Jump to content

ElasticSearch - Ddos


desti

Recommended Posts

Posted

A very simple attack happened the other day, thousands of "GET /search/?q=1" (or 2...9) requests from different IP, mysql reply "too many connections". 

Do you want to return the minimum request length limit?

Posted

Come on, really?

*.*.*.* - [02/Jan/2020:21:12:36 +0100] "GET /search/?q=1 HTTP/1.1", 20-30 rps, attacks from thousands different IP's, сan you tell me rule for iptables? 

I added a line and the attack stopped killing the server. 

if (!\IPS\Member::loggedIn()->member_id AND \strlen(\IPS\Request::i()->q) <= 2 ) die();
 

 

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...