Re: Nimda-A Worm/Virus threatens networks

From: Karsten W. Rohrbach (karsten@rohrbach.de)
Date: 09/18/01


Date: Tue, 18 Sep 2001 20:31:28 +0200
From: "Karsten W. Rohrbach" <karsten@rohrbach.de>
To: Jim Arnold <jim@ohio.com>


Jim Arnold(jim@ohio.com)@2001.09.18 14:21:50 +0000:
> i am running an apache server on linux. how do i stop it from gobbling
> all my bandwidth? i'm being hit by dozens of different servers.

you might configure your 404 error handler to spit out a very small
file (for example containing just one space character '%20').

mod_throttle or other bandwidth control tools will not help, since the
worm hits each server it scan with a list of several uris and that's
pretty it.

if the worm catches a 404 http error it will cease scanning this
particular system. bad, that it does not honor redirect requests ;-)

/k

-- 
> Those who make peaceful revolution impossible will make violent
> revolution inevitable.
KR433/KR11-RIPE -- WebMonster Community Founder -- nGENn GmbH Senior Techie
http://www.webmonster.de/ -- ftp://ftp.webmonster.de/ -- http://www.ngenn.net/
karsten&rohrbach.de -- alpha&ngenn.net -- alpha&scene.org -- catch@spam.de
GnuPG 0x2964BF46 2001-03-15 42F9 9FFF 50D4 2F38 DBEE  DF22 3340 4F4E 2964 BF46
Please do not remove my address from To: and Cc: fields in mailing lists. 10x

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: Nimda-A Worm/Virus threatens networks
    ... >> i am running an apache server on linux. ... i'm being hit by dozens of different servers. ... > mod_throttle or other bandwidth control tools will not help, ... that it does not honor redirect requests;-) ...
    (FreeBSD-Security)
  • Re: Nimda-A Worm/Virus threatens networks
    ... >>> i am running an apache server on linux. ... i'm being hit by dozens of different servers. ... >> mod_throttle or other bandwidth control tools will not help, ... These requests ...
    (FreeBSD-Security)
  • RE: sendmail blocking
    ... the administrator I don't receive any NDRs. ... >> mail server, and the external world that acts as a mail ... Since Nick has been receiving this junk email for a year now ... marketing mailing lists. ...
    (RedHat)
  • RE: Exchange 2003 Share SMTP Name Space between Forests
    ... The email server that is forwarding the mail to the other server is in ... Either double click the Default Policy, ... create a new SMTP address. ... Hit OK. ...
    (microsoft.public.exchange.setup)
  • Re: ISA Problem or Firewall Client issue?
    ... The server is a Dell Power Edge SBS 2003 server ... with ISA 2004 and a dual NIC configuration. ... bandwidth between my site and them. ... of users who use the network for functions other than Internet and e-mail. ...
    (microsoft.public.windows.server.sbs)

Quantcast