Pete Stephenson
2017-07-20 14:54:34 UTC
Hi all,
I've been receiving some queries that, while not stressing my server,
appear to be abusive in nature...though perhaps accidentally so.
Here's a quick excerpt from the logs:
216.241.59.205 - - [20/Jul/2017:14:46:51 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
216.241.59.205 - - [20/Jul/2017:14:46:53 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
216.241.59.205 - - [20/Jul/2017:14:46:56 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
216.241.59.205 - - [20/Jul/2017:14:46:58 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
This particular client is making continuous requests for the main page
of my server every 2-3 seconds. They're not making any queries for keys,
submitting keys, etc., but are only requesting the main page.
This has been going on since at least the 15th of July.
I haven't observed any other odd traffic, so it seems unlikely that a
botnet is involved. Maybe a script that has gone awry?
Although slightly annoying, it doesn't consume much resources. Any
suggestions on how to deal with this client? For example, should I
continue to serve them normally, firewall their IP address, etc.? Any
suggestions on how to deal with more serious abuse in the future?
Cheers!
-Pete
I've been receiving some queries that, while not stressing my server,
appear to be abusive in nature...though perhaps accidentally so.
Here's a quick excerpt from the logs:
216.241.59.205 - - [20/Jul/2017:14:46:51 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
216.241.59.205 - - [20/Jul/2017:14:46:53 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
216.241.59.205 - - [20/Jul/2017:14:46:56 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
216.241.59.205 - - [20/Jul/2017:14:46:58 +0000] "GET / HTTP/1.1" 200
5285 "-" "-"
This particular client is making continuous requests for the main page
of my server every 2-3 seconds. They're not making any queries for keys,
submitting keys, etc., but are only requesting the main page.
This has been going on since at least the 15th of July.
I haven't observed any other odd traffic, so it seems unlikely that a
botnet is involved. Maybe a script that has gone awry?
Although slightly annoying, it doesn't consume much resources. Any
suggestions on how to deal with this client? For example, should I
continue to serve them normally, firewall their IP address, etc.? Any
suggestions on how to deal with more serious abuse in the future?
Cheers!
-Pete
--
Pete Stephenson
Pete Stephenson