PitchLake - a tar pit for scanners
by Simon Biles
One of my first tasks in the office this morning, after a cup of coffee of course, was to review my server logs. As of yet I’ve not got enough staff to have a minion to do this for me, but to be honest I’d miss the connection to the real world of computing if I did. I run a Linux server in a datacentre in Birmingham as my company’s main web-server and my high bandwidth, static IP’d pen-test machine. For the last few months I’ve been meaning to do something about the 404 errors (http//
en.wikipedia.org/wiki/HTTP_404) that are being reported by Apache – some are my fault for taking pages away that people clearly still cross reference – the others though are clearly the work of automated web vulnerability scanning tools…
Please use this thread for discussion of Simon's latest column.
Just a quick note - it's rapidly moved from Version 0.2 as per the article to V0.3.3 - mostly as I realised what stupid errors that I made with regard to race conditions !
I've updated the article!
Jamie
Ta(r) !