Path: csiph.com!usenet.pasdenom.info!weretis.net!feeder4.news.weretis.net!storethat.news.telefonica.de!telefonica.de!news-1.dfn.de!news.dfn.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Sandman Newsgroups: comp.os.linux.networking,comp.os.linux.security,comp.infosystems.www.servers.unix Subject: wpad.dat attack on Linux Apache server Date: Fri, 24 May 2013 11:22:15 +0200 Lines: 88 Message-ID: Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit X-Trace: individual.net DL8Pzwu8OiUlXPPg/O/+hAERdB0pQCJO0wqaiiaHBu+3lhlRI= X-Orig-Path: mr Cancel-Lock: sha1:w0R0cX271XPzZvQ8/Hlh9Xtz2t0= User-Agent: MT-NewsWatcher/3.5.2 (Intel Mac OS X) X-Face: $@,Vfa$,)%=Qa7L]y)&oZj_\EiHc}}Af0Bei"4a_%)"c6TQ+P/:53>;PNGuWUmkqyeN-qM65foJ[;T_(k;>]&G\T4Lhm:2 ujye2_,iUJFE;NZn>y;.|-hl7g~bIOF1qG\o CNAME -> cluster.mydomain.com -> A -> 123.123.123.123 Which means that every visitor to my sites has their web browser first look up www.client.com to find cluster.mydomain.com which in turn points to my IP. No, the mydomain.com had a wildcard setting, so if and when they would access "wpad.mydomain.com" my DNS would point that to cluster.mydomain.com and then that wold point to the IP. So supposedly, all the request could channel to my server this way. I have now removed wildcard for mydomain.com, and also added a wpad host for all my domains that points to 127.0.0.1. I'm waiting to see that propagate and see if it makes any difference. It hasn't so far. Do any of you guys have any ideas what this might be? Or rather - how do I trouble shoot this some more? I have: Slow transfer speeds on apache Super fast on other ports (SFTP for instance) Thousands of requests per minute that are now being blocked Super low CPU usage Super low RAM usage No reported ethernet errors -- Sandman[.net]