DiscussionSLA

[BUG] DDOS Makes Fake Resources Lists

Published 7 months ago

# SafeLine WAF
# โœ… done
# ๐Ÿž bug

Published 7 months ago

profile_photo

Bulkahov

Updated a year ago

0

After a attack of ddos or scanners. Safeline take as resource list the urls that scanned the botnet/bots as source list and it fulls the list of total assets.

In this case we not have wordpress also we not have several lot of urls detected
image.png
image.png
image.png

profile_photo

Bulkahov

Updated a year ago

0

Run mode: Defense , All in Strict Mode.

profile_photo

Bulkahov

Updated a year ago

0

I made this post here because on github all is on chinese and i dont want to bother, if is wrong section, please delete the post.

profile_photo

Monster

Updated a year ago

0

Thanks for the feedback, I need to confirm first, are these pages returning 404?

profile_photo

Bulkahov

Updated a year ago

Yes, pages returning 404 but is marked as assets anyway

profile_photo

Monster

Updated a year ago

0

We have found a similar phenomenon before, where requests with an http status code other not match 200 will also be recorded. This problem has been fixed in version 6.0.3.

profile_photo

Bulkahov

Updated a year ago

0

I see only happends if i have the challenge active, maybe is that, i will try to reproduce error on a fresh domain

profile_photo

Bulkahov

Updated a year ago

0

Yes, i started with a normal website on strict mode and defense (not challenge) and attacked the website with random folders like /qa /am and custom files like text.txt and yeah it making false assets but i see only happends on nginx, im testing another but yeah seems a little issue

profile_photo

Bulkahov

Updated a year ago

0

image.png

profile_photo

zhiduopc

Updated 8 months ago

0

This is supposed to be layer 7, DDOS doesn't do scans and L7's

profile_photo

Deleted User

Updated 8 months ago

0

there must be improvement here!