note 60167 deleted from security.hiding by danbrown

From: Date: Tue, 28 Dec 2010 00:43:17 +0000
Subject: note 60167 deleted from security.hiding by danbrown
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-175265@lists.php.net to get a copy of this message
Note Submitter: ---- Even you hide your PHP, requests for bugy scripts still come. No matter whether you have the script on your server or not. You can make an additional step for those requests. Since the host now trying that buggy script then, in the future when a new bug arises it will be tried by that host again with a high possibility. So banning that host completey at its first attempt may be a good idea. For this, 1- Add Permanent links for those requests in your httpd.conf: RedirectMatch permanent (.*)awstats(.*)$ http://your_server/your_script.html RedirectMatch permanent (.*)xmlrpc(.*)$ http://your_server/your_script.html and add whatever you want to ban. 2- Write following code in your_script.html <? $host= $_SERVER['REMOTE_ADDR']; $dropit = "iptables -A INPUT -i eth0 -p tcp -s $host -m multiport --destination-ports 80,25,22 -j DROP"; shell_exec($dropit); exit ?> Yavuz Darendelioglu

« previous php.notes (#175265) next »