Darren |
04-20-2005 12:05 AM |
Under attack, a memo will be sent out later with details on how we plan to compensate for this. We do have back ups but the attack is not letting us do much.
Details:
Good evening.
The form of the attack has changed. Currently the attackers are using a botnet to send malformed HTTP requests to the server, then let the connections sit in the "established" state thereby preventing other connections from going through. This also forces me to have to manually run through the logs to find the malformed requests and block each address individually, then restart Apache to release the connection.
This is my top priority today and I am doing this every five minutes. Currently the number of blocked bots is 927.
|