Solved

htaccess question

Posted on 2015-01-06
8
80 Views
Last Modified: 2015-01-23
Hello,

I am running a php server and keep getting thousands of requests for a .asp file that is clearly not on the server. I want to throw them off the site, it is crashing the server.

I have this as a rule in my htaccess:

RewriteCond %{THE_REQUEST} ^[A-Z]+\s([^\s]+)\.asp\s
RewriteRule .*$ http://127.0.0.1 [R=301,L]
RewriteRule ^(.*)\.asp$ http://127.0.0.1

Open in new window


but this address is still loading, I am guessing that it is because there is a variable, how can I block these too?

https://domain.com/sm_login.asp?SID=ot8klbtvok43ga6gvchl74pd56

Open in new window


Matt
0
Comment
Question by:movieprodw
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
8 Comments
 
LVL 13

Expert Comment

by:Ugo Mena
ID: 40533943
+FollowSymLinks must be enabled for any rules to work, this is a security requirement of the rewrite engine. Normally it's enabled in the root and you shouldn't have to add it, but it doesn't hurt to do so.

Options +FollowSymlinks
RewriteEngine on
RewriteRule ^(.+)\.asp$ http://redirectToThisLink.html [R,NC]

Open in new window

0
 
LVL 62

Expert Comment

by:gheist
ID: 40534063
Server crashes for other reasons.
Serving 404 errors is very lightweight action within core.

There should be some other deficiency that makes server crash.
Please filter ASP 404 from error logs and check better stuff that may crash your server.
0
 
LVL 1

Author Comment

by:movieprodw
ID: 40534074
Not if you are using magento and the 404 page is a magento loaded page.
0
Monthly Recap

May was a big month for new releases from Linux Academy! Take a look at what our team built recently in our blog. You can access the newest releases from our blog.

 
LVL 62

Expert Comment

by:gheist
ID: 40534086
Is your apache using a lot of RAM?
0
 
LVL 1

Author Comment

by:movieprodw
ID: 40534088
Ultralites,

That did not work. The URL is still loading and showing the magento 404 page.

RewriteCond %{THE_REQUEST} ^[A-Z]+\s([^\s]+)\.asp\s
RewriteRule .*$ http://127.0.0.1 [R=301,L]
RewriteRule ^(.*)\.asp$ http://127.0.0.1

Options +FollowSymlinks
RewriteEngine on
RewriteRule ^(.+)\.asp$ http://127.0.0.1 [R,NC]

Open in new window

0
 
LVL 1

Author Comment

by:movieprodw
ID: 40534097
gheist, the ram is very low but I am getting these DDoS style attacks where they are loading thousands of .asp?sid=xxxxxx urls and it is clogging up the bandwidth and using all of the ram
0
 
LVL 62

Accepted Solution

by:
gheist earned 500 total points
ID: 40534100
It is not DDOS. it is attempt to take over old ASP session (not ASPx), you are compeltely immune to the attack, though your apache configuration could wish better.
At least remove heavy 404 page provided by Magento - it serves no purpose, just does damage and grief.

Could you try to manage moving on to worker MPM and php-cgi linked with mod_fcgid? That will greatly reduce memory consumption - namely you will have small apache like with no modules, and few PHP backends of large RAM
0
 
LVL 1

Author Closing Comment

by:movieprodw
ID: 40565951
Thanks
0

Featured Post

Learn by Doing. Anytime. Anywhere.

Do you like to learn by doing?
Our labs and exercises give you the chance to do just that: Learn by performing actions on real environments.

Hands-on, scenario-based labs give you experience on real environments provided by us so you don't have to worry about breaking anything.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s 2016. Password authentication should be dead — or at least close to dying. But, unfortunately, it has not traversed Quagga stage yet. Using password authentication is like laundering hotel guest linens with a washboard — it’s Passé.
This article discusses four methods for overlaying images in a container on a web page
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question