阿里云的流量清洗方式我也是醉了 - V2EX
Recommended Services
Amazon Web Services
LeanCloud
New Relic
ClearDB
kungfuchicken

阿里云的流量清洗方式我也是醉了

  •  
  •   kungfuchicken Dec 18, 2015 5514 views
    This topic created in 3799 days ago, the information mentioned may be changed or developed.

    今天煎蛋的 CDN 域名触发了流量清洗,清洗方式真是简单粗暴完全不区分的文件格式的,直接简单粗暴的把 JS 文件的内容替换成了下面的 HTML 代码
    <html><head><meta http-equiv="refresh" cOntent="1; url='http://42.120.48.125/rd.s/Dvr00cDMFetOtGHs?url=http://42.120.48.125/static/js/tucao.js?v=20150930'"><link rel="shortcut icon" href="data:image/x-icon;," type="image/x-icon"></head></html>
    然后导致网站前台 JS 功能全挂...跑去 CDN 面板关了 CC 防护才消停。

    10 replies    2015-12-25 21:36:01 +08:00
    yutian2211
        1
    yutian2211  
       Dec 18, 2015
    煎蛋 er 前来报道
    BOYPT
        2
    BOYPT  
       Dec 18, 2015
    阿里云系列虽然看起来很多产品,不过也都是赶鸭子上架的吧,今年一年内突然就上了一大堆。
    虽然说很多是开源的架构,实际的运营稳定性着实不让人放心。
    tinyproxy
        3
    tinyproxy  
       Dec 18, 2015 via iPhone
    我上一次手动触发流量清洗是因为用 aria2c 拉服务器的东东,然后。。。老板收到短信以为我们又被攻击了
    fqzz
        4
    fqzz  
       Dec 19, 2015
    同意,还经常误报,简直不能忍
    huage
        5
    huage  
       Dec 19, 2015
    阿里今年上线的许多产品可能真的不太成熟,所以阿里方面应该对用户作出适当的补偿
    aliyun123
        6
    aliyun123  
       Dec 21, 2015
    您好,基础防护中的 CC 防护是默认关闭的,如果您手工开启会提示打开 7 层 DDOS 防护的,同时我们提供了增值服务安全网络,安全网络提供了增强 CC 防御,可解决这个问题,您可以参考下,如果还有疑问可以提交在线工单我们核实。
    kungfuchicken
        7
    kungfuchicken  
    OP
       Dec 21, 2015 via Android
    @aliyun123 我说的不是 cc 防护的问题,而是你们防火墙处理 cc 请求的方式太简单粗暴
    chousb
        8
    chousb  
       Dec 24, 2015
    保姆式的安全,谁用谁知道,毕竟坑就在那里。
    helloworld01
        9
    helloworld01  
       Dec 25, 2015
    @kungfuchicken 简单粗暴?!求举个例子
    kungfuchicken
        10
    kungfuchicken  
    OP
       Dec 25, 2015
    @helloworld01 主题里面我已经说的很清楚了
    About     Help     Advertise     Blog     API     FAQ     Solana     5376 Online   Highest 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 48ms UTC 05:48 PVG 13:48 LAX 22:48 JFK 01:48
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86