web server attack
Robert Huff
roberthuff at rcn.com
Fri Apr 7 19:11:23 UTC 2006
Frank Laszlo writes:
> >> Does anyone know what this is and what I can do to stop it
> >> besides adding the ip address to my firewall block rules?
> >
> > I suppose that someone is trying to exploit mod_proxy to connect to an
> > SMTP server (that's the "CONNECT 4.79.181.15:25" part), or at least
> > get HTTP replies back.
>
> Setup mod_security to block that type of request. Any chance you
> can capture some packets and send a link? I'd like to take a look
> at it.
Running apache-2.2, I don't seem to have _security among the
modules. Do I need to change my config (and rebuild), or does it
perhaps go by another name in this version?
Robert Huff
More information about the freebsd-questions
mailing list