[svlug] someone is hammering my webserver

Bill Teeple bill at teeple.tv
Mon Jan 28 10:39:45 PST 2008


Drop it using IPTABLES - just issue the IPTABLES command - drop the
packet for port 80 and they won't get any more responses from your site
and your system will be better off. (or whatever firewall you employ)

I don't know about redirecting... my two cents.

Bill


On Mon, 2008-01-28 at 10:31 -0800, Larry Colen wrote:
> On Mon, Jan 28, 2008 at 10:28:20AM -0800, Jeff Shippen wrote:
> # looks like it is all from the same IP, which you can block, or even better,
> # redirect their request to 127.0.0.1.
> 
> Yup, another 80,000 hits since I sent the last message:
> red4est:/var/log/apache# grep 83.156.199.176 access.log* | wc
>  530090 11660614 103915191
> 
> 





More information about the svlug mailing list