Lista de correo ecs-isp@2rosenthals.com Mensaje #1387
De: "Massimo S." <ecs-isp@2rosenthals.com> Encabezados Completos
Mensaje no decodificado
Asunto: help with Injoy FW rule (bots that search for strings and get a number or 404)
Fecha: Mon, 31 Aug 2026 10:24:38 +0200
Para: eCS ISP Mailing List <ecs-isp@2rosenthals.com>

Hi all,

there is a kind of DDOS attack from bots/crawlers/exploit scanners or such that soon or later generate this situation:

[Mon Aug 31 06:50:02.467000 2026] [mpm_mpmt_os2:error] [pid 96:tid 1] (70007)The timeout specified has expired: AH00194: apr_socket_accept
[Mon Aug 31 06:50:02.042000 2026] [mpm_mpmt_os2:notice] [pid 64:tid 1] AH00201: caught SIGTERM, shutting down [Mon Aug 31 06:50:02.467000 2026] [mpm_mpmt_os2:error] [pid 96:tid 1]

each time i see in the http log stuff like this:

34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /store HTTP/1.1" 404 196 65 14
34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /cart HTTP/1.1" 404 196 69 12
34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /controllers HTTP/1.1" 404 196 68 17

etc. etc.

Is there a possibility to make a rule that if an IP get too many 404 in a certain period
of time it get blocked (DENY, bot blacklist)?

Thanks for any help.

massimo
Subscribirse en modo directo (FEED) Subscribirse en modo resumen (DIGEST) Subscribirse en modo índice (INDEX) Desubscribirse E-mail al Listmaster