Quantcast
Channel: HAProxy community - Latest topics
Viewing all articles
Browse latest Browse all 4849

How to distinguish Probe GET from Legit GET requests

$
0
0

Is it possible to distinguish between unwanted GET requests with path-names but without website URL and normal/legitimate GET requests containing Full URL names?

Reason for this inquiry is that I see a behavior pattern in my HAProxy logs the starts with GET requests without a URL name, followed flooding of GET requests probing(guessing) all kinds of path names related to apps like WP / Wiki / PHPmyAdmin, Etc…

Many times, this behavior is repeated in a coordinated manner from numerous different IP addresses almost as if the first IP informs the others to join the scan(probing).

My goal is as follows:
REJECTGET /pw/Main_Page HTTP/1.1
ACCEPT “GET https://mysite.com/pw/Main_Page HTTP/1.1”

Is this something feasible with HAProxy ACLs?

P.S.
I am not worried about googlebot or other crawlers not being able to index my site.

Thank you.

1 post - 1 participant

Read full topic


Viewing all articles
Browse latest Browse all 4849

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>