Re: myriads of access to unknown pages on my server bring my server down (DOS?)

Re: myriads of access to unknown pages on my server bring my server down (DOS?)

am 10.03.2010 15:27:46 von pilsl

>
> You might be accidentally running Apache as a forward proxy. Do you
> have 'ProxyRequests On' in your configuration?
>

oh my god. You were right. I ran a open proxy for weeks now.

I turned this option on when I was trying to make a stubborn ReverseProxy working and never turned it off. So I seems fortunate that the leak was only widely discovered this morning.

I turned the option off now and things are getting back to normal. Number of apache-processes is reducing below 100 and the logs show me that there are still many strange requests but they are all answered with 404 and hopefully systemload will return to its normal high soon :)

Looking forward to be listed in dozens of blacklists for spamming the next week. Stupid me. Should have been more careful.


THNX A LOT !!
peter

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org