4 ms·
If I'm not mistaken, the above implies accepting a TCP connection (3-way handshake) and a request from the attacker; then you look up the contents of the user-a
by NetStrikeForce 11y ago
If I'm not mistaken, the above implies accepting a TCP connection (3-way handshake) and a request from the attacker; then you look up the contents of the user-agent header and decide to stop replying based on its contents.
This will get you nothing in a typical DDoS scenario, but thanks for sharing as it may come handy for other situations.
- creshal 11y agoFiltering like that also has a rather big performance impact on the nginx side and make things worse under moderate, but not DDoS-y, traffic conditions.