CB9TOIIIA
@CB9TOIIIA
Joomla разработчик

DDOS — случайный реферер (ботнет)?

Всем привет! ДДОСЯТ сайты, перешел на VDS + CloudFlare (PRO), прошу помощи, как можно отбить такие атаки?

108.162.254.65 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://203g96q6e93.ua/" "Opera/9.80 (Windows NT 6.1; U; Edition Grenada Local; ru) Presto/2.10.289 Version/9.06"

108.162.254.65 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://4du9f.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.014982; .NET CLR 3.5.014982; .NET CLR 3.0.014982"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://l9q904vb20.net/" "Opera/9.80 (Windows NT 6.1; WOW64; U; Edition France Local; ru) Presto/2.10.289 Version/11.08"

108.162.212.48 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 504 182 "http://891f25944drj0.ua/" "Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0"

141.101.98.213 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://bg61dar789x.org/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.537976; .NET CLR 3.5.537976; .NET CLR 3.0.537976"

141.101.98.213 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://85rh4er9k3.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.033922; .NET CLR 3.5.033922; .NET CLR 3.0.033922"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://v410e78grgrki9.net/" "Opera/9.80 (Windows NT 5.1; U; Edition Grenada Local; ru) Presto/2.10.289 Version/5.08"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://0z8n634c.org/" "Mozilla/5.0 (Windows NT 6.1; rv:12.0) Gecko/20100101 Firefox/12.0"

141.101.80.49 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://98l3j47grimx.com/" "Mozilla/5.0 (Windows NT 6.1; rv:15.0) Gecko/20100101 Firefox/15.0"

173.245.62.188 - - [15/Oct/2014:17:23:15 +0300] "GET / HTTP/1.1" 499 0 "http://fsl4y5zt79.org/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SLCC2; .NET CLR 2.0.989772; .NET CLR 3.5.989772; .NET CLR 3.0.989772"

108.162.212.16 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://960culf1sqsu.ua/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.029777; .NET CLR 3.5.029777; .NET CLR 3.0.029777"

108.162.254.65 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://8gen0pguofs19.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.498375; .NET CLR 3.5.498375; .NET CLR 3.0.498375"

108.162.223.131 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://72ihk.net/" "Mozilla/5.0 (Windows NT 6.1; rv:17.0) Gecko/20100101 Firefox/17.0"

108.162.254.65 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://953qu3w4v0r7.org/" "Mozilla/5.0 (Windows NT 5.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0"

103.22.200.180 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://648z620t6f.net/" "Opera/9.80 (Windows NT 6.1; WOW64; U; Edition Romania Local; ru) Presto/2.10.289 Version/7.05"

141.101.80.49 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://34yupy175a3587.org/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.349828; .NET CLR 3.5.349828; .NET CLR 3.0.349828"

108.162.254.65 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://zi22jg4j00.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.029356; .NET CLR 3.5.029356; .NET CLR 3.0.029356"

108.162.223.131 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://lsu7849.ua/" "Opera/9.80 (Windows NT 5.1; WOW64; U; Edition Egypt Local; ru) Presto/2.10.289 Version/12.09"

141.101.75.95 - - [15/Oct/2014:17:23:16 +0300] "GET / HTTP/1.1" 499 0 "http://2x9rgrr69lr.net/" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.045441; .NET CLR 3.5.045441; .NET CLR 3.0.045441"
  • Вопрос задан
  • 4259 просмотров
Пригласить эксперта
Ответы на вопрос 2
AMar4enko
@AMar4enko
Айпишники повторяются. Делайте request throttling, при превышении количества запросов в единицу времени записывайте ip-адрес в отдельный лог, на этот лог натравливайте fail2ban.
Ответ написан
opium
@opium
Просто люблю качественно работать
Да самый банальный ддос
Ответ написан
Ваш ответ на вопрос

Войдите, чтобы написать ответ

Войти через центр авторизации
Похожие вопросы