Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 02-01-2004, 11:02 PM   #1
ZoiNk
Confirmed User
 
Join Date: Feb 2002
Location: Canada
Posts: 2,370
Blocking HEAD requests in apache

Does anyone know how to block head requests and still let legit connections through. I am sure there is a way in the htaccess file, or if not, using the apache config. Anyone know? Thanks,
ZoiNk
__________________
"People can have the Model T in any color - so long as it's black." - Henry Ford
ZoiNk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-01-2004, 11:18 PM   #2
RK
Confirmed User
 
Join Date: Aug 2001
Location: In a Bunker
Posts: 868
Why would you block HEAD requests?

Are you being attacked?
__________________
Does anyone look down here?
RK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-01-2004, 11:20 PM   #3
fuzebox
making it rain
 
fuzebox's Avatar
 
Industry Role:
Join Date: Oct 2003
Location: seattle
Posts: 22,114
What are you trying to accomplish?
fuzebox is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-01-2004, 11:21 PM   #4
freeadultcontent
Confirmed User
 
Join Date: Oct 2002
Location: "evitcepsrep ruoy egnahc"
Posts: 9,976
Never turn down head.
freeadultcontent is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-01-2004, 11:30 PM   #5
ZoiNk
Confirmed User
 
Join Date: Feb 2002
Location: Canada
Posts: 2,370
A friend of mine was asking, so I thought I would try and find the answer for him.

Attackers try bruteforcing htaccess password protection, and it shows up as a HEAD request, not a get request. for the password protected area, i want to allow only GET requests. there is multiple attempts by dozens of ip addresses at the same time, so it is hard/not practical to block them or redirect stuff. the attacks come and go, but it would be easier on server resources if would just deny HEAD requests for that directory and not bother to authenicate.

ZoiNk
__________________
"People can have the Model T in any color - so long as it's black." - Henry Ford
ZoiNk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-01-2004, 11:31 PM   #6
ZoiNk
Confirmed User
 
Join Date: Feb 2002
Location: Canada
Posts: 2,370
Quote:
Originally posted by freeadultcontent
Never turn down head.
.... Except when it comes from a guy offering....

ZoiNk
__________________
"People can have the Model T in any color - so long as it's black." - Henry Ford
ZoiNk is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-01-2004, 11:50 PM   #7
RK
Confirmed User
 
Join Date: Aug 2001
Location: In a Bunker
Posts: 868
So I was right.
Use something like this, this is not PHP but the only way the board will let me post it:

PHP Code:
<Limit GET POST>
  ...
  
access restriction directives such as require or deny
  
...
</
Limit
__________________
Does anyone look down here?

Last edited by RK; 02-01-2004 at 11:53 PM..
RK is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-02-2004, 12:08 AM   #8
nuclei
old school fart
 
Industry Role:
Join Date: May 2001
Location: Florida
Posts: 1,015
drop this in a .htaccess in the directory you want to deny HEAD requests from. Then test to make sure it doesnt deny get/post. It shouldn't tho.


&lt;Limit HEAD&gt;
order deny,allow
deny from all
&lt;/Limit&gt;
__________________
The next generation of SEO
nuclei is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 02-02-2004, 12:25 AM   #9
CGI
Confirmed User
 
Join Date: Apr 2002
Location: Portland, OR
Posts: 139
&lt;LimitExcept GET POST&gt;
order deny,allow
deny from all
&lt;/LimitExcept&gt;
__________________
Komply - The 2257 record keeping & content management application (sneak preview)
Manic Cash - Tight Niches, Solid Payouts...
ICQ 346121285

Last edited by CGI; 02-02-2004 at 12:28 AM..
CGI is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.