• Global community
    • Language:
      • Deutsch
      • English
      • Español
      • Français
      • Português
  • 日本語コミュニティ
    Dedicated community for Japanese speakers
  • 한국 커뮤니티
    Dedicated community for Korean speakers
Exit
0

HTTP status code to return when attacked

Explorer ,
Feb 04, 2014 Feb 04, 2014

Copy link to clipboard

Copied

My question is not specific to ColdFusion, I know how to set HTTP status codes.

What I am wondering is if anyone knows of any best practices for what to do when a known attack comes into a site. I am speaking primarally of specifically formatted URLs of people scanning to find weaknesses in my sites.

I have collected a large number of URLs that we get scanned for regularly that are clear attempts to locate weaknesses.

Should I?

  1. Send a 404 telling them the attacked page does not exists
  2. Send a 503 making them think it errored
  3. Send a 200 with a blank page making them think they go to a real page
  4. Something else I havn't concidered

I am trying to avoid any sort of escalation on their part thinking they can hit my site harder, IE, if they get a 503, might they believe that my site could be weak and they step up the attack...

Any thoughts would be greatly apreciated.

Thanks

TOPICS
Advanced techniques

Views

356

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Feb 13, 2014 Feb 13, 2014

Copy link to clipboard

Copied

LATEST

Be proactive: go on the offensive. For example, the famous Mykonos web security software chooses to:

Warn the attacker

Block the user

Force a CAPTCHA

Slow the connection

Simulate a broken application

Force log-out

Votes

Translate

Translate

Report

Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources
Documentation