I am looking at a website under seige by DDOS attacks and now what the attackers are doing is hitting the URL and putting some random characters on the end that change every time.

One form is this:
The other form is this:

The difference is 1 versus 2 β€œ/” characters and of course the random number at the end.

What kind of rule blocks this?

Edit: Check this

Thanks. That was helpful. I created one that’s working great, not just on that random nonsense, but anything else depending on referral url and/or a few other items.

