bballad, you're absolutely right. I was trying to say that sometimes you don't have to patch, sometimes you can protect your server just by a configuration change (urlscan does this for you but I like to stay in control and do it myself). I never really liked URLScan. It kinda screws up my logs which leaves me in the dark. As for filtering urls we use a reverse proxy for that.




Reply With Quote