【 Combat Report!】 Good morning, good afternoon, good evening everyone. Since the day before yesterday, we have been continuously facing malicious attacks from multiple scripts. This morning, we reached a small peak, receiving over 200,000 malicious requests in just a few hours, which has consumed nearly 10GB of traffic. We have now blacklisted the following IP ranges:
182.34.4.0/24
180.119.118.0/23
140.75.192.0/24
121.233.200.0/24
61.147.92.0/24
120.238.245.0/24
58.222.45.0/24
218.90.199.0/24
Since these requests are consuming about 100 MB of traffic every 5 minutes, we have not triggered the CDN's 5-minute 200MB cap limit. Additionally, with the weekend morning spent sleeping, more than half of this month's CDN free quota has already been consumed (and it's only the beginning of the month (×﹏×)).
If we continue to be attacked and the CDN free quota is exhausted, we will redirect all domestic traffic to overseas lines to avoid the situation for a while. At that time, there may be significant delays in website loading times and some regions may be inaccessible. We ask for your understanding.
Finally, please show mercy to the script masters.
Follow-up#
In light of the ongoing sporadic malicious attacks, we have begun writing and have enabled a script for automatic detection and updating of the CDN blacklist. This time, I should be able to get a good night's sleep.
This article is synchronized and updated to xLog by Mix Space. The original link is https://www.vinking.top/notes/23