i've also had a thought, I also implemented the following:LimitRequestLine 4000Which is about half of the default size i beleive, could this be limiting the impact on my servers and thus not making them vulnerable.Does anyone know what length of request the killapache script sends?cheersSteve