Mailing List ecs-isp@2rosenthals.com Archived Message #1387

From: "Massimo S." <ecs-isp@2rosenthals.com> Full Headers
Undecoded message
Subject: help with Injoy FW rule (bots that search for strings and get a number or 404)
Date: Mon, 31 Aug 2026 10:24:38 +0200
To: eCS ISP Mailing List <ecs-isp@2rosenthals.com>

Hi all,

there is a kind of DDOS attack from bots/crawlers/exploit scanners or such that soon or later generate this situation:

[Mon Aug 31 06:50:02.467000 2026] [mpm_mpmt_os2:error] [pid 96:tid 1] (70007)The timeout specified has expired: AH00194: apr_socket_accept
[Mon Aug 31 06:50:02.042000 2026] [mpm_mpmt_os2:notice] [pid 64:tid 1] AH00201: caught SIGTERM, shutting down [Mon Aug 31 06:50:02.467000 2026] [mpm_mpmt_os2:error] [pid 96:tid 1]

each time i see in the http log stuff like this:

34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /store HTTP/1.1" 404 196 65 14
34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /cart HTTP/1.1" 404 196 69 12
34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /controllers HTTP/1.1" 404 196 68 17

etc. etc.

Is there a possibility to make a rule that if an IP get too many 404 in a certain period
of time it get blocked (DENY, bot blacklist)?

Thanks for any help.

massimo

Subscribe: Feed, Digest, Index.
Unsubscribe
Mail to ListMaster