Archive

Posts Tagged ‘WAF’

Skipfish fuzzing scanner & mod_security

February 6th, 2011 2 comments

My first skipfish test (on a local server) ended almost as soon as it was started (probably less than a minute.) My first test on a live, Internet resident server lasted about 2+ hours…   Big diff! From the Skipfish Readme:  Normal dictionary fuzzing. In this mode, every ${filename}.${extension} pair will be attempted. This mode is Continue reading →

Apache, mod_security & GEO-IP

April 27th, 2010 Comments off

I previously posted about using the mod_geoip Apache module to control web access via .htaccess files or server configuration adjustments (i.e. editing httpd.conf.)   Here we are adding the mod_security Apache module into the mix. Wait!  if we can control access via mod_geoip why do we need mod_security? The simple answer is….  you don’t need it Continue reading →

GeoIP Blocking – examples for Apache

April 19th, 2010 Comments off

The GOOD news – using the GeoIP module (mod_geoip.c.) can be quite simple.  The module provides much more than simply a relatively easy means to manage web server access – it opens up some opportunities for data mining. The BAD news – when limiting access make sure that this is what you really want/need to Continue reading →

________________________________________________
YOUR GeoIP Data | Ip: 38.107.179.221
Continent: NA | Country Code: US | Country Name: United States
Region: CA | State/Region Name: California | City: Glendora
(US only) Area Code: 626 | Postal code/Zip:
Latitude: 34.132099 | Longitude: -117.851097
Note - if using a mobile device your physical location may NOT be accurate...
________________________________________________

Georgia-USA.Com - Web Hosting for Business
____________________________________