ElasticSearch - Ddos


Come on, really?

*.*.*.* - [02/Jan/2020:21:12:36 +0100] "GET /search/?q=1 HTTP/1.1", 20-30 rps, attacks from thousands different IP's, сan you tell me rule for iptables? 

I added a line and the attack stopped killing the server. 

if (!\IPS\Member::loggedIn()->member_id AND \strlen(\IPS\Request::i()->q) <= 2 ) die();


