Web Application Security
fail2ban Oct 21 2010 03:40PM
Kai Witzke (security gaark de) (6 replies)
Re: fail2ban Oct 27 2010 07:09PM
Adrian J Milanoski (amilanoski gmail com)
RE: fail2ban Oct 26 2010 03:31PM
Perry B. Whelan (perry commercev3 com) (1 replies)
Re: fail2ban Oct 27 2010 10:02PM
robert webappsec org
Re: fail2ban Oct 26 2010 07:20AM
Dale Stirling (dale puredistortion com)
Re: fail2ban Oct 26 2010 06:17AM
Rafel Ivgi (rafelivgi gmail com)
Re: fail2ban Oct 26 2010 04:09AM
Jamuse (jamuse gmail com)
On Thu, Oct 21, 2010 at 5:40 PM, Kai Witzke <security (at) gaark (dot) de [email concealed]> wrote:
> Hey everybody!
>
> I have some serious problems with flooding attacks to my apache2. No
> problems with logins oder syn floods, just a huge amount of simple
> requests to my server from the same ip. Anyone got a nice howto on that
> or maybe a nice regex prepared for counting such requests and blocking
> the greedy ones?

Hi Kai,

Take a look at ModSecurity's SecGuardianLog. You set a threshold in
httpd-guardian.pl and use blacklist to block the IP. Another native
ModSecurity option is detailed here:
https://secure.jwall.org/blog/2009/07/19/1248004300834.html

--
- Josh

This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now!
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------

[ reply ]
Re: fail2ban Oct 26 2010 01:51AM
Adrian J Milanoski (amilanoski gmail com) (1 replies)
Re: fail2ban Oct 26 2010 08:09AM
Ryan Dewhurst (ryandewhurst gmail com) (1 replies)
Re: fail2ban Oct 26 2010 11:23AM
primehaxor (primehaxor gmail com)


 

Privacy Statement
Copyright 2010, SecurityFocus