From owner-freebsd-questions@FreeBSD.ORG Sat Mar 27 07:28:16 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7AB8616A4CE for ; Sat, 27 Mar 2004 07:28:16 -0800 (PST) Received: from franklin-belle.com (adsl-65-68-247-73.dsl.crchtx.swbell.net [65.68.247.73]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3638D43D31 for ; Sat, 27 Mar 2004 07:28:16 -0800 (PST) (envelope-from jacks@sage-american.com) Received: from sagea (sagea.sage-american [10.0.0.3]) by franklin-belle.com (8.12.8p2/8.12.8) with SMTP id i2RFSEmr091414 for ; Sat, 27 Mar 2004 09:28:15 -0600 (CST) (envelope-from jacks@sage-american.com) Message-Id: <3.0.5.32.20040327092812.01f49a10@10.0.0.15> X-Sender: jacks@10.0.0.15 X-Mailer: QUALCOMM Windows Eudora Pro Version 3.0.5 (32) Date: Sat, 27 Mar 2004 09:28:12 -0600 To: freebsd-questions@freebsd.org From: "Jack L. Stone" Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" X-Spam-Status: No, hits=0.6 required=4.5 tests=AWL,MY_OBFUX autolearn=ham version=2.63-sageame.rules_v3.1 X-Spam-Checker-Version: SpamAssassin 2.63-sageame.rules_v3.1 (2004-01-11) on franklin-belle.com Subject: Very long URL with malice intended X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 27 Mar 2004 15:28:16 -0000 Am running FBSD-4.8 with Apache/1.3.26 I posted this question first on the Apache.org list, but no reply. Thought I would try here even though slightly offtopic. Within the past couple of weeks, the Apache logs have shown a new type of intrusion -- a very, very long URL request -- that finally receives a error 414. I don't know the purpose of this one, but doesn't appear well-intended. It comes late at night and from different IPs. One request even used one of my own IPs. So, the firewall won't help -- nor server deny. My question is what syntax can I add, if any, to my httpd.conf to redirect such requests..?? Here's a very small (about 1-5%) snippet of the nasty URL: 65.35.186.74 - - [26/Mar/2004:19:01:04 -0600] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb 1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x0 2\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb 1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x0 2\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb 1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x0 2\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02 .... and on and on.... Any suggestions on a way to stop these much appreciated. Best regards, Jack L. Stone, Administrator Sage American http://www.sage-american.com jacks@sage-american.com