Liste de diffusion ecs-isp@2rosenthals.com Message #1387
De: "Massimo S." <ecs-isp@2rosenthals.com> En-têtes complèts
Message brut
Sujet: help with Injoy FW rule (bots that search for strings and get a number or 404)
Date: Mon, 31 Aug 2026 10:24:38 +0200
À: eCS ISP Mailing List <ecs-isp@2rosenthals.com>

Hi all,

there is a kind of DDOS attack from bots/crawlers/exploit scanners or such that soon or later generate this situation:

[Mon Aug 31 06:50:02.467000 2026] [mpm_mpmt_os2:error] [pid 96:tid 1] (70007)The timeout specified has expired: AH00194: apr_socket_accept
[Mon Aug 31 06:50:02.042000 2026] [mpm_mpmt_os2:notice] [pid 64:tid 1] AH00201: caught SIGTERM, shutting down [Mon Aug 31 06:50:02.467000 2026] [mpm_mpmt_os2:error] [pid 96:tid 1]

each time i see in the http log stuff like this:

34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /store HTTP/1.1" 404 196 65 14
34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /cart HTTP/1.1" 404 196 69 12
34.34.225.86 - - [31/Aug/2026:09:36:00 +0100] "GET /controllers HTTP/1.1" 404 196 68 17

etc. etc.

Is there a possibility to make a rule that if an IP get too many 404 in a certain period
of time it get blocked (DENY, bot blacklist)?

Thanks for any help.

massimo
S'abonner aux messages S'abonner aux sommaires S'abonner aux indexes Se désabonner Ecrire un email au responsable de la liste