Skip to content

Introduce nginx hardening rules to avoid the service being flooded with spam requests #74

@warunawickramasingha

Description

@warunawickramasingha

It has been observed that the production errorreporter service is being flooded with bulks of spamy GET and POST requests most of the time and resulting(luckily) in 404 / 403 to paths like below.

GET /.env
GET /.env.production
GET /.git/config
GET /.ssh/id_rsa
GET /.aws/credentials
GET /.env.local
etc

Such requests usually come as bursts in DDoS fashion and are originating from malicious bots/crawlers from the internet. These can be mitigated by having better nginx hardening rules and rate limits.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestsecurityTo be associated with anything related to Security

    Type

    No type

    Projects

    Status

    Backlog

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions