Re: internal dummy connection again

2007-03-18 Thread Paul Querna
Jeff Trawick wrote: On 3/16/07, Karl Chen <[EMAIL PROTECTED]> wrote: > On 2007-03-05 13:24 PST, Joe Orton writes: Joe> On Mon, Mar 05, 2007 at 09:33:56PM +0100, Ruediger Pluem wrote: >> On 03/03/2007 05:47 AM, Karl Chen wrote: present. Also >> other issues like noise in the log

Re: internal dummy connection again

2007-03-17 Thread Karl Chen
> On 2007-03-17 11:19 PDT, William A Jr Rowe writes: William> Karl - you can pretty easily toggle requests with William> mod_log_custom and either mod_setenvif or mod_rewrite William> to not appear in the log, I'll leave that as an William> exercise to the reader (or efficient

Re: internal dummy connection again

2007-03-17 Thread William A. Rowe, Jr.
Karl Chen wrote: > > What about the NOOP idea? If the connection could be reliably > detected to be coming from [EMAIL PROTECTED], would there still be > a risk of an attack going unnoticed? > > It seems reasonable to elide those messages by default, or at > least write them to a different log f

Re: internal dummy connection again

2007-03-17 Thread Jeff Trawick
On 3/16/07, Karl Chen <[EMAIL PROTECTED]> wrote: > On 2007-03-05 13:24 PST, Joe Orton writes: Joe> On Mon, Mar 05, 2007 at 09:33:56PM +0100, Ruediger Pluem wrote: >> On 03/03/2007 05:47 AM, Karl Chen wrote: present. Also >> other issues like noise in the log file. I've also see

Re: internal dummy connection again

2007-03-17 Thread Karl Chen
> On 2007-03-05 13:24 PST, Joe Orton writes: Joe> On Mon, Mar 05, 2007 at 09:33:56PM +0100, Ruediger Pluem wrote: >> On 03/03/2007 05:47 AM, Karl Chen wrote: present. Also >> other issues like noise in the log file. I've also seen >> people complaining that "GET /" might incu

Re: internal dummy connection again

2007-03-05 Thread Joe Orton
On Mon, Mar 05, 2007 at 09:33:56PM +0100, Ruediger Pluem wrote: > On 03/03/2007 05:47 AM, Karl Chen wrote: > > present. Also other issues like noise in the log file. I've also > > seen people complaining that "GET /" might incur the cost of > > dynamic content generation for /. > > Hm. Just thin

Re: internal dummy connection again

2007-03-05 Thread William A. Rowe, Jr.
William A. Rowe, Jr. wrote: > Ruediger Pluem wrote: >> On 03/03/2007 05:47 AM, Karl Chen wrote: >> >>> present. Also other issues like noise in the log file. I've also >>> seen people complaining that "GET /" might incur the cost of >>> dynamic content generation for /. >> Hm. Just thinking loud.

Re: internal dummy connection again

2007-03-05 Thread William A. Rowe, Jr.
Ruediger Pluem wrote: > > On 03/03/2007 05:47 AM, Karl Chen wrote: > >> present. Also other issues like noise in the log file. I've also >> seen people complaining that "GET /" might incur the cost of >> dynamic content generation for /. > > Hm. Just thinking loud. Can we avoid this if we repl

Re: internal dummy connection again

2007-03-05 Thread Ruediger Pluem
On 03/03/2007 05:47 AM, Karl Chen wrote: > present. Also other issues like noise in the log file. I've also > seen people complaining that "GET /" might incur the cost of > dynamic content generation for /. Hm. Just thinking loud. Can we avoid this if we replace GET / with OPTIONS /? > > Wo

Re: internal dummy connection again

2007-03-05 Thread Paul Querna
Karl Chen wrote: > Would it be possible to connect to a non-SSL port, if possible, so > at least the string "internal dummy connection" shows up? > > Even better would be to not show that string at all. When I > connect to httpd and close the connection without sending > anything, Not sendi