Seen today on the Apache user's mailing list:
"I noticed someone was using a CONNECT xxx.xxx.xxx.xxx http command
against Apache. I was wondering how to disable the CONNECT command
from executing on Apache. In a couple of entries I noticed a
connection from Seattle that might be a spammer so I want to disable
the CONNECT command from running successfully."
Being a good Samaritan I replied with a few tips. But later I couldn't
help wondering: is this a troll who's hoping for a response like,
"Yeah, we have that at www.oursite.org as well", just to get a new
address of an open proxy?
Or is this a valid question on a list of
an Apache self-help group? Am I being paranoid? Do I have reason to
be?