DDOS

The most obvious indicator is the spike of ips, either from same ip or from different ips.

Indicator from the log

Prevention

see detail - Bo Cyber Logbook - Metigation

Bypassing CDN

Your CDN might serve a cached URL at /products, but if an attacker appends the query with a random string like /products?a=abcd, your CDN cannot serve the cached page, and the origin server is forced to respond. Similarly, changing user agents, spoofing referrer pages, or launching requests from diverse geographic regions can help attackers evade WAF filtering rules.

Entended Readings:


Last Modified: 2025-12-28
Have Questions? Shoot me a text » Linkedin