Some clients have mentioned their sites are running a little slow today and upon investigation I can see that the /usr/local/apache/logs/access_log is going mental with these types of entries below.....like thousands every minute from different ip's.
My server load is fine. Idle is 98% most times. mod_qos is not picking anything up in error_log apart from the occasional mod_qos entry.
Could this be another type of attack?
Should I be blocking anyb ip's registering in the access_log with +20 attempts?
My server load is fine. Idle is 98% most times. mod_qos is not picking anything up in error_log apart from the occasional mod_qos entry.
Could this be another type of attack?
Should I be blocking anyb ip's registering in the access_log with +20 attempts?
Code:
208.180.198.235 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
208.180.198.235 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
176.33.110.202 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
176.33.110.202 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
78.93.53.146 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
78.93.53.146 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
87.239.28.229 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
87.239.28.229 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
213.87.143.113 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
213.87.143.113 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
151.240.131.199 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
151.240.131.199 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
41.254.5.34 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
41.254.5.34 - - [19/Feb/2014:14:03:42 +0000] "-" 408 -
71.189.193.181 - - [19/Feb/2014:14:03:43 +0000] "-" 408 -
71.189.193.181 - - [19/Feb/2014:14:03:43 +0000] "-" 408 -
71.175.133.235 - - [19/Feb/2014:14:03:43 +0000] "-" 408 -