banner

[Rule] Rules  [Home] Main Forum  [Portal] Portal  
[Members] Member Listing  [Statistics] Statistics  [Search] Search  [Reading Room] Reading Room 
[Register] Register  
[Login] Loginhttp  | https  ]
 
Forum Index Thảo luận hệ điều hành Windows Hỏi về: DELETE / HTTP/1.1.....  XML
  [Question]   Hỏi về: DELETE / HTTP/1.1..... 28/04/2008 04:50:37 (+0700) | #1 | 127868
[Avatar]
pham.channhan
Member

[Minus]    0    [Plus]
Joined: 30/12/2007 23:28:22
Messages: 81
Location: Nhàcủamìnhtới
Offline
[Profile] [PM] [Yahoo!]
Em request cái này đến host.
Code:
DELETE / HTTP/1.1
Connection: Keep-Alive
Host: xyz.byethost13.com
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT)
Accept:*/*
 

Kết quả là nguyên cái host của em(xyz.byethost13.com) Sạch trơn!
Nhưng HVA hay Google thì khác, kết quả trả về:
HTTP/1.1 400 Bad Request
Date: Sun, 27 Apr 2008 08:46:24 GMT
Content-Type: text/html; charset=UTF-8
Server: GFE/1.3
Content-Length: 3567
Connection: Keep-Alive


<html><head>
<meta http-equiv="content-type" content="text/html;charset=utf-8">
<title>400 Bad Request</title>
<style><!--
body {font-family: arial,sans-serif}
div.nav {margin-top: 1ex}
div.nav A {font-size: 10pt; font-family: arial,sans-serif}
span.nav {font-size: 10pt; font-family: arial,sans-serif; font-weight: bold}
div.nav A,span.big {font-size: 12pt; color: #0000cc}
div.nav A {font-size: 10pt; color: black}
A.l:link {color: #6f6f6f}
A.u:link {color: green}
//--></style>
<script><!--
var rc=400;
//-->
</script>
</head>
<body text=#000000 bgcolor=#ffffff>
<table border=0 cellpadding=2 cellspacing=0 width=100%><tr><td rowspan=3 width=1% nowrap>
<b><font face=times color=#0039b6 size=10>G</font><font face=times color=#c41200 size=10>o</font><font face=times color=#f3c518 size=10>o</font><font face=times color=#0039b6 size=10>g</font><font face=times color=#30a72f size=10>l</font><font face=times color=#c41200 size=10>e</font>  </b>
<td> </td></tr>
<tr><td bgcolor=#3366cc><font face=arial,sans-serif color=#ffffff><b>Error</b></td></tr>
<tr><td> </td></tr></table>
<blockquote>
<H1>Bad Request</H1>
Your client has issued a malformed or illegal request.
<BR><BR>Please see Google's Terms of Service posted at http://www.google.com/terms_of_service.html
<BR><BR><P>We have encountered an error while processing your request. If you would like to provide us with information about this error, please <A HREF="http://www.google.com/support/bin/request.py?contact_type=user&hl=en">report</A> your problem. In your email, please send us the <b>entire</b> code displayed below. Please also send us any information you may know about how you are performing your Google searches-- for example, "I'm using the Opera browser on Linux to do searches from home. My Internet access is through a dial-up account I have with the FooCorp ISP." or "I'm using the Konqueror browser on Linux to search from my job at myFoo.com. My machine's IP address is 10.20.30.40, but all of myFoo's web traffic goes through some kind of proxy server whose IP address is 10.11.12.13." (If you don't know any information like this, that's OK. But this kind of information can help us track down problems, so please tell us what you can.)</P><P>We will use all this information to diagnose the problem, and we'll hopefully have you back up and searching with Google again quickly!</P>
<P>Please note that although we read all the email we receive, we are not always able to send a personal response to each and every email. So don't despair if you don't hear back from us!</P>
<P>Also note that if you do not send us the <b>entire</b> code below, <i>we will not be able to help you</i>.</P><P>Best wishes,<BR>The Google Team</BR></P><BLOCKQUOTE>/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/<BR>
KJfj_F-CqpJ1u3JyhsBkz21oWwfcY2bxQw4uibNcPdcRFxfai<BR>
aiytj8khk9AjB_ZWX0GirjdbM9CPdnaoDYI-m7cEEoF4RJFQd<BR>
XxdmeAmZSqV__ypofHiuPdmBR2JFQ-6OEEjgcvPwxGSMgR-CQ<BR>
lrsggDmxsYK7u1H0fXmKUH2hruN82Zs9NchEm2pmW60is0Ucq<BR>
ijoQXTBPLh1-wcw-a1xvhdGEkOx_YYAK2Fgokfrd8KbmhAMsg<BR>
RliPuorLcsMTWSxoNrjvAg579-VyWBNociMoE9H_kyzwFWCZz<BR>
-sztN-fTgdqARz1fUj8j-VpSfMmjoYX1MD1MCyTNiaywFv57O<BR>
8SuSnq5m3jm4vIqGLs-owndjzH6R-EIk00rdSTNUABcBEaYdZ<BR>
fPGyX5JYineq-vCXJ_qPg1ZEyAYBVgssaJaqSibV7khohBnsU<BR>
VRVZqALwIe2lD6pddd_si5dbwedfB0ZBk1YVndw54ecOw==<BR>
+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+/+<BR></BLOCKQUOTE>

<p>
</blockquote>
<table width=100% cellpadding=0 cellspacing=0><tr><td bgcolor=#3366cc><img alt="" width=1 height=4></td></tr></table>
</body></html>
 


hay

HTTP/1.1 405 Method Not Allowed
Date: Sun, 27 Apr 2008 08:47:36 GMT
Server: Spartan ver 0.1
Accept-Ranges: bytes
Vary: Accept-Encoding,User-Agent
Transfer-Encoding: chunked
Content-Type: text/html; charset=UTF-8
Connection: Keep-Alive

86a
<HTML>
<HEAD>
<TITLE>::: H V A : F o r u m - error 405 :::</TITLE>
<style type="text/css">
<!--
BODY {
font-family : Verdana, Geneva, Arial, Helvetica;
font-size : small;
font-weight : bold;
text-align : center;
}

A {
color : White;
text-decoration : none;
}

A:HOVER {
color : #666666;
text-decoration : none;
}

A.Link {
color: #FFCC33;
text-decoration: none;

}
-->
</style>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"></HEAD>
<body bgcolor="#000000">
<div align="center">
<p> </p>
<p> </p>
<p> </p>
<p><a href="/" class="Link"><strong>:::
H V A : F o r u m :::</strong></a></p>
<TABLE cellSpacing=5 width="85%" border=0>
<TBODY>
<TR>
<TD class=txt><hr align="center" width="80%" size="1" noshade></TD>
</TR>
<TR>
<TD class=txt>
<p align="center"><strong><font color="#FFFFFF">Phương thức truy cập không được phép!</font></strong><font color="#FFFFFF"><br>
Phương thức truy cập không được server xử lý.</font></p>
<P align=center><font color="#FFFFFF">Xin vui lòng bấm và o đường dẫn
"</font><a href="/" class="Link">:::HVA:Forum:::</a><font color="#FFFFFF">" để trở về trang chủ.</font><BR>
</P>
</TD>
</TR>
<TR>
<TD class=txt> <div align="left">
<hr align="center" width="80%" size="1" noshade>
</div></TD>
</TR>
<TR>
<TD class=txt>
<p align="center"><span class="txt"><strong><font color="#FFFFFF">Method Not Allowed!</font></strong> </span><font color="#FFFFFF"><br>
The request method is not allowed by the server.</font></p>
<p align="center"><font color="#FFFFFF">Please click on "</font><a href="/" class="Link">:::HVA:Forum:::</a><font color="#FFFFFF">"
link above to get back to the home page.</font></p>
<hr align="center" width="80%" size="1" noshade></TD>
</TR>
</TBODY>
</TABLE>

<p> </p>
</div>
</HTML>
0

 

Vậy làm sao chống được cái request "hắc ám" nì?
[Up] [Print Copy]
  [Question]   Re: Hỏi về: DELETE / HTTP/1.1..... 28/04/2008 06:30:19 (+0700) | #2 | 127878
[Avatar]
conmale
Administrator

Joined: 07/05/2004 23:43:15
Messages: 9353
Location: down under
Offline
[Profile] [PM]
Mèn.... dùng diễn đàn HVA để thử nghiệm sống vậy sao trời smilie . Lỡ nó delete cái gì thật thì tội nghiệp.

Bồ dùng apache? vậy thì thử trong httpd.conf

Code:
RewriteEngine on
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK|DELETE|PUT|LINK|UNLINK|CHECKOUT|CHECKIN|PUT|)
RewriteRule .* - [F]


hoặc:
Dùng directive <Limit GET POST> trong virtual host hoặc directory.

hoặc:
Dùng mod_security (1.9x):
Code:
SecFilterSelective REQUEST_METHOD "!^(POST|GET)$" "deny,status:405"
What bringing us together is stronger than what pulling us apart.
[Up] [Print Copy]
[digg] [delicious] [google] [yahoo] [technorati] [reddit] [stumbleupon]
Go to: 
 Users currently in here 
1 Anonymous

Powered by JForum - Extended by HVAOnline
 hvaonline.net  |  hvaforum.net  |  hvazone.net  |  hvanews.net  |  vnhacker.org
1999 - 2013 © v2012|0504|218|