[113738] in North American Network Operators' Group
Re: Malicious code just found on web server
daemon@ATHENA.MIT.EDU (Gadi Evron)
Mon Apr 20 14:05:32 2009
Date: Mon, 20 Apr 2009 21:03:36 +0300
From: Gadi Evron <ge@linuxbox.org>
To: Ingo Flaschberger <if@xip.at>
In-Reply-To: <alpine.LFD.1.10.0904201959520.3868@filebunker.xip.at>
Cc: "nanog@nanog.org" <nanog@nanog.org>
Errors-To: nanog-bounces@nanog.org
Ingo Flaschberger wrote:
> Hi,
>
> I see this every day at my webservers with a lot of *outdated*
> *exploitable* customer websites [I love old joomla's];
> but mod_security does a great job nuking sql and various other exploits.
mod_security saves our collective behinds every day at nearly every very
big Internet service provider I know of, and definitely hosting operations.
Mostly I like tweaking with it to see patterns of people who try to mess
with me, rather than use most of the usual rules it has.
Gadi.