Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > rocksolid.shared.security > #7 > unrolled thread

long live return code 444

Started byAnonymous <poster@anon.com>
First post2020-07-26 15:58 -0700
Last post2020-08-05 19:01 +0000
Articles 7 — 4 participants

Back to article view | Back to rocksolid.shared.security


Contents

  long live return code 444 Anonymous <poster@anon.com> - 2020-07-26 15:58 -0700
    Re: long live return code 444 retro.guy@rocksolidbbs.com (Retro Guy) - 2020-07-27 08:20 +0000
    Zones Anonymous <poster@anon.com> - 2020-07-27 11:25 -0700
      Re: Zones retro.guy@rocksolidbbs.com (Retro Guy) - 2020-08-05 04:51 +0000
    nginx is great Anonymous <poster@anon.com> - 2020-08-01 15:13 -0700
      Re: nginx is great AnonUser@rslight.i2p (AnonUser) - 2020-08-05 01:13 +0000
    Re: long live return code 444 anon <anon@anon.com> - 2020-08-05 19:01 +0000

#7 — long live return code 444

FromAnonymous <poster@anon.com>
Date2020-07-26 15:58 -0700
Subjectlong live return code 444
Message-ID<opsec.703.16vmh7@anon.com>
https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return

Block certain kinds of ddos at application level simply by dropping the connection with your reverse http proxy. works like a charm, simpler and more effective than lowlevel blocking attempts (like with iptables).

You can base the criteria which connection to drop on all kind of shit like user-agent, url, request method or any other var you can access. Also you can use combinations of them to fingerprint annoying bots.

And nginxs non standard return code 444 simply drops the connection without giving any answer, thus not wasting any more server resoources like cpu time or open sockets or giving more information to potential attackers. 

Fucking awesome ! nginx just rocks.

-- 
Posted on def2

[toc] | [next] | [standalone]


#8

Fromretro.guy@rocksolidbbs.com (Retro Guy)
Date2020-07-27 08:20 +0000
Message-ID<4fbc28ca82cf5d7628dd03beef312c86$1@www.novabbs.com>
In reply to#7
Anonymous wrote:

> https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return

> Block certain kinds of ddos at application level simply by dropping the connection with your reverse http proxy. works like a charm, simpler and more effective than lowlevel blocking attempts (like with iptables).

I use zones to limit requests and a few other ways of blocking. It works great. I wasn't familiar with the code you mention here, I need to check it out.

> Fucking awesome ! nginx just rocks.

Been really impressed with nginx so far!

Retro Guy

-- 
Posted on: Rocksolid Light
www.novabbs.com

[toc] | [prev] | [next] | [standalone]


#9 — Zones

FromAnonymous <poster@anon.com>
Date2020-07-27 11:25 -0700
SubjectZones
Message-ID<opsec.705.1js4ni@anon.com>
In reply to#7
>I use zones to limit requests

I looked at zones as well, but if you cannot use the ip (because it is a service on tor), than your are kind of stuck in some situations.
In my case I used a combination of the URL and the posting method to get rid of some annoying script kids.

-- 
Posted on def2

[toc] | [prev] | [next] | [standalone]


#17 — Re: Zones

Fromretro.guy@rocksolidbbs.com (Retro Guy)
Date2020-08-05 04:51 +0000
SubjectRe: Zones
Message-ID<dae9ba9695017ce0efcbee5554f12fab$1@www.novabbs.com>
In reply to#9
Anonymous wrote:

>>I use zones to limit requests

> I looked at zones as well, but if you cannot use the ip (because it is a service on tor), than your are kind of stuck in some situations.
> In my case I used a combination of the URL and the posting method to get rid of some annoying script kids.

It's nice to be able to throttle spiders, and it's not difficult if you have an ip address. Even i2p provides a specific ip for each identity, so it works. With tor, you can't really throttle without throttling everyone.

-- 
Posted on: novaBBS
www.novabbs.com

[toc] | [prev] | [next] | [standalone]


#15 — nginx is great

FromAnonymous <poster@anon.com>
Date2020-08-01 15:13 -0700
Subjectnginx is great
Message-ID<opsec.711.2dzng2@anon.com>
In reply to#7
nginx is great for sure, and it also comes with some pitfalls (concerning the configuration). the nginx team was so fed up with those that they put together a page dedicated to what not to do. It's really great and it saved me some headaches already:
https://www.nginx.com/resources/wiki/start/topics/tutorials/config_pitfalls/#passing-uncontrolled-requests-to-php
Also good to read:
https://www.nginx.com/resources/wiki/start/topics/depth/ifisevil/
https://agentzh.blogspot.com/2011/03/how-nginx-location-if-works.html

-- 
Posted on def2

[toc] | [prev] | [next] | [standalone]


#16 — Re: nginx is great

FromAnonUser@rslight.i2p (AnonUser)
Date2020-08-05 01:13 +0000
SubjectRe: nginx is great
Message-ID<baa1f124146a0b8ca5f51f388e28258b$1@rslight.i2p>
In reply to#15
Anonymous wrote:

> nginx is great for sure, and it also comes with some pitfalls (concerning the configuration). the nginx team was so fed up with those that they put together a page dedicated to what not to do. It's really great and it saved me some headaches already:
> https://www.nginx.com/resources/wiki/start/topics/tutorials/config_pitfalls/#passing-uncontrolled-requests-to-php

Interesting, and pretty nicely written. Standarize and simplify are good goals.

> Also good to read:
> https://www.nginx.com/resources/wiki/start/topics/depth/ifisevil/
> https://agentzh.blogspot.com/2011/03/how-nginx-location-if-works.html

Haven't checked these out yet.

-- 
Posted on: Rocksolid Light
rslight.i2p

[toc] | [prev] | [next] | [standalone]


#18

Fromanon <anon@anon.com>
Date2020-08-05 19:01 +0000
Message-ID<95b9482bebb165b27724bb50470eadf4@def4>
In reply to#7
>With tor, you can't really throttle without throttling everyone.

Yes, and with the method mentioned in the op you can actually kill the buggers connections instead of just throttling.

-- 
Posted on def4

[toc] | [prev] | [standalone]


Back to top | Article view | rocksolid.shared.security


csiph-web