Re: nimda, etc.
| From: | Gaylen Fraley | Date: | Fri, 21 Sep 2001 23:10:58 +0000 |
| Subject: | Re: nimda, etc. | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-68232@lists.php.net to get a copy of this message | ||
Are you sure about that? I am trying his script and I just had an "attack"
and I watched the traffic through my firewall software. It dropped off
immediately, i.e. showed no activity. I was expecting to see somekind of a
persistant connection, but It doesn't seem to be there. I tested it myself
and got the same results. My browser just sat there spinning, but there was
no traffic in and out of my site.
--
Gaylen
gfraley5@earthlink.net
http://www.gaylenandmargie.com
PHP KISGB v1.2 Guestbook http://www.gaylenandmargie.com/publicscripts
"Sean Straw / Pse" <PSE-L@mail.professional.org> wrote in message
news:5.1.0.14.2.20010921142209.075637e0@mail.professional.org...
> At 13:48 2001-09-21 -0700, Bill Rausch wrote:
> > sleep( 300 );
> >
> >I felt that if nothing else I could slow the worm down a little by
> >wasting its time before it races off to the next potential target.
> >Does what I'm doing make any sense or am I all confused?
>
> I do like the concept behind the sleep idea, but this is going to tie up
> acesses to *YOUR* server, which means you're literally setting yourself up
> for a DoS. I doubt that was a design goal.
>
> I think setting up a script which hands off the vitising IP address to
your
> firewall and stealths the requests would be much better. If I could get
an
> answer to a cache implementation question I posted here this morning, I'd
> be moving along to providing such a facility to those interested...
>
> FTR, the implementation I have in place right now is invoked via a
> rewriterule in apache, so I don't log 404 errors.
>
> ---
> Please DO NOT carbon me on list replies. I'll get my copy from the
list.
>
> Sean B. Straw / Professional Software Engineering
> Post Box 2395 / San Rafael, CA 94912-2395
>