Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > rocksolid.shared.security > #7 > unrolled thread
| Started by | Anonymous <poster@anon.com> |
|---|---|
| First post | 2020-07-26 15:58 -0700 |
| Last post | 2020-08-05 19:01 +0000 |
| Articles | 7 — 4 participants |
Back to article view | Back to rocksolid.shared.security
long live return code 444 Anonymous <poster@anon.com> - 2020-07-26 15:58 -0700
Re: long live return code 444 retro.guy@rocksolidbbs.com (Retro Guy) - 2020-07-27 08:20 +0000
Zones Anonymous <poster@anon.com> - 2020-07-27 11:25 -0700
Re: Zones retro.guy@rocksolidbbs.com (Retro Guy) - 2020-08-05 04:51 +0000
nginx is great Anonymous <poster@anon.com> - 2020-08-01 15:13 -0700
Re: nginx is great AnonUser@rslight.i2p (AnonUser) - 2020-08-05 01:13 +0000
Re: long live return code 444 anon <anon@anon.com> - 2020-08-05 19:01 +0000
| From | Anonymous <poster@anon.com> |
|---|---|
| Date | 2020-07-26 15:58 -0700 |
| Subject | long live return code 444 |
| Message-ID | <opsec.703.16vmh7@anon.com> |
https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return Block certain kinds of ddos at application level simply by dropping the connection with your reverse http proxy. works like a charm, simpler and more effective than lowlevel blocking attempts (like with iptables). You can base the criteria which connection to drop on all kind of shit like user-agent, url, request method or any other var you can access. Also you can use combinations of them to fingerprint annoying bots. And nginxs non standard return code 444 simply drops the connection without giving any answer, thus not wasting any more server resoources like cpu time or open sockets or giving more information to potential attackers. Fucking awesome ! nginx just rocks. -- Posted on def2
[toc] | [next] | [standalone]
| From | retro.guy@rocksolidbbs.com (Retro Guy) |
|---|---|
| Date | 2020-07-27 08:20 +0000 |
| Message-ID | <4fbc28ca82cf5d7628dd03beef312c86$1@www.novabbs.com> |
| In reply to | #7 |
Anonymous wrote: > https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return > Block certain kinds of ddos at application level simply by dropping the connection with your reverse http proxy. works like a charm, simpler and more effective than lowlevel blocking attempts (like with iptables). I use zones to limit requests and a few other ways of blocking. It works great. I wasn't familiar with the code you mention here, I need to check it out. > Fucking awesome ! nginx just rocks. Been really impressed with nginx so far! Retro Guy -- Posted on: Rocksolid Light www.novabbs.com
[toc] | [prev] | [next] | [standalone]
| From | Anonymous <poster@anon.com> |
|---|---|
| Date | 2020-07-27 11:25 -0700 |
| Subject | Zones |
| Message-ID | <opsec.705.1js4ni@anon.com> |
| In reply to | #7 |
>I use zones to limit requests I looked at zones as well, but if you cannot use the ip (because it is a service on tor), than your are kind of stuck in some situations. In my case I used a combination of the URL and the posting method to get rid of some annoying script kids. -- Posted on def2
[toc] | [prev] | [next] | [standalone]
| From | retro.guy@rocksolidbbs.com (Retro Guy) |
|---|---|
| Date | 2020-08-05 04:51 +0000 |
| Subject | Re: Zones |
| Message-ID | <dae9ba9695017ce0efcbee5554f12fab$1@www.novabbs.com> |
| In reply to | #9 |
Anonymous wrote: >>I use zones to limit requests > I looked at zones as well, but if you cannot use the ip (because it is a service on tor), than your are kind of stuck in some situations. > In my case I used a combination of the URL and the posting method to get rid of some annoying script kids. It's nice to be able to throttle spiders, and it's not difficult if you have an ip address. Even i2p provides a specific ip for each identity, so it works. With tor, you can't really throttle without throttling everyone. -- Posted on: novaBBS www.novabbs.com
[toc] | [prev] | [next] | [standalone]
| From | Anonymous <poster@anon.com> |
|---|---|
| Date | 2020-08-01 15:13 -0700 |
| Subject | nginx is great |
| Message-ID | <opsec.711.2dzng2@anon.com> |
| In reply to | #7 |
nginx is great for sure, and it also comes with some pitfalls (concerning the configuration). the nginx team was so fed up with those that they put together a page dedicated to what not to do. It's really great and it saved me some headaches already: https://www.nginx.com/resources/wiki/start/topics/tutorials/config_pitfalls/#passing-uncontrolled-requests-to-php Also good to read: https://www.nginx.com/resources/wiki/start/topics/depth/ifisevil/ https://agentzh.blogspot.com/2011/03/how-nginx-location-if-works.html -- Posted on def2
[toc] | [prev] | [next] | [standalone]
| From | AnonUser@rslight.i2p (AnonUser) |
|---|---|
| Date | 2020-08-05 01:13 +0000 |
| Subject | Re: nginx is great |
| Message-ID | <baa1f124146a0b8ca5f51f388e28258b$1@rslight.i2p> |
| In reply to | #15 |
Anonymous wrote: > nginx is great for sure, and it also comes with some pitfalls (concerning the configuration). the nginx team was so fed up with those that they put together a page dedicated to what not to do. It's really great and it saved me some headaches already: > https://www.nginx.com/resources/wiki/start/topics/tutorials/config_pitfalls/#passing-uncontrolled-requests-to-php Interesting, and pretty nicely written. Standarize and simplify are good goals. > Also good to read: > https://www.nginx.com/resources/wiki/start/topics/depth/ifisevil/ > https://agentzh.blogspot.com/2011/03/how-nginx-location-if-works.html Haven't checked these out yet. -- Posted on: Rocksolid Light rslight.i2p
[toc] | [prev] | [next] | [standalone]
| From | anon <anon@anon.com> |
|---|---|
| Date | 2020-08-05 19:01 +0000 |
| Message-ID | <95b9482bebb165b27724bb50470eadf4@def4> |
| In reply to | #7 |
>With tor, you can't really throttle without throttling everyone. Yes, and with the method mentioned in the op you can actually kill the buggers connections instead of just throttling. -- Posted on def4
[toc] | [prev] | [standalone]
Back to top | Article view | rocksolid.shared.security
csiph-web