Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Apr 2003
    Location
    Auckland, New Zealand
    Posts
    172

    Default mod_sec rules to drop this...

    Hi Yah,

    Apache continually dying and error logs show this over & over again...

    [error] [client 84.137.32.94] request failed: erroneous characters after protocol string: $MyNick galaxy1205|$Lock EXTENDEDPROTOCOLABCABCABCABCABCABC Pk=DCPLUSPLUS0.674ABCABC|
    [Sun Nov 12 17:24:16 2006] [error] [client 84.137.32.94] request failed: erroneous characters after protocol string: $MyNick galaxy1205|$Lock EXTENDEDPROTOCOLABCABCABCABCABCABC Pk=DCPLUSPLUS0.674ABCABC|
    [Sun Nov 12 17:24:16 2006] [error] [client 84.137.32.94] request failed: erroneous characters after protocol string: $MyNick galaxy1205|$Lock EXTENDEDPROTOCOLABCABCABCABCABCABC Pk=DCPLUSPLUS0.674ABCABC|
    [Sun Nov 12 17:24:18 2006] [error] [client 83.27.85.210] request failed: erroneous characters after protocol string: $MyNick BOSS|$Lock EXTENDEDPROTOCOLABCABCABCABCABCABC Pk=DCPLUSPLUS0.698ABCABC|
    [Sun Nov 12 17:24:18 2006] [error] [client 83.27.85.210] request failed: erroneous characters after protocol string: $MyNick BOSS|$Lock EXTENDEDPROTOCOLABCABCABCABCABCABC Pk=DCPLUSPLUS0.698ABCABC|
    [Sun Nov 12 17:24:18 2006] [error] [client 83.27.85.210] request failed: erroneous characters after protocol string: $MyNick BOSS|$Lock EXTENDEDPROTOCOLABCABCABCABCABCABC Pk=DCPLUSPLUS0.698ABCABC|

    All from different IP's etc etc. Had a search through Google for this and only one other post & nothing resolved for them. Has anyone got a mod_sec rule that would drop this ???
    Have already increased the maxclient & dropped the timeout in httpd.conf to relieve the server a bit

    Thanks in advance

    Chae

  2. #2
    Member
    Join Date
    Apr 2003
    Location
    Auckland, New Zealand
    Posts
    172

    Default

    As a follow up to typing this the techsupport from the Datacentre where the servers are housed have basically said that they can't do anything their side to help...

    "Unfortunately most networks don't implement solutions like TopLayer to prevent these kind of outbound attacks..." then they basically tell me that I can add the IP's into our firewall which of course doesn't help as they're (hundreds up hundreds) spoofed (sigh)

    So now we've got a crippled server because of these requests

  3. #3
    Member
    Join Date
    Jul 2002
    Location
    Canada
    Posts
    675

    Default

    Could you not add something like this with mod-security?

    secfilter $MyNick
    Upload Guardian 2.0 - Sign up for our early beta
    ServerProgress - Server security, consulting and assistance

  4. #4
    Member
    Join Date
    May 2005
    Posts
    99

    Default

    buddy you are under attack of botnets thats why the apache marks nicks like IRC .. coz that things are botnets hosted in one irc server to attack.

    i recomend you some thing like mod security, mod_choke and mod_ddosevasive

    i recomend you one idc with firewall like ipsecurenetwork.com or something like that .. to prevent DDoS attacks

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by west-domains View Post
    or something like that .. to prevent DDoS attacks
    If your server is under good DDoS attack, none would would stop it including APF, BFD, Mod security and Mod Evasive, or any other software-based firewall. You have to have hardware-based firewall such as Cisco Guard.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

Similar Threads & Tags
Similar threads

  1. Updated mod_sec rules
    By p0liX in forum Security
    Replies: 143
    Last Post: 10-02-2011, 07:01 AM
  2. Updated mod_sec rules
    By p0liX in forum cPanel and WHM Discussions
    Replies: 117
    Last Post: 12-14-2009, 12:30 PM
  3. mod_sec rules (where to get the best version)
    By cookiesunshinex in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 06-29-2009, 11:12 PM
  4. Can someone help with mod_sec rules and an application I am trying to run?
    By betoranaldi in forum cPanel and WHM Discussions
    Replies: 7
    Last Post: 05-15-2009, 01:06 PM
  5. Who writes and maintains the default WHM mod_sec rules?
    By Kaydiddle in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 03-02-2009, 08:54 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube