squid help - increasing web security

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



   Can anyone help with this ?

   I use squid as an accelerator on my border firewall. (ie incoming to
my webserver hit the reverse squid proxy which mediates the request to
the real webserver if it is not cached).

   I have noticed that whenever the script kiddies attack/scan my
website, they always scan the website using http://[ip]

   They never use any domain name - presumably the scripts scan blocks
of ip's and so they care not a jot what domain is hosted at that ip.

   So - I believe i can avoid a large number of scans, if I can prevent
http://[ip] from ever reaching the webserver.

   As I read the squid docs, "acl dstdomain IP" may block what I want,
but may do a DNS lookup on domain for the normal traffic and then block
that too - clearly not what I want.

   So how to I contruct an acl which matches http://[ipaddress] and
which does not match http://domain, where the IP of domain is [ipaddress].

   thanks ...

-- 
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
Guidelines: http://fedoraproject.org/wiki/Communicate/MailingListGuidelines
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux