4 ms·
That is actually cool, it is a tarpit for these bots! On a well configured site the LB timeouts should be short enough anyway. But it is a risk, especially on
by treffer 4y ago
That is actually cool, it is a tarpit for these bots!
On a well configured site the LB timeouts should be short enough anyway.
But it is a risk, especially on classic DOS attacks.
- quesera 4y agoYep it's great for tarpitting if you are not behind an LB. The other problem, if you are behind an LB, is that the client (DoS attacker) will get a 503 from the LB after timeout. So, no gain even if your timeouts are reasonable. It'd be great if you could return a custom response from nginx that would tell the LB to drop the request -- or you could move the exploit-detection logic to the LB instead of nginx, and the LB could do its own 444 equivalent.