HTTP Vulnerability Scan ProtectionProtection overviewRdpGuard monitors Microsoft IIS, Apache HTTP Server and nginx access logs for requests that may indicate vulnerability scanning, such as repeated requests for missing pages or attempts to find exposed credentials and repository files. When detections from an IP address reach your configured blocking limit, RdpGuard temporarily blocks that address. HTTP protection uses a set of detection rules to identify suspicious requests. Start with the standard rules, then adjust them to the paths and applications hosted on your server. If your websites are behind a reverse proxy, also review the proxy settings to identify and block the original client. Enable and configure HTTP protection
IIS log directories Select each site's log folder, for example Enable W3C logging in IIS. Include Client IP Address ( Apache access log directories![]() Select the access log directory configured in Apache, for example nginx access log directories Select nginx as the web server and add the directory containing its access logs, for example RdpGuard handles nginx's default Detection rulesSelect Override standard detection rules to edit the rules. Your custom set replaces the standard rules; it is not added to them. Keep any standard rules you still need in the custom set, or clear the checkbox to return to the defaults. Write one rule per line. A line beginning with This example matches requests for ZIP files, except those under Supported fields and their corresponding IIS W3C field names:
Make sure your log format includes the fields used by your rules. Apache Common logs do not contain Referer or User-Agent values; use Combined logs for rules that depend on them. Threshold Without This rule produces one detection for every 15 HTTP 404 responses to requests from the same IP address. It does not block the address after 15 requests by itself: blocking still depends on the detection limit configured in RdpGuard. If that limit is 3 and no other rules contribute, this rule alone needs 45 matching requests before the address is blocked, assuming the counters have not reset. A threshold helps avoid treating an occasional broken link as a scan attempt. For a path that has no legitimate use on your website, you may choose a rule without a threshold. Configure the blocking limit and counter reset interval in Tools, Options, on the General tab. Sample rulesThe following rules match the current standard set. Archive and WordPress checks are commented out. Enable them only if requests to those paths should be treated as scanning on your websites; otherwise, you could block legitimate visitors. Advanced settingsClick Advanced settings... in HTTP Protection Settings to open Advanced HTTP Settings. The X-Forwarded-For options below apply to IIS logs. ![]() Read the client IP address from the X-Forwarded-For field By default, RdpGuard uses Client IP Address ( Configure your trusted proxy to supply the real client IP and prevent clients from injecting their own first address into the header. Restrict direct access to IIS so requests cannot bypass the proxy. See Configuring IIS to Detect Client IP Behind a Proxy for the IIS logging setup. Use the connection IP address if X-Forwarded-For is missing Enable this option to use Click OK, then Save in HTTP Protection Settings to apply the changes. For Apache, RdpGuard reads the IP address from the first field of each access log entry; these X-Forwarded-For checkboxes do not affect Apache logs. Configure Apache to write the original client IP there, using a trusted proxy setup such as mod_remoteip. For nginx, RdpGuard also uses the first field of each access log entry ( Blocking requests when using X-Forwarded-ForReading X-Forwarded-For identifies the client, but does not change where blocking happens. When the connection to your server comes from a reverse proxy, a Windows firewall rule for the original client IP will not block that proxied connection. Block the client at the proxy. For IIS, you can also use IIS IP Address and Domain Restrictions with Proxy Mode and RdpGuard Custom Actions as shown below. Configuring Custom Actions in RdpGuard This example adds and removes IPv4 deny entries for one IIS website. Replace
IP Blocked action
Arguments: IP Unblocked action
Arguments: Save the actions. After a local detection triggers a block, verify that the deny entry appears for the selected IIS site and requests from that client are denied through the proxy. When RdpGuard unblocks the address, the second action removes the entry. These actions handle future IP Blocked and IP Unblocked events from local detections; they do not synchronize the existing blocked list or addresses blocked only through IP Cloud. | RdpGuard 10.4.5 Free Trial RdpGuard protects:
Our customers say "This sotware is really great. It's a relief. Because my server is constantly under attack. Thanks RdpGuard" - Joaquim De Sousa Marques "Nice product. I used to implement something similiar in a low-tech and cumbersome manner via a script called TSBlock (not mine). This makes it much easier and is well worth the pricetag for SMB's." - J. Johnson "Absolutely amazed at your product. We are a church in the North Dallas area, and I discovered this morning multiple failed logon attempts via our Remote Access Server. A friend suggested your product, so I immediately downloaded the trial. It had a list of about five blocked IP addresses in minutes, and that was enough to lead me to push the BUY button. Over the past 10-15 minutes the list is now about thirty with at least a third being international attempts to break into our system. Thanks for a great product. You may have just saved us much grief." - John Hallford "Love the software. RDP on our Windows servers is just ridiculous. We would block it in the router but we have lots of old-time customers that would have issues." - Scott Hirsch "Love the software! Makes it easier than tailoring VB Scripts!!" - Nick Brennan "It's a great product - really stopping those RDP attackers :-)" - Dave, UK "First of all: Your application is very (!!!) useful and I like it very much securing my 2012 R2 server. RdpGuard is the best solution, I found on the market and after 10 minutes of testing it I ordered the fully-featured version. :-)" - Carsten Baltes Our Other Products |