[Date Prev][Date Next][Thread Prev][Thread Next][Thread Index]

[fw1-gurus] http protocol level inspection and smart defense



Hello all,

NGAI on a Nokia.
A newbie smart defense question I'm afraid. We have a web site behind our firewall, we receive a lot of http "gets" like this:
http get / http/1.1
And thats all no other http headers at all, in the request.

Apparently this is a worm looking for an Apache web server, as they respond in an unsual way if they do not recieve the "host" header. We haven't had any Apache servers so I haven't worried about it to much. But now I have an Apache server so I would like to block at the firewall any http "gets" that do not have at least one other header (any header) but e.g. "host:"

Is it possible to do something like this? I know it does not conform to the http RFC but... I'm not worried about that.

Cheers Simon Chang.

_________________________________________________________________
Protect your PC - get McAfee.com VirusScan Online http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963


---------------------------------------------------------------------
FireWall-1 Gurus Mailing List (http://www.phoneboy.com/gurus)
To unsubscribe, mailto:fw1-gurus-unsubscribe@xxxxxxxxxxxxxxxxxx
For additional commands, mailto:fw1-gurus-help@xxxxxxxxxxxxxxxxxx