Hello,
my site is under attack for a week. I enabled captcha challenge for every country code. but still the attackers (bots) can go through to my website. how is that possible ? I tried setup testcookie & recaptcha for nginx but I can’t solve this attack. the attackers using layer7 method for attacking my website.
Im using Cloudflare free plan. why Cloudflare doesn’t protect us ?
I think the attacker using proxy for IP spoof every IP adress does two request I can’t rate limit this. please help me.
nginx access log file.
38.121.155.127 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43440 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A" "138.121.155.127"
103.241.227.108 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" "103.241.227.108"
89.38.97.65 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0" "89.38.97.65"
185.139.68.154 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43440 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25" "185.139.68.154"
241.200.239.225 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US" "241.200.239.225"
100.24.54.138 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25" "100.24.54.138"
192.207.200.252 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1)" "192.207.200.252"
95.65.1.200 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Linux; Android 7.1.1; G8231 Build/41.2.A.0.219; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/59.0.3071.125 Mobile Safari/537.36" "95.65.1.200"
139.5.71.220 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1)" "139.5.71.220"
68.183.152.170 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Linux; Android 4.4.2; Nexus 4 Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.114 Mobile Safari/537.36" "68.183.152.170"
139.5.71.233 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US" "139.5.71.233"
191.189.73.51 - - [19/Jan/2019:19:26:30 +0000] "GET / HTTP/1.1" 200 984 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36" "191.189.73.51"
93.41.192.228 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (PlayStation 4 3.11) AppleWebKit/537.73 (KHTML, like Gecko)" "93.41.192.228"
185.139.68.154 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25" "185.139.68.154"
62.201.220.50 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43430 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "62.201.220.50"
252.232.32.94 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US" "252.232.32.94"
77.120.40.54 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/5.0 (Linux; Android 7.1.1; G8231 Build/41.2.A.0.219; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/59.0.3071.125 Mobile Safari/537.36" "77.120.40.54"
192.207.200.252 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43439 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1)" "192.207.200.252"
95.0.235.61 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/5.0 (Linux; Android 5.1; AFTS Build/LMY47O) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/41.99900.2250.0242 Safari/537.36" "95.0.235.61"
191.102.104.34 - - [19/Jan/2019:19:26:31 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25" "191.102.104.34"
209.33.120.66 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0" "209.33.120.66"
81.161.196.5 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US" "81.161.196.5"
200.216.227.141 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43442 "-" "Mozilla/5.0 (Linux; Android 4.4.2; Nexus 4 Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.114 Mobile Safari/537.36" "200.216.227.141"
241.224.235.112 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (compatible; MSIE 10.0; Windows Phone 8.0; Trident/6.0; IEMobile/10.0; ARM; Touch; NOKIA; Lumia 920)" "241.224.235.112"
81.162.195.215 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (iPhone9,4; U; CPU iPhone OS 10_0_1 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A403 Safari/602.1" "81.162.195.215"
81.162.195.215 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (iPhone9,4; U; CPU iPhone OS 10_0_1 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A403 Safari/602.1" "81.162.195.215"
243.74.93.40 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0" "243.74.93.40"
147.91.111.130 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43440 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0" "147.91.111.130"
91.227.183.222 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (CrKey armv7l 1.5.16041) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.0 Safari/537.36" "91.227.183.222"
109.86.199.155 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43429 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0" "109.86.199.155"
41.162.76.170 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "41.162.76.170"
35.183.230.83 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43439 "-" "Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14" "35.183.230.83"
176.123.129.14 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43440 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0" "176.123.129.14"
194.213.212.57 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; WOW64; Trident/4.0; SLCC1)" "194.213.212.57"
185.199.87.235 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43440 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; XBOX_ONE_ED) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36 Edge/14.14393" "185.199.87.235"
68.183.179.243 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43440 "-" "Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14" "68.183.179.243"
240.187.54.149 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43429 "-" "Mozilla/5.0 (Linux; Android 7.0; SM-G892A Build/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Mobile Safari/537.36" "240.187.54.149"
170.245.59.250 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43429 "-" "Mozilla/5.0 (iPad; CPU OS 6_0 like Mac OS X) AppleWebKit/536.26 (KHTML, like Gecko) Version/6.0 Mobile/10A5376e Safari/8536.25" "170.245.59.250"
78.61.157.167 - - [19/Jan/2019:19:26:32 +0000] "GET / HTTP/1.1" 200 43441 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0" "78.61.157.167"