<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[blog.rayfoo] &#187; web server</title>
	<atom:link href="http://blog.rayfoo.info/tag/web-server/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rayfoo.info</link>
	<description>Here&#039;s where I write stuff, and you read what I wrote.</description>
	<lastBuildDate>Fri, 30 Jul 2010 04:30:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>DNS rebinding defense with Nginx</title>
		<link>http://blog.rayfoo.info/2010/02/dns-rebinding-defense-with-nginx</link>
		<comments>http://blog.rayfoo.info/2010/02/dns-rebinding-defense-with-nginx#comments</comments>
		<pubDate>Fri, 26 Feb 2010 16:47:58 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[DNS rebinding]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server administration]]></category>
		<category><![CDATA[web server]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=461</guid>
		<description><![CDATA[DNS rebinding&#8217;s a particularly nasty attack, having similar characteristics as CSRF attacks where the user&#8217;s browser can be used to access/attack sites on behalf of the attacker. I&#8217;m not going to describe how it works here, there&#8217;s plenty of literature out there that talks about it.  And if that&#8217;s not enough, Google Is Your Friend. [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2010/02/dns-rebinding-defense-with-nginx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Testing Slowloris against nginx</title>
		<link>http://blog.rayfoo.info/2009/10/testing-slowloris-against-nginx</link>
		<comments>http://blog.rayfoo.info/2009/10/testing-slowloris-against-nginx#comments</comments>
		<pubDate>Mon, 12 Oct 2009 05:59:24 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[RSnake]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Slowloris]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[web server]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=244</guid>
		<description><![CDATA[CCCCCCCCCCOOCCOOOOO888@8@8888OOOOCCOOO888888888@@@@@@@@@8@8@@@@888OOCooocccc:::: CCCCCCCCCCCCCCCOO888@888888OOOCCCOOOO888888888888@88888@@@@@@@888@8OOCCoococc::: CCCCCCCCCCCCCCOO88@@888888OOOOOOOOOO8888888O88888888O8O8OOO8888@88@@8OOCOOOCoc:: CCCCooooooCCCO88@@8@88@888OOOOOOO88888888888OOOOOOOOOOCCCCCOOOO888@8888OOOCc:::: CooCoCoooCCCO8@88@8888888OOO888888888888888888OOOOCCCooooooooCCOOO8888888Cocooc: ooooooCoCCC88@88888@888OO8888888888888888O8O8888OOCCCooooccccccCOOOO88@888OCoccc ooooCCOO8O888888888@88O8OO88888OO888O8888OOOO88888OCocoococ::ccooCOO8O888888Cooo oCCCCCCO8OOOCCCOO88@88OOOOOO8888O888OOOOOCOO88888O8OOOCooCocc:::coCOOO888888OOCC oCCCCCOOO88OCooCO88@8OOOOOO88O888888OOCCCCoCOOO8888OOOOOOOCoc::::coCOOOO888O88OC oCCCCOO88OOCCCCOO8@@8OOCOOOOO8888888OoocccccoCO8O8OO88OOOOOCc.:ccooCCOOOO88888OO CCCOOOO88OOCCOOO8@888OOCCoooCOO8888Ooc::...::coOO88888O888OOo:cocooCCCCOOOOOO88O CCCOO88888OOCOO8@@888OCcc:::cCOO888Oc..... ....cCOOOOOOOOOOOc.:cooooCCCOOOOOOOOO OOOOOO88888OOOO8@8@8Ooc:.:...cOO8O88c. . .coOOO888OOOOCoooooccoCOOOOOCOOOO OOOOO888@8@88888888Oo:. . ...cO888Oc.. .oOOOOOOOOOCCoocooCoCoCOOOOOOOO COOO888@88888888888Oo:. .O8888C: .oCOo. ...cCCCOOOoooooocccooooooooCCCOO CCCCOO888888O888888Oo. .o8Oo. .cO88Oo: :. .:..ccoCCCooCooccooccccoooooCCCC coooCCO8@88OO8O888Oo:::... .. :cO8Oc. . ..... :. .:ccCoooooccoooocccccooooCCC :ccooooCO888OOOO8OOc..:...::. .co8@8Coc::.. .... ..:cooCooooccccc::::ccooCCooC .:::coocccoO8OOOOOOC:..::....coCO8@8OOCCOc:... ....:ccoooocccc:::::::::cooooooC ....::::ccccoCCOOOOOCc......:oCO8@8@88OCCCoccccc::c::.:oCcc:::cccc:..::::coooooo .......::::::::cCCCCCCoocc:cO888@8888OOOOCOOOCoocc::.:cocc::cc:::...:::coocccccc ...........:::..:coCCCCCCCO88OOOO8OOOCCooCCCooccc::::ccc::::::.......:ccocccc:co .............::....:oCCoooooCOOCCOCCCoccococc:::::coc::::....... ...:::cccc:cooo ..... ............. .coocoooCCoco:::ccccccc:::ccc::.......... ....:::cc::::coC . . ... .... [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2009/10/testing-slowloris-against-nginx/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Weird web server access log entries</title>
		<link>http://blog.rayfoo.info/2009/10/weird-web-server-access-log-entries</link>
		<comments>http://blog.rayfoo.info/2009/10/weird-web-server-access-log-entries#comments</comments>
		<pubDate>Wed, 07 Oct 2009 04:43:44 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[1Portfolio]]></category>
		<category><![CDATA[abuse]]></category>
		<category><![CDATA[anomaly]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[bad customer service]]></category>
		<category><![CDATA[ISP]]></category>
		<category><![CDATA[load balancer]]></category>
		<category><![CDATA[logs]]></category>
		<category><![CDATA[nginx]]></category>
		<category><![CDATA[Singnet]]></category>
		<category><![CDATA[web server]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=223</guid>
		<description><![CDATA[Don&#8217;t have the answer to this yet, but it sure makes me really really curious as to the cause. In my web server access logs, I get plenty of entries that look like this: 69.64.58.126 - - [02/Oct/2009:14:20:55 +0800] "-" 400 0 "-" "-" That means that these IP addresses have been connecting to my [...]]]></description>
		<wfw:commentRss>http://blog.rayfoo.info/2009/10/weird-web-server-access-log-entries/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
