I'm getting massive amounts of attacks from this beastie
-
155.4.128.166 – – [11/Feb/2016:10:40:16 +0000] “GET /valentines-amaretto-truffles/undefined/fp?zoneid=314857&tid=m_314857_a5a89c610b924c1ebca4f17144b4d508&cv=0e59d8f&err=Cannot%20read%20property%20%27left%27%20of%20undefined&msg=URL%3A%20http%3A%2F%2Fwww.lazycatkitchen.com%2Fvalentines-amaretto-truffles%2F%20LINE%3A%201092%20COL%3A%2078%20MSG%3A%20Uncaught%20TypeError%3A%20Cannot%20read%20property%20%27left%27%20of%20undefined%20ERR%3A%20TypeError%3A%20Cannot%20read%20property%20%27left%27%20of%20undefined&stack=TypeError%3A%20Cannot%20read%20property%20%27left%27%20of%20undefined%0A%20%20%20%20at%20OVVAsset.positionBeacons%20(eval%20at%20%3Canonymous%3E%20(unknown%20source)%2C%20%3Canonymous%3E%3A1092%3A78) HTTP/1.1” 404 26015 “https://www.lazycatkitchen.com/valentines-amaretto-truffles/” “Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.103 Safari/537.36”
I get thousands of these and my CPU usage goes up to 40-50% (on a small AWS instance) until I find the IP address and manually block it. Right now NinjaFirewall does not block this. I guess I need to create a custom rule for this? Any tips on how to do this? I note that whoever it is has frigged together a plausible UserAgent. Should I block requests that are over a certain size? Maybe 512 characters?
- The topic ‘I'm getting massive amounts of attacks from this beastie’ is closed to new replies.