Re: nimda, etc.

From: Date: Fri, 21 Sep 2001 23:10:58 +0000
Subject: Re: nimda, etc.
References: 1 2  Groups: php.general 
Request: Send a blank email to php-general+get-68232@lists.php.net to get a copy of this message
Are you sure about that? I am trying his script and I just had an "attack" and I watched the traffic through my firewall software. It dropped off immediately, i.e. showed no activity. I was expecting to see somekind of a persistant connection, but It doesn't seem to be there. I tested it myself and got the same results. My browser just sat there spinning, but there was no traffic in and out of my site. -- Gaylen gfraley5@earthlink.net http://www.gaylenandmargie.com PHP KISGB v1.2 Guestbook http://www.gaylenandmargie.com/publicscripts "Sean Straw / Pse" <PSE-L@mail.professional.org> wrote in message news:5.1.0.14.2.20010921142209.075637e0@mail.professional.org... > At 13:48 2001-09-21 -0700, Bill Rausch wrote: > > sleep( 300 ); > > > >I felt that if nothing else I could slow the worm down a little by > >wasting its time before it races off to the next potential target. > >Does what I'm doing make any sense or am I all confused? > > I do like the concept behind the sleep idea, but this is going to tie up > acesses to *YOUR* server, which means you're literally setting yourself up > for a DoS. I doubt that was a design goal. > > I think setting up a script which hands off the vitising IP address to your > firewall and stealths the requests would be much better. If I could get an > answer to a cache implementation question I posted here this morning, I'd > be moving along to providing such a facility to those interested... > > FTR, the implementation I have in place right now is invoked via a > rewriterule in apache, so I don't log 404 errors. > > --- > Please DO NOT carbon me on list replies. I'll get my copy from the list. > > Sean B. Straw / Professional Software Engineering > Post Box 2395 / San Rafael, CA 94912-2395 >

« previous php.general (#68232) next »