本帖最后由 宝塔用户_jajsgl 于 2024-12-23 18:22 编辑
为了能快速了解并处理您的问题,请提供以下基础信息: 问题描述:全都是如下的访问链接,头部是固定的,这是哪种攻击呢?能不能针对“postreview”之类的关键词进行URL屏蔽呢?提前谢过各路大神 相关截图(日志、错误):"HEAD /home.php?ac=follow&fuid=78622&hash=41c15d7b&mod=spacecp&op=add HTTP/1.1" 200 0 ………… "HEAD /forum.php?action=postreview&do=support&hash=6419bb4e&mod=misc&pid=3054265&tid=49992 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=against&hash=f6ac8d87&mod=misc&pid=3012543&tid=49359 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=support&hash=e3beb046&mod=misc&pid=3060363&tid=18459 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=support&hash=ca7ac6a0&mod=misc&pid=2961995&tid=40899 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=against&hash=5dbb6134&mod=misc&pid=1123259&tid=26906 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=support&hash=e3beb046&mod=misc&pid=3060106&tid=18459 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=support&hash=e3beb046&mod=misc&pid=3060789&tid=18459 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=support&hash=52b9f2f7&mod=misc&pid=2807752&tid=47585 HTTP/1.1" 200 0 "………… "HEAD /forum.php?action=postreview&do=against&hash=69b258a2&mod=misc&pid=2815931&tid=47828 HTTP/1.1" 200 0 "…………
基本上就是以下这些类型,这些可以直接用WAF进行屏蔽吗?
/connect.php?do=support&hash /connect.php?do=subtract&hash /connect.php?do=add&hash /connect.php?do=against&hash /connect.php?formhash /connect.php?idtype=pid&mid=namepost /forum.php?do=support&action=postreview /forum.php?do=support&action=postreview /forum.php?action=postreview&do=against&hash /forum.php?action=postreview&do=support&hash /forum.php?action=recommend&do=add&hash /forum.php?action=recommend&do=subtract&hash /forum.php?action=reply&extra=page /forum.php?action=reply&mod=post /forum.php?mod=misc&action=postreview&do=against&tid /forum.php?mod=misc&action=postreview&do=support&tid
|
|