A website has been under script-driven DDoS attack since two days ago, peaking this morning with over 20,000 malicious requests and nearly 10GB of traffic consumed in hours, using more than half of the monthly CDN free quota. The attacked IP ranges have been blacklisted. If the quota is exhausted, domestic traffic will be redirected to an overseas line, causing slower load times or regional inaccessibility. The owner asks attackers to stop. An automatic detection and blacklist-updating script has since been deployed to counter ongoing sporadic attacks.
Bad news: We’re running dry!
【 Battle Update! 】 Good morning, good afternoon, good evening, everyone! Since the day before yesterday, we've been under continuous malicious attacks from multiple scripts. This morning it peaked, with over 200,000 malicious requests in just a few hours, consuming nearly 10GB of bandwidth. We’ve already added these IP ranges to the blacklist:
Since these requests were consuming around 100MB every 5 minutes, they didn’t trigger the CDN's 5-minute 200MB cap limit, and with me sleeping through the weekend morning, the monthly CDN free quota has already been more than half used up.
If the attacks continue until the CDN free quota is exhausted, we’ll redirect all domestic traffic to an overseas line to lie low for a while. At that point, things like the site loading much slower and being inaccessible from some regions may happen. Please bear with us.
Finally, to the script masters, please have mercy.
Not a drop left
Follow-up
Since the malicious attacks are still continuing sporadically, I’ve started working on and enabled a script to automatically detect and update the CDN blacklist. This time, I might actually get a good night's sleep.