Monday, September 21, 2015

Re: Invalid HTTP_HOST, can someone explain why I am getting this?

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQIcBAEBCAAGBQJWAIQCAAoJEC0ft5FqUuEhOjgP/1sQ4I456ofPDRv8MXgwlU1E
rG9f7O4OIzMtsPxoF3UwTDQ13EDEcHwh8+H1Rb2Cm0wXAWFVCiYu84sF1XPITwjQ
7Y4raOh/L+k23SSBiTZiNd6BIthVK/frlW6wFZydBIuGLIspNOw3C9o19ZPwrJsc
2ZNddr9HKM+yLOOgfGkcoXUDvxFkHB/oTHZxhSKzDBJ74DQxGFZwoiS0QVmQxAdT
dnBfM+O/mzMoA2hFftYXE7QZbdILcf5hIJOrIdmEk+6xTSK0lweN7Jbzqi8hF7pR
B4QhucDYCalh++mjcNU8GdQp4j1Wm6L4Hp5CudknRg2izt52Zaqixmpb4PabpFwa
6SDMK5u35i0UAtc7sNuWCyRHpIt6/gzTGkFT9zWaXKQScNEn09sCgI1aKdKQKVll
ZPz42r3wWgxwJLcGYfSHwbukS2HLNkjWkHlweg4o2MGae6L8v/RC1mHikuqZoqYE
tn0PB54eodW/EtMMzkMeKBbNhzG5Z3ucbLfh7LXXxIXt2bq7yjynsNFkvBbnJviU
QlR08L/L/d7Idmn99KYdjSsoN4zSVNiVYxvChmlvkx1Yi/GogwzIw34XBznJq7gK
pXzvd8WtZn7/cL3wYx/LQ0ohcFeXw6kMeiPodKQQs2pl+wKu060FH7qCef4db5jL
jSMM0jBGbgBsrgtvN/oq
=maPz
-----END PGP SIGNATURE-----
On 09/21/2015 04:22 PM, François Schiettecatte wrote:
> Not likely, all that is happening is that you are getting requests
> where the 'Host:' HTTP header is not set or set to something other
> than what is accepted by your site. Most likely a buggy client. I get
> that all the time, I just ignore it.
>
> Cheers
>
> François
>
>> On Sep 21, 2015, at 6:16 PM, frocco <farocco@gmail.com> wrote:
>>
>> I am still getting this invalid host from time to time. Does this
>> mean that someone is trying to hack my site?
>>
>> www.g3suprimentos.com.br is not anything I own.
>>
>> For now, I am just ignoring this.

The best way to solve this for good and never get those errors again is
to fix it in your front-end webserver configuration, so that it ignores
requests for the wrong Host and doesn't even pass them on to Django in
the first place. If you're using nginx that means setting your
`server_name` directive correctly. If you're using Apache that means
using a name-based (non-default) VirtualHost. Any webserver should
provide some way to do this.

Carl

--
You received this message because you are subscribed to the Google Groups "Django users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to django-users+unsubscribe@googlegroups.com.
To post to this group, send email to django-users@googlegroups.com.
Visit this group at http://groups.google.com/group/django-users.
To view this discussion on the web visit https://groups.google.com/d/msgid/django-users/56008402.70309%40oddbird.net.
For more options, visit https://groups.google.com/d/optout.

No comments:

Post a Comment