Re: Denial of webserving attack prevention!

From: Loki Harfagr (loki_at_DarkDesign.free.fr)
Date: 05/15/05


Date: Sun, 15 May 2005 18:33:51 +0200

Le Thu, 05 May 2005 06:40:12 -0700, themf a écrit :

>
>>
>> If they are running "ab" on your computer you might want to seriously
>
>> think about removing that user from your computer. If they are doing
>> malicious stuff they are obviously someone that you dont want around.
>>
>
> Er - the guy running ab is on ANOTHER computer, not mine!

That's understood :-)

And that's another reason to act at the kernel/firewall level instead of
at the server/userspace level where it can be pretty too late.

Which don't stop you of setting further user rules at the apache level,
but I think it's better to stop the possible deep attacks as soon as can
be; i-e use the advice given by Martijn :-)