Replies: 0
I have a website with WordFence that is under attack. It receives about 900 search requests per minutes (sometimes 20 per second) that do not originating from the website itself. Example below.
Wordfence is set to throttle to 120 per minute, which apparently doesn’t work here.
Why doesn’t WordFence block these IP addresses?
As soon as I block the IP’s in htaccess, the attack continues with new IP’s.
Thanks
JP
165.231.225.11 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=m+0+9+8 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.182 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=a+9+0+y HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.110 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=8+d+x+7 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.230 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=w+0+n+w HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.110 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=t+o+6+y HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.132 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=o+z+c+5 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.214.44.104 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=y+2+q+m HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.230 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=8+b+q+y HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.230 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=j+5+a+t HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
165.231.225.11 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=i+4+1+9 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.182 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=m+2+s+q HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
165.231.225.11 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=a+1+5+r HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.182 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=4+u+4+f HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.110 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=u+j+e+7 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.230 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=6+z+f+f HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.132 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=8+h+1+8 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
196.242.6.148 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=4+i+r+q HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.214.44.104 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=o+i+5+t HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
107.150.70.110 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=r+m+j+8 HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.214.44.104 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=w+a+5+f HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.132 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=m+w+q+t HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"
181.215.16.230 - - [28/Mar/2021:05:10:22 +0200] "GET /?s=6+i+n+p HTTP/1.1" 403 202 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36"