How to block these requests with http:// in the params?

Shri @ DevLib.Org shri at devlib.org
Tue Nov 24 09:41:04 MSK 2009


How would I go about blocking requests which try to exploit application / php flaws?

One in particular is ... of the form http://www.domain.com/search.php?searchterm=http://217.218.xxx.x/abc.php 

I'd like to block all requests which have a param that begins with http:// (searchterm in the above case).

Can this be done at a server level?

Regards,
Shri



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://nginx.org/pipermail/nginx/attachments/20091124/f6ff0e04/attachment.html>


More information about the nginx mailing list