DevSecOps

Tags 1 follower

Follow from the Fediverse

Follow #devsecops from Mastodon or any other Fediverse app and its public posts arrive in your timeline. No vutuv account needed.

@devsecops@tags.vutuv.de

Your address is used once, to send you to your own server's follow dialog. It is never stored here.

The most endorsed users with this tag

Posts with this tag

1 post

Filters
Andreu Casablanca 🐀 @castarco hachyderm.io

We tweaked our firewalls and our Anubis rules. The attack persisted, but it was contained.

We also scaled our systems to avoid more accidental downtimes caused by these scrapping operations… Then the attackers scaled up their scrapping campaign, and found new ways to bypass our #Anubis config.

This past night I managed to come up with a stricter configuration that blocks virtually all of them (I don’t know for how long this will last, though).

As of now, our Anubis instance is stopping around 40 requests per second.

I know that this is “nothing” for anyone working in very big systems, but bear in mind that this is after I already blocked around 3.5% of all the IPv4 addresses existing, and it accounts for 95% of our traffic. For every legitimate request we have, we have 19 that come from bots.

P.S.: In an ideal world, I would openly share the rules I found to work well… Unfortunately I don’t think that would be a good idea. I don’t want to make the scrappers’ job any easier.

FuckAI Fuck_AI Devops DevSecOps
A graph, plotting the number of requests reaching our Forgejo instance. One can see how around 2am (Berlin timezone), that number collapses to zero, after some improvements have been applied to our Anubis configuration.
A graph:
- in red, the amount  of "challenges" issues by Anubis
- in blue, the amount of "challenges" validated by Anubis

the graph shows how around 2am (Berlin timezone), Anubis stopped validating bots requests
A graph:
- in blue, the amount  of "challenges" issues by Anubis
- in red, the amount of requests directly allowed by Anubis
- in green, the amount of requests directly denied by Anubis

the graph shows seemingly random fluctuations in requests per second that reached our systems