Welcome to WebmasterWorld Guest from

Forum Moderators: Ocean10000 & incrediBILL & phranque

Message Too Old, No Replies

"CONNECT" Verb in apache

Can I block this verb?

7:33 pm on Jul 30, 2007 (gmt 0)

Junior Member

10+ Year Member

joined:Apr 8, 2005
votes: 0

I have apache (2.2) proxying to an IIS6 server. I keep getting errors from IIS "Connect not allowed". It appears that random people are trying to test a spam exploit in apache (using the connect verb). Is there any way to tell Apache to not allow the connect verb? (I would assume in the httpd.conf file).

Many thanks in advance!

3:23 pm on July 31, 2007 (gmt 0)

Senior Member

WebmasterWorld Senior Member jdmorgan is a WebmasterWorld Top Contributor of All Time 10+ Year Member

joined:Mar 31, 2002
votes: 0

A simple way is to use the Apache core <Limit> container and a mod_access Deny from directive to return a 403-forbidden response for requests using the CONNECT method:

Deny from all

See Apache mod_access for information about the Order directive; If you have other Allows or Denys, you may need to integrate the above code with them.