Chinese DOS Attack?
Wow it seems that there was a massive denial of service attack launched on this site today from China. Some spam bot was submitting HTTP requests with huge headers to bogus URLs. Not sure if this correlates to some bug in IIS but that would make sense. In any case this site is hosted on a very fast server on a very fast line so most people probably didn’t even notice the attack. Needless to say the offending IP range has been blocked at the firewall which returned everything to normal. The range, in case anyone is curious, is 220.181.0.0/16 with the actual IPs being 220.181.34.0 given that a /24 block is probably more responsible but because so few non-spammer visits come from China I really don’t care if I block them out.
Leave a Reply