Re: [EMAIL PROTECTED] Deny CONNECT & GET http requests (BIG Security Hole??)

2007-06-20 Thread Tony Anecito
Hi Guys, I am very interested in what you are talking about. Especially the CONNECT/POST discussion. I have what I believe is a spammer doing the CONNECT/POST and getting a status 200 from apache. Is this truely a php issue? Should I drop using php? Do you both agree and the apache group t

Re: [EMAIL PROTECTED] Deny CONNECT & GET http requests (BIG Security Hole??

2007-06-20 Thread Joshua Slive
On 6/20/07, Tony Anecito <[EMAIL PROTECTED]> wrote: Hi Guys, I am very interested in what you are talking about. Especially the CONNECT/POST discussion. I have what I believe is a spammer doing the CONNECT/POST and getting a status 200 from apache. Is this truely a php issue? Should I drop using

Re: [EMAIL PROTECTED] Deny CONNECT & GET http requests (BIG Security Hole??

2007-06-20 Thread Tony Anecito
Thanks Joshua you answered all my questions even the one about testing. All I got was the last message and it only referenced the php/CONNECT not the whole discussion. I will try these things immediately. The Seattle company which is trying the CONNECT/POST test is really annoying. Regar

Re: [EMAIL PROTECTED] Deny CONNECT & GET http requests (BIG Security Hole?

2007-06-20 Thread Joshua Slive
Just to put a cap on this thread, I've expanded the faq entry on this subject and transfered it to the docs wiki: http://wiki.apache.org/httpd/Logs/Proxy_Abuse Feel free to correct any errors or omissions. - The official User-To