The joys of mod_security

I installed mod_security on here last night after getting so much referer spam to my CGI's that it was killing my machine. I set it up and then used the MT-Blacklist to mod_security script to put all the domains in my blacklist on the blocking list. Well, just overnight it blocked 100s of requests to my system, which means 100s of times that CGI scripts were not run. Yay!

DOS Block

Just saw a couple of announcements abou ta new version of the Apache DoS Evasive Maneuvers Module coming out. This is definitely something I want to check out. Basically rejects requests when it senses a DOS. This could be a very nice thing to have both on a large scale server as well as a home server (much easier to take out a little DSL link). This and adding in some things to block all the stupid script kiddie IIS attacks are on my list of things to do.


