Re: apache and nimbda

From: elliptic (elliptic@localhost.localdomain)
Date: 01/29/02


Date: Tue, 29 Jan 2002 07:13:36 -0700 (MST)
From: elliptic <elliptic@localhost.localdomain>
To: Christophe Zwecker <doc@zwecker.de>


> thinkin of that Ive got a customer with IIS server which he cannot
> change for apache, for some reason, I wonder which linux based tools
> (the firewal runs on linux) there are to block nimda. Can a proxy acting
> as a reverse proxy do it ?

The use of a secondary server would work for this purpose. One could use
the built-in proxy functions of Apache combined with a Linux machine to
insulate the IIS server from hostile network traffic.

Personally, I'd proxy all critical systems. If Apache isn't an option,
I'd also look at something like SecureIIS from EEye[1].

Cheers,
ellipse

[1] Dale Coddington is leet.



Relevant Pages

  • [UNIX] "Slapper" OpenSSL/Apache Worm Propagation
    ... The worm is a modified derivative of the Apache ... Current versions of the Slapper worm only target the following Linux ... Mod_ssl is the Apache web server interface to OpenSSL, ...
    (Securiteam)
  • Re: (Another) simple benchmark
    ... Interesting that the linux you are claiming to use would use prefork ... Apache as default, while this is the default on FreeBSD I would think ... the threaded worker would be used on a lot of linux dists, since they don't have the option to easily rebuild it. ...
    (freebsd-performance)
  • Re: [PHP] Copy Function Errors
    ... default most linux distributions do not give apache a password. ... Try testing to make sure you can ftp to the server using a normal ftp ... Subject: Copy Function Errors ...
    (php.general)
  • Re: (Another) simple benchmark
    ... In absence of anything smarter to do, I installed WBEL 3 Linux ... Apache is a well known server-grade product, ... It shouldn't behave this badly on FreeBSD. ... FreeBSD CPU time was 100% spent, with 90%-95% spent in sys time ...
    (freebsd-current)
  • Re: (Another) simple benchmark
    ... In absence of anything smarter to do, I installed WBEL 3 Linux ... Apache is a well known server-grade product, ... It shouldn't behave this badly on FreeBSD. ... FreeBSD CPU time was 100% spent, with 90%-95% spent in sys time ...
    (freebsd-performance)