note 60167 deleted from security.hiding by danbrown
| From: | danbrown@php.net | Date: | Tue, 28 Dec 2010 00:43:17 +0000 |
| Subject: | note 60167 deleted from security.hiding by danbrown | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-175265@lists.php.net to get a copy of this message | ||
Note Submitter:
----
Even you hide your PHP, requests for bugy scripts still come.
No matter whether you have the script on your server or not.
You can make an additional step for those requests. Since the host now trying that buggy script
then, in the future when a new bug arises it will be tried by that host again with a high
possibility. So banning that host completey at its first attempt may be a good idea. For this,
1- Add Permanent links for those requests in your httpd.conf:
RedirectMatch permanent (.*)awstats(.*)$ http://your_server/your_script.html
RedirectMatch permanent (.*)xmlrpc(.*)$ http://your_server/your_script.html
and add whatever you want to ban.
2- Write following code in your_script.html
<?
$host= $_SERVER['REMOTE_ADDR'];
$dropit = "iptables -A INPUT -i eth0 -p tcp -s $host -m multiport --destination-ports 80,25,22
-j DROP";
shell_exec($dropit);
exit
?>
Yavuz Darendelioglu