>is it possible to filter with vernish some known hack attempts, link

Yes, Kristian did something "mod_security" like I think.

It's pretty easy to blast individual bad things out of the way;
	sub vcl_recv {
		if (req.url ~ "_vti_bin/owssvr.dll") { error 503; }

