PDA

View Full Version : "/w00tw00t.at.ISC.SANS.DFind:) HTTP/1.1" - how to prevent?



Fli
09-21-2013, 08:49 PM
Hello, im getting alot of requests/scans on my server and it makes the server freeze. (load 30)

87.98.*** - - [17/Jul/2013:15:20:47 +0200] "GET /w00tw00t.at.ISC.SANS.DFindhttp://www.webhostingtalk.com/images/wht_smilies/smile.gif HTTP/1.1" 400 307 "-" "-"
5.135.*** - - [17/Jul/2013:18:34:05 +0200] "GET /w00tw00t.at.ISC.SANS.DFindhttp://www.webhostingtalk.com/images/wht_smilies/smile.gif HTTP/1.1" 400 307 "-" "-"
37.59.*** - - [17/Jul/2013:19:04:05 +0200] "GET /w00tw00t.at.ISC.SANS.DFindhttp://www.webhostingtalk.com/images/wht_smilies/smile.gif HTTP/1.1" 400 307 "-" "-"
89.107.*** - - [17/Jul/2013:21:24:32 +0200] "GET /w00tw00t.at.blackhats.romanian.anti-sechttp://www.webhostingtalk.com/images/wht_smilies/smile.gif HTTP/1.1" 404 316 "-" "ZmEu"
89.107.*** - - [17/Jul/2013:21:24:32 +0200] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 303 "-" "ZmEu"
89.107.*** - - [17/Jul/2013:21:24:32 +0200] "GET /phpmyadmin/scripts/setup.php HTTP/1.1" 404 303 "-" "ZmEu"

Please how can i protect from this and make it dont take my server load? Thank you


----------------

I tried to set "PS_INTERVAL" value in COnfig Server Firewall (its for port scanning and is in seconds).

When i turn OFF demo mode of CSF, i cant access any of the websites hosted on this server, and on its VPSes.