP_USER_AGENT} Googlebot-Image         [OR]
ReWriteCond %{HTTP_USER_AGENT} Go!Zilla                [OR]
ReWriteCond %{HTTP_USER_AGENT} GrabNet                 [OR]
ReWriteCond %{HTTP_USER_AGENT} Grafula                 [OR]
ReWriteCond %{HTTP_USER_AGENT} Harvest                 [OR]
ReWriteCond %{HTTP_USER_AGENT} hloader                 [OR]
ReWriteCond %{HTTP_USER_AGENT} HMView                  [OR]
ReWriteCond %{HTTP_USER_AGENT} httplib                 [OR]
ReWriteCond %{HTTP_USER_AGENT} HTTrack                 [NC,OR]
ReWriteCond %{HTTP_USER_AGENT} humanlinks              [OR]
ReWriteCond %{HTTP_USER_AGENT} ia_archiver             [OR]
ReWriteCond %{HTTP_USER_AGENT} Image\ Stripper         [OR]
ReWriteCond %{HTTP_USER_AGENT} Image\ Sucker           [OR]
ReWriteCond %{HTTP_USER_AGENT} Indy\ Library           [NC,OR]
ReWriteCond %{HTTP_USER_AGENT} InfoNaviRobot           [OR]
ReWriteCond %{HTTP_USER_AGENT} InterGET                [OR]
ReWriteCond %{HTTP_USER_AGENT} Internet\ Ninja         [OR]
ReWriteCond %{HTTP_USER_AGENT} JennyBot                [OR]
ReWriteCond %{HTTP_USER_AGENT} JetCar                  [OR]
ReWriteCond %{HTTP_USER_AGENT} JOC\ Web\ Spider        [OR]
ReWriteCond %{HTTP_USER_AGENT} Kenjin.Spider           [OR]
ReWriteCond %{HTTP_USER_AGENT} Keyword.Density         [OR]
ReWriteCond %{HTTP_USER_AGENT} larbin                  [OR]
ReWriteCond %{HTTP_USER_AGENT} LeechFTP                [OR]
ReWriteCond %{HTTP_USER_AGENT} LexiBot                 [OR]
ReWriteCond %{HTTP_USER_AGENT} libWeb/clsHTTP          [OR]
ReWriteCond %{HTTP_USER_AGENT} LinkextractorPro        [OR]
ReWriteCond %{HTTP_USER_AGENT} LinkScan/8.1a.Unix      [OR]
ReWriteCond %{HTTP_USER_AGENT} LinkWalker              [OR]
ReWriteCond %{HTTP_USER_AGENT} lwp-trivial             [OR]
ReWriteCond %{HTTP_USER_AGENT} Mass\ Downloader        [OR]
ReWriteCond %{HTTP_USER_AGENT} Mata.Hari               [OR]
ReWriteCond %{HTTP_USER_AGENT} Microsoft.URL           [OR]
ReWriteCond %{HTTP_USER_AGENT} MIDown\ tool            [OR]
ReWriteCond %{HTTP_USER_AGENT} MIIxpc                  [OR]
ReWriteCond %{HTTP_USER_AGENT} Mister.PiX              [OR]
ReWriteCond %{HTTP_USER_AGENT} Mister\ PiX             [OR]
ReWriteCond %{HTTP_USER_AGENT} moget                   [OR]
ReWriteCond %{HTTP_USER_AGENT} Mozilla/2               [OR]
ReWriteCond %{HTTP_USER_AGENT} Mozilla/3.Mozilla/2.01  [OR]
ReWriteCond %{HTTP_USER_AGENT} Mozilla.*NEWT           [OR]
ReWriteCond %{HTTP_USER_AGENT} Navroad                 [OR]
ReWriteCond %{HTTP_USER_AGENT} NearSite                [OR]
ReWriteCond %{HTTP_USER_AGENT} NetAnts                 [OR]
ReWriteCond %{HTTP_USER_AGENT} NetMechanic             [OR]
ReWriteCond %{HTTP_USER_AGENT} NetSpider               [OR]
ReWriteCond %{HTTP_USER_AGENT} Net\ Vampire            [OR]
ReWriteCond %{HTTP_USER_AGENT} NetZIP                  [OR]
ReWriteCond %{HTTP_USER_AGENT} NICErsPRO               [OR]
ReWriteCond %{HTTP_USER_AGENT} NPBot                   [OR]
ReWriteCond %{HTTP_USER_AGENT} Octopus                 [OR]
ReWriteCond %{HTTP_USER_AGENT} Offline.Explorer        [OR]
ReWriteCond %{HTTP_USER_AGENT} Offline\ Explorer       [OR]
ReWriteCond %{HTTP_USER_AGENT} Offline\ Navigator      [OR]
ReWriteCond %{HTTP_USER_AGENT} Openfind                [OR]
ReWriteCond %{HTTP_USER_AGENT} PageGrabber             [OR]
ReWriteCond %{HTTP_USER_AGENT} Papa\ Foto              [OR]
ReWriteCond %{HTTP_USER_AGENT} pavuk                   [OR]
ReWriteCond %{HTTP_USER_AGENT} pcBrowser               [OR]
ReWriteCond %{HTTP_USER_AGENT} ProPowerBot/2.14        [OR]
ReWriteCond %{HTTP_USER_AGENT} ProWebWalker            [OR]
ReWriteCond %{HTTP_USER_AGENT} ProWebWalker            [OR]
ReWriteCond %{HTTP_USER_AGENT} QueryN.Metasearch       [OR]
ReWriteCond %{HTTP_USER_AGENT} ReGet                   [OR]
ReWriteCond %{HTTP_USER_AGENT} RepoMonkey              [OR]
ReWriteCond %{HTTP_USER_AGENT} RMA                     [OR]
ReWriteCond %{HTTP_USER_AGENT} SiteSnagger             [OR]
ReWriteCond %{HTTP_USER_AGENT} SlySearch               [OR]
ReWriteCond %{HTTP_USER_AGENT} SmartDownload           [OR]
ReWriteCond %{HTTP_USER_AGENT} SpankBot                [OR]
ReWriteCond %{HTTP_USER_AGENT} spanner                 [OR]
ReWriteCond %{HTTP_USER_AGENT} SuperBot                [OR]
ReWriteCond %{HTTP_USER_AGENT} SuperHTTP               [OR]
ReWriteCond %{HTTP_USER_AGENT} Surfbot                 [OR]
ReWriteCond %{HTTP_USER_AGENT} suzuran                 [OR]
ReWriteCond %{HTTP_USER_AGENT} Szukacz/1.4             [OR]
ReWriteCond %{HTTP_USER_AGENT} tAkeOut                 [OR]
ReWriteCond %{HTTP_USER_AGENT} Teleport                [OR]
ReWriteCond %{HTTP_USER_AGENT} Teleport\ Pro           [OR]
ReWriteCond %{HTTP_USER_AGENT} Telesoft                [OR]
ReWriteCond %{HTTP_USER_AGENT} The.Intraformant        [OR]
ReWriteCond %{HTTP_USER_AGENT} TheNomad                [OR]
ReWriteCond %{HTTP_USER_AGENT} TightTwatBot            [OR]
ReWriteCond %{HTTP_USER_AGENT} Titan                   [OR]
ReWriteCond %{HTTP_USER_AGENT} toCrawl/UrlDispatcher   [OR]
ReWriteCond %{HTTP_USER_AGENT} toCrawl/UrlDispatcher   [OR]
ReWriteCond %{HTTP_USER_AGENT} True_Robot              [OR]
ReWriteCond %{HTTP_USER_AGENT} turingos                [OR]
ReWriteCond %{HTTP_USER_AGENT} TurnitinBot/1.5         [OR]
ReWriteCond %{HTTP_USER_AGENT} URLy.Warning            [OR]
ReWriteCond %{HTTP_USER_AGENT} VCI                     [OR]
ReWriteCond %{HTTP_USER_AGENT} VoidEYE                 [OR]
ReWriteCond %{HTTP_USER_AGENT} WebAuto                 [OR]
ReWriteCond %{HTTP_USER_AGENT} WebBandit               [OR]
ReWriteCond %{HTTP_USER_AGENT} WebCopier               [OR]
ReWriteCond %{HTTP_USER_AGENT} WebEMailExtrac.*        [OR]
ReWriteCond %{HTTP_USER_AGENT} WebEnhancer             [OR]
ReWriteCond %{HTTP_USER_AGENT} WebFetch                [OR]
ReWriteCond %{HTTP_USER_AGENT} WebGo\ IS               [OR]
ReWriteCond %{HTTP_USER_AGENT} Web.Image.Collector     [OR]
ReWriteCond %{HTTP_USER_AGENT} Web\ Image\ Collector   [OR]
ReWriteCond %{HTTP_USER_AGENT} WebLeacher              [OR]
ReWriteCond %{HTTP_USER_AGENT} WebmasterWorldForumBot  [OR]
ReWriteCond %{HTTP_USER_AGENT} WebReaper               [OR]
ReWriteCond %{HTTP_USER_AGENT} WebSauger               [OR]
ReWriteCond %{HTTP_USER_AGENT} Website\ eXtractor      [OR]
ReWriteCond %{HTTP_USER_AGENT} Website.Quester         [OR]
ReWriteCond %{HTTP_USER_AGENT} Website\ Quester        [OR]
ReWriteCond %{HTTP_USER_AGENT} Webster.Pro             [OR]
ReWriteCond %{HTTP_USER_AGENT} WebStripper             [OR]
ReWriteCond %{HTTP_USER_AGENT} Web\ Sucker             [OR]
ReWriteCond %{HTTP_USER_AGENT} WebWhacker              [OR]
ReWriteCond %{HTTP_USER_AGENT} WebZip                  [OR]
ReWriteCond %{HTTP_USER_AGENT} Wget                    [OR]
ReWriteCond %{HTTP_USER_AGENT} Widow                   [OR]
ReWriteCond %{HTTP_USER_AGENT} [Ww]eb[Bb]andit         [OR]
ReWriteCond %{HTTP_USER_AGENT} WWW-Collector-E         [OR]
ReWriteCond %{HTTP_USER_AGENT} WWWOFFLE                [OR]
ReWriteCond %{HTTP_USER_AGENT} Xaldon\ WebSpider       [OR]
ReWriteCond %{HTTP_USER_AGENT} Spam                    [NC,OR]
ReWriteCond %{HTTP_USER_AGENT} Xenu’s [OR]
ReWriteCond %{HTTP_USER_AGENT} Zeus
RewriteRule ^.*$ http://www.google.de/search?hl=de&q=spam[L]

 

Filed under Allgemein, Security having

2 Responses

  1. Blu:RayNe says:

    Was den BKA Referrer angeht, mag es Schwachsinn und von ein paar Idioten sein. Aber hey, die Sicherheitsmaßnahmen unserer Politiker sind deutlicher idiotischer, denn Sicherheit bringen Sie keine, aber Überwachung stattdessen!

  2. Martin Kliehm says:

    Das BKA wird mit Sicherheit anonyme Router wie Tor verwenden, darum ist diese Maßnahme etwas kindisch… ;)

Leave a Comment

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.