{"id":278896,"date":"2023-09-19T22:16:57","date_gmt":"2023-09-19T20:16:57","guid":{"rendered":"https:\/\/blog.wedos.cz\/?p=278896"},"modified":"2023-09-19T22:17:06","modified_gmt":"2023-09-19T20:17:06","slug":"waf-report-z-wedos-global-protection-za-srpen-2023","status":"publish","type":"post","link":"https:\/\/blog.wedos.com\/cs\/waf-report-z-wedos-global-protection-za-srpen-2023","title":{"rendered":"WAF report z WEDOS Global Protection za srpen 2023"},"content":{"rendered":"\n<p>Druh\u00fd pr\u00e1zdninov\u00fd m\u011bs\u00edc rozhodn\u011b nebyl \u010das odpo\u010dinku. Jednak jsme pokra\u010dovali v budov\u00e1n\u00ed WEDOS Global, ale tak\u00e9 museli \u0159e\u0161it vzr\u016fstaj\u00edc\u00ed aktivitu n\u011bkter\u00fdch botnet\u016f, kter\u00e9 prim\u00e1rn\u011b nem\u011bly v \u00famyslu prov\u00e1d\u011bt DDoS \u00fatoky, ale hledaly zranitelnosti. Kdy\u017e se pak sesypaly v jeden okam\u017eik jejich requesty, tak n\u011bkter\u00e9 na\u0161e z\u00e1kazn\u00edky dok\u00e1zaly nemile potr\u00e1pit.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>V posledn\u00edch m\u011bs\u00edc\u00edch obecn\u011b roste po\u010det \u00fatok\u016f SQLi. Tyto \u00fatoky v mal\u00e9 m\u00ed\u0159e jedou prakticky nep\u0159etr\u017eit\u011b a \u00fato\u010d\u00edc\u00ed botnety se sna\u017e\u00ed b\u00fdt nen\u00e1padn\u00e9. V\u011bt\u0161inou je odhal\u00edme d\u00edky agregaci dat z v\u00edce jak stovek tis\u00edc dom\u00e9n, kter\u00e9 u n\u00e1s hostuj\u00ed. Nicm\u00e9n\u011b v srpnu to \u00fato\u010dn\u00edci rozjeli opravdu ve velk\u00e9m a jedna IP adresa zkusila za den t\u0159eba i n\u011bkolik milion\u016f request\u016f. <\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je to SQLi?<\/strong><\/p>\n\n\n\n<p>SQLi (SQL injection), je typ \u00fatoku sm\u011b\u0159uj\u00edc\u00ed na datab\u00e1ze. P\u0159i tomto \u00fatoku se nepovolen\u00e9 SQL p\u0159\u00edkazy vkl\u00e1daj\u00ed do vstupn\u00edch pol\u00ed aplikace s c\u00edlem manipulovat nebo z\u00edskat p\u0159\u00edstup k datab\u00e1zi. Kdy\u017e aplikace neov\u011b\u0159uje a nespr\u00e1vn\u011b zpracov\u00e1v\u00e1 u\u017eivatelsk\u00fd vstup, m\u016f\u017ee to \u00fato\u010dn\u00edkovi umo\u017enit spustit vlastn\u00ed SQL k\u00f3d v datab\u00e1zi. D\u016fsledky SQLi mohou zahrnovat naru\u0161en\u00ed integrity dat, ztr\u00e1tu dat, z\u00edsk\u00e1n\u00ed citliv\u00fdch informac\u00ed a v n\u011bkter\u00fdch p\u0159\u00edpadech i \u00fapln\u00e9 ovl\u00e1dnut\u00ed datab\u00e1ze \u010di hostitelsk\u00e9ho syst\u00e9mu.<\/p>\n<\/div><\/div>\n\n\n\n<p>Do \u00fatok\u016f se nav\u00edc ke konci srpna ve velk\u00e9m zapojili i IP adresy z \u010c\u00edny. Po detailn\u011bj\u0161\u00ed anal\u00fdze jsme zjistili, \u017ee se jedn\u00e1 o p\u0159\u00edstupy p\u0159ev\u00e1\u017en\u011b z mobiln\u00edch za\u0159\u00edzen\u00ed. Z\u0159ejm\u011b se jedn\u00e1 o n\u011bjakou rozs\u00e1hlej\u0161\u00ed infekci malware. V \u010c\u00edn\u011b se hojn\u011b vyu\u017e\u00edv\u00e1 IPv6, tak\u017ee je t\u0159eba d\u00e1vat si pozor i na to. Na\u0161t\u011bst\u00ed na \u00fatoky p\u0159es IPv6 jsme u\u017e roky dob\u0159e p\u0159ipraveni jak softwarov\u011b, tak i hardwarov\u011b.<\/p>\n\n\n\n<p>Koncem srpna za\u010dali ru\u0161t\u00ed hacke\u0159i \u00fato\u010dit na \u010desk\u00e9 finan\u010dn\u00ed instituce. Situaci jsme detailn\u011b monitorovali. Z\u00e1kazn\u00edk\u016fm z \u0159ad finan\u010dn\u00edch instituc\u00ed, kte\u0159\u00ed maj\u00ed slu\u017eby u n\u00e1s, se \u00fato\u010dn\u00edci vyhnuli. Naposledy jsme \u00fasp\u011b\u0161n\u011b eliminovali \u00fatoky t\u00e9to skupiny p\u0159i prezidentsk\u00fdch volb\u00e1ch, kdy na jednoho na\u0161eho z\u00e1kazn\u00edka ne\u00fasp\u011b\u0161n\u011b \u00fato\u010dili b\u011bhem prvn\u00edho kola. V druh\u00e9m u\u017e jej vynechali. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WEDOS Global<\/h2>\n\n\n\n<p>WEDOS Global je na\u0161e celosv\u011btov\u00e1 infrastruktura postaven\u00e1 na BGP Anycast a reverzn\u00edch proxy. Hlavn\u00ed my\u0161lenka je stahovat si p\u0159es BGP n\u00e1v\u0161t\u011bvnost z okol\u00ed do lokalit, kde m\u00e1me hardware, a tam provoz filtrovat, cachovat odpov\u011bdi atd. D\u00edky tomu dok\u00e1\u017eeme odolat i velmi siln\u00fdm DDoS \u00fatok\u016fm, proto\u017ee jejich nejv\u011bt\u0161\u00ed s\u00edla se st\u00e1v\u00e1 jejich slabinou. <\/p>\n\n\n\n<p>Aktu\u00e1ln\u011b m\u00e1me na\u0161e vlastn\u00ed fyzick\u00e9 servery ve 24 lokalit\u00e1ch. V ka\u017ed\u00e9 minim\u00e1ln\u011b 45 fyzick\u00fdch server\u016f a 2 switche a garantovanou konektivitu alespo\u0148 100 Gbps. Na dal\u0161\u00edch lokalit\u00e1ch pracujeme.<\/p>\n\n\n\n<p>Infrastrukturu pou\u017e\u00edv\u00e1me pro provoz Anycast DNS a na\u0161\u00ed slu\u017eby WEDOS Global Protection. Do budoucna p\u0159ibudou dal\u0161\u00ed slu\u017eby. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lokality<\/h3>\n\n\n\n<p>V srpnu jsme \u017e\u00e1dnou dal\u0161\u00ed lokalitu nespustili.<\/p>\n\n\n\n<p>Aktu\u00e1ln\u011b m\u00e1me rozpracovanou lokalitu <strong>Irsko (Dublin)<\/strong>, kde servery, switche a dal\u0161\u00ed hardware u\u017e m\u00e1me na m\u00edst\u011b, a nyn\u00ed \u010dek\u00e1me, a\u017e n\u00e1m v\u0161e zapoj\u00ed. <\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Pos\u00edlen\u00ed lokality Hlubok\u00e1 nad Vltavou (olej)<\/h4>\n\n\n\n<p>Jedna z d\u016fle\u017eit\u00fdch lokalit, kter\u00e1 odbavuje v\u011bt\u0161inu provozu v \u010cesku, je v na\u0161em datacentru WEDOS DC2. Jedn\u00e1 se o 90 fyzick\u00fdch server\u016f a 4 switche, kter\u00e9 jsou chlazeny v olejov\u00e9 l\u00e1zni. Jedn\u00e1 se o velice ekonomick\u00e9 a p\u0159itom ekologick\u00e9 \u0159e\u0161en\u00ed.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/IMG_1327-scaled.jpeg\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"768\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/IMG_1327-1024x768.jpeg\" alt=\"\" class=\"wp-image-277337 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/IMG_1327-1024x768.jpeg 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/IMG_1327-300x225.jpeg 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/IMG_1327-768x576.jpeg 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/IMG_1327-1536x1152.jpeg 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/IMG_1327-scaled.jpeg 2048w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/768;\" \/><\/a><\/figure>\n\n\n\n<p>U tohoto bodu jsme u v\u0161ech server\u016f nav\u00fd\u0161ili RAM. D\u016fvodem je p\u0159\u00edprava na testov\u00e1n\u00ed nov\u00fdch funkcionalit, kter\u00e9 WEDOS Global m\u016f\u017ee poskytovat, a lep\u0161\u00ed a d\u016fkladn\u011bj\u0161\u00ed anal\u00fdza provozu pro hled\u00e1n\u00ed a eliminaci kybernetick\u00fdch hrozeb v re\u00e1ln\u00e9m \u010dase.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Nov\u00e9 peeringy (propoje)<\/h3>\n\n\n\n<p>Aktu\u00e1ln\u011b jsou DNS WEDOS Global v TOP 25 na sv\u011bt\u011b, ale pokud chceme b\u00fdt je\u0161t\u011b lep\u0161\u00ed, tak je neust\u00e1l\u00e1 expanze a optimalizace na\u0161ich propoj\u016f nezbytn\u00e1. Nov\u00fdmi lokalitami se u\u017e moc d\u00e1l neposuneme. Tak\u017ee v u\u017e existuj\u00edc\u00edch lokalit\u00e1ch mus\u00edme hledat partnery \u010di IXP sdru\u017euj\u00edc\u00ed velk\u00fd po\u010det s\u00edt\u00ed anebo u\u017eivatel\u016f.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je to IXP peering?<\/strong><\/p>\n\n\n\n<p>Peering je dohoda mezi dv\u011bma poskytovateli internetov\u00fdch slu\u017eeb (ISP), kter\u00e1 umo\u017e\u0148uje, aby jejich s\u00ed\u0165ov\u00fd provoz proch\u00e1zel p\u0159\u00edmo mezi nimi, ani\u017e by musel proj\u00edt t\u0159et\u00ed stranou. <\/p>\n\n\n\n<p>Tento p\u0159\u00edm\u00fd p\u0159enos dat m\u016f\u017ee zv\u00fd\u0161it rychlost a spolehlivost internetov\u00e9ho p\u0159ipojen\u00ed, proto\u017ee \u00fadaje nemus\u00ed cestovat tak daleko nebo p\u0159es dal\u0161\u00ed r\u016fzn\u00e9 s\u00edt\u011b. Tak\u00e9 to m\u016f\u017ee sn\u00ed\u017eit n\u00e1klady, proto\u017ee ob\u011b strany se mohou vyhnout poplatk\u016fm, kter\u00e9 by jinak mohly platit t\u0159et\u00edm stran\u00e1m za p\u0159enos dat.<\/p>\n\n\n\n<p>Peering obvykle prob\u00edh\u00e1 na tzv. internetov\u00fdch v\u00fdm\u011bnn\u00fdch bodech (IXP), kde m\u016f\u017ee mnoho ISP propojit sv\u00e9 s\u00edt\u011b dohromady.<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">LINX<\/h4>\n\n\n\n<p>LINX (London Internet Exchange) je jeden z nejv\u011bt\u0161\u00edch internetov\u00fdch v\u00fdm\u011bnn\u00fdch bod\u016f (IXP) na sv\u011bt\u011b a nach\u00e1z\u00ed se v Lond\u00fdn\u011b (Velk\u00e1 Brit\u00e1nie), kde m\u00e1me tak\u00e9 jeden bod WEDOS Global. V srpnu se n\u00e1m poda\u0159ilo dot\u00e1hnout v\u0161e pot\u0159ebn\u00e9. V\u00edce v samostatn\u00e9m \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/nove-prime-propojeni-s-linx-posiluje-nasi-celosvetovou-infrastrukturu-wedos-global\" data-type=\"post\" data-id=\"262014\" target=\"_blank\" rel=\"noopener\">Nov\u00e9 p\u0159\u00edm\u00e9 propojen\u00ed s LINX posiluje na\u0161i celosv\u011btovou infrastrukturu WEDOS Global<\/a><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Dal\u0161\u00ed propoje<\/h4>\n\n\n\n<p>B\u011bhem letn\u00edch m\u011bs\u00edc\u016f jsme nezah\u00e1leli a \u00fasp\u011b\u0161n\u011b domluvili dal\u0161\u00ed propoje, kter\u00e9 postupn\u011b realizujeme v n\u00e1sleduj\u00edc\u00edch m\u011bs\u00edc\u00edch. Konkr\u00e9tn\u011b se jedn\u00e1 o \u0160v\u00e9dsko, Finsko (FICIX), Norsko a D\u00e1nsko.<\/p>\n\n\n\n<p>V Amsterdamu (Holandsko) domlouv\u00e1me propoj do AMS-IX (Amsterdam Internet Exchange), co\u017e je jeden z nejv\u011bt\u0161\u00edch v\u00fdm\u011bnn\u00fdch bod\u016f na sv\u011bt\u011b.<\/p>\n\n\n\n<p>Dal\u0161\u00ed, jako nap\u0159\u00edklad VIX.at, BIX.hu, SIX.sk a mnoho dal\u0161\u00edch, jsou v procesu.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"block-cf8be3ad-2224-472b-a4bd-d94ca3c9f21c\">Chcete se o WEDOS Global dozv\u011bd\u011bt v\u00edce?<\/h3>\n\n\n\n<p id=\"block-7a0e9de9-994a-4368-83c1-98199a50b21d\">Pokud v\u00e1s zaj\u00edm\u00e1 WEDOS Global a r\u00e1di byste se dozv\u011bd\u011bli v\u00edce o pokro\u010dil\u00fdch technologi\u00edch kter\u00e9 pou\u017e\u00edv\u00e1me, tak pro hlub\u0161\u00ed a detailn\u00ed pohled do technologick\u00e9 architektury, na n\u00ed\u017e je postavena infrastruktura WEDOS Global, v\u00e1m doporu\u010dujeme poslechnout si na\u0161i p\u0159edn\u00e1\u0161ku z konference Kubernetes Community Days Czech &amp; Slovak 2023. Tuto odbornou prezentaci vedli dva kolegov\u00e9, kte\u0159\u00ed hraj\u00ed kl\u00ed\u010dovou roli ve v\u00fdvoji WEDOS Global.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"Glob\u00e1ln\u00ed Kubernetes infrastruktura, jej\u00ed v\u00fdvoj a \u00fadr\u017eba-WEDOS Global - Jakub Sassmann a Martin Du\u0161ek\" width=\"525\" height=\"295\" data-src=\"https:\/\/www.youtube.com\/embed\/siA5YFE5N4E?start=25&#038;feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" data-load-mode=\"1\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">WEDOS Global Protection<\/h2>\n\n\n\n<p>WEDOS Global Protection je prvn\u00ed slu\u017eba postaven\u00e1 na na\u0161\u00ed infrastruktu\u0159e WEDOS Global. Prim\u00e1rn\u011b je navr\u017een\u00e1 na eliminaci \u0161irok\u00e9 \u0161k\u00e1ly kybernetick\u00fdch \u00fatok\u016f, kter\u00e9 p\u0159esahuj\u00ed mo\u017enosti b\u011b\u017en\u00e9ho datacentra. Sta\u010d\u00ed j\u00ed spustit a o v\u0161e se postar\u00e1me. Nemus\u00edte nic nastavovat, sta\u010d\u00ed jen sledovat grafy zachycen\u00fdch \u00fatok\u016f.<\/p>\n\n\n\n<p>T\u00edm to ale nekon\u010d\u00ed. WEDOS Global Protection v\u00fdrazn\u011b zv\u00fd\u0161\u00ed odezvu va\u0161eho webu po cel\u00e9m sv\u011bt\u011b d\u00edky AnycastDNS. Pom\u016f\u017ee i p\u0159i velk\u00e9 n\u00e1v\u0161t\u011bvnosti d\u00edky webov\u00e9 cache. V budoucnu tak\u00e9 nab\u00eddne nov\u00e9 technologie jako je t\u0159eba HTTP\/3 bez nutnosti cokoliv nastavovat na va\u0161em serveru. A to nejlep\u0161\u00ed na tom v\u0161em je, \u017ee nemus\u00edte nic st\u011bhovat. Sta\u010d\u00ed jen nasm\u011brovat va\u0161i dom\u00e9nu na na\u0161e DNS, my v\u00e1m vy\u010dist\u00edme provoz a zrychl\u00edme web u va\u0161eho st\u00e1vaj\u00edc\u00edho provozovatele.<\/p>\n\n\n\n<p>Slu\u017eba u\u017e je spu\u0161t\u011bn\u00e1 a m\u016f\u017eete ji jak vyzkou\u0161et, tak i zakoupit. A jak pom\u016f\u017ee konkr\u00e9tn\u011b v\u00e1m? Zkuste se pod\u00edvat na <a href=\"https:\/\/www.wedos.com\/cs\/wedos-global-reseni\/\" target=\"_blank\" rel=\"noopener\">p\u0159ehled vyu\u017eit\u00ed WEDOS Global Protection<\/a> na na\u0161em webu.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Statistiky WEDOS Global Protection<\/h2>\n\n\n\n<p>V srpnu pokra\u010dovala ni\u017e\u0161\u00ed aktivita \u00fato\u010dn\u00edk\u016f. Des\u00edtky milion\u016f request\u016f formou L7 HTTP flood \u00fatoku op\u011bt nikdo nezkusil. Sp\u00ed\u0161e se setk\u00e1v\u00e1me s velmi kr\u00e1tk\u00fdmi jednor\u00e1zov\u00fdmi pokusy \u00fato\u010dn\u00edk\u016f, kte\u0159\u00ed testuj\u00ed na\u0161e ochrany. <\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je L7 DDoS \u00fatok?<\/strong><\/p>\n\n\n\n<p>L7 DDoS \u00fatok je typ kybernetick\u00fdch \u00fatok\u016f na web anebo aplikaci, kter\u00fd pou\u017e\u00edv\u00e1 b\u011b\u017en\u00e9 internetov\u00e9 po\u017eadavky jako GET a POST. C\u00edlem je zpomalit anebo znep\u0159\u00edstupnit webovou str\u00e1nku anebo t\u0159eba API. <\/p>\n\n\n\n<p>\u00datoky na L7 jsou obt\u00ed\u017en\u011b odhaliteln\u00e9 a odli\u0161iteln\u00e9 od norm\u00e1ln\u00edho provozu, proto\u017ee pou\u017e\u00edvaj\u00ed stejn\u00e9 protokoly a metody jako legitimn\u00ed u\u017eivatel\u00e9. K jejich eliminaci je pot\u0159eba pou\u017e\u00edt speci\u00e1ln\u00ed n\u00e1stroje a techniky a d\u016fkladnou anal\u00fdzu s\u00ed\u0165ov\u00e9ho provozu.<\/p>\n<\/div><\/div>\n\n\n\n<p>Po\u0159\u00e1d plat\u00ed, \u017ee je to pro \u00fato\u010dn\u00edky prost\u011b pl\u00fdtv\u00e1n\u00ed zdroji. Zkus\u00ed z n\u011bkolika stovek IP adres synchronizovan\u00fd \u00fatok, kter\u00fd m\u00e1 zp\u016fsobit probl\u00e9m ne\u017e se sepne specifick\u00e1 ochrana, uplatn\u00ed limity, zapne lok\u00e1ln\u00ed blokov\u00e1n\u00ed atd. V\u011bt\u0161inou je to p\u00e1r vte\u0159in, pak to vypnou. O to, aby web ust\u00e1l prvotn\u00ed n\u00e1por se star\u00e1 WAF.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je WAF (Web Application Firewall)?<\/strong><\/p>\n\n\n\n<p>WAF (Web Application Firewall) je ochrana na na\u0161ich reverzn\u00edch proxy serverech, kter\u00e1 je um\u00edst\u011bna mezi \u00fato\u010dn\u00edkem a va\u0161\u00edm webem. V re\u00e1ln\u00e9m \u010dase proch\u00e1z\u00ed ka\u017ed\u00fd po\u017eadavek a hled\u00e1 v n\u011bm specifick\u00e9 znaky \u00fatoku anebo zneu\u017eit\u00ed bezpe\u010dnostn\u00ed d\u00edry. Pokud naraz\u00ed na podez\u0159el\u00fd po\u017eadavek, m\u016f\u017ee jej p\u0159esm\u011brovat na test (p\u0159esm\u011brov\u00e1n\u00ed, captcha) anebo zablokovat.<\/p>\n<\/div><\/div>\n\n\n\n<p>Naproti tomu v\u011bt\u0161\u00ed \u00fatok znamen\u00e1 v\u00edce zapojen\u00fdch ochran, p\u0159\u00edsn\u011bj\u0161\u00ed pravidla, specifick\u00e1 pravidla pro probl\u00e9mov\u00e9 lokality a n\u00e1sledn\u00e9 zkoum\u00e1n\u00ed, kter\u00e9 pak vede k odhalen\u00ed botnet\u016f, p\u0159\u00edpadn\u011b podn\u011bt\u016fm pro zlep\u0161en\u00ed na\u0161ich ochran. Dal\u0161\u00ed \u00fatoky jsou pak m\u00e9n\u011b a m\u00e9n\u011b efektivn\u00ed. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A te\u010f \u010d\u00edsla \ud83d\ude42<\/h3>\n\n\n\n<p>N\u00e1sleduj\u00edc\u00ed statistiky jsou z reverzn\u00edch proxy server\u016f na jednotliv\u00fdch bodech (lokalit\u00e1ch), kter\u00e9 odbavuj\u00ed po\u017eadavky o\u010di\u0161t\u011bn\u00e9 od L3\/L4 DDoS \u00fatok\u016f. D\u00e1le do p\u0159ehledu nejsou zahrnuty n\u011bkter\u00e9 po\u017eadavky, kter\u00e9 pou\u017e\u00edv\u00e1me pro monitorov\u00e1n\u00ed dostupnosti a fungov\u00e1n\u00ed jednotliv\u00fdch bod\u016f, aby statistiky nezkreslovaly.<\/p>\n\n\n\n<p>Ke konci srpna po\u010det chr\u00e1n\u011bn\u00fdch dom\u00e9n WEDOS Global Protection narostl na <strong>4650 dom\u00e9n<\/strong> (+372). \u010c\u00e1st jsou dom\u00e9ny, kter\u00e9 p\u0159idala podpora kv\u016fli \u00fatok\u016fm, anebo to jsou  n\u00e1ro\u010dn\u00e9 weby, kter\u00fdm v\u00fdrazn\u011b pom\u00e1h\u00e1 webov\u00e1 cache na reverzn\u00edm proxy serveru. Mimo n\u00e1s vyu\u017e\u00edv\u00e1 WEDOS Global Protection <strong>1117 u\u017eivatel\u016f<\/strong> (+88).<\/p>\n\n\n\n<p>V srpnu bylo zaznamen\u00e1no celkem <strong>2&nbsp;638&nbsp;773&nbsp;794<\/strong> po\u017eadavk\u016f z <strong>8&nbsp;494&nbsp;078<\/strong> unik\u00e1tn\u00edch IP adres, kter\u00e9 sm\u011b\u0159ovaly na chr\u00e1n\u011bn\u00e9 dom\u00e9ny. V pr\u016fm\u011bru za den odbavily proxy servery 85&nbsp;121&nbsp;735 po\u017eadavk\u016f.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"434\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu-1024x434.png\" alt=\"\" class=\"wp-image-285848 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu-1024x434.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu-300x127.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu-768x326.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu-1536x651.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-requestu.png 1859w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/434;\" \/><\/a><figcaption class=\"wp-element-caption\">Denn\u00ed graf p\u0159\u00edstup\u016f na WEDOS Global za srpen, o\u010di\u0161t\u011bn\u00fdch od L3\/L4 a statistik.<\/figcaption><\/figure>\n\n\n\n<p>Co se t\u00fdk\u00e1 n\u00e1r\u016fstu unik\u00e1tn\u00edch IP adres, tak vliv na to m\u00e1 sez\u00f3nnost, respektive pr\u00e1zdniny. V\u011bt\u0161ina n\u00e1v\u0161t\u011bvn\u00edk\u016f web\u016f chr\u00e1n\u011bn\u00fdch WGP je st\u00e1le z \u010cR a SR. Tito n\u00e1v\u0161t\u011bvn\u00edci se v\u00edce p\u0159ipojovali ze zahrani\u010d\u00ed. D\u00e1le p\u0159ib\u00fdv\u00e1 velk\u00fdch z\u00e1kazn\u00edk\u016f ze zahrani\u010d\u00ed. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"626\" height=\"816\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230901-srpen-staty.png\" alt=\"\" class=\"wp-image-287268 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-staty.png 626w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-staty-230x300.png 230w\" data-sizes=\"(max-width: 626px) 100vw, 626px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 626px; --smush-placeholder-aspect-ratio: 626\/816;\" \/><figcaption class=\"wp-element-caption\">Po\u010det p\u0159\u00edstup\u016f podle st\u00e1t\u016f p\u0159es WEDOS Global Protection.<\/figcaption><\/figure>\n\n\n\n<p>Statistiky st\u00e1le nud\u00edc\u00edch se ochran \ud83d\ude42<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-regular\"><table><tbody><tr><td>L7 DDoS &#8211; zachycen\u00fdch limitov\u00e1n\u00edm p\u0159\u00edstup\u016f (HTTP flood)<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>5 885 991<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">+72 %<\/td><\/tr><tr><td>L7 DDoS &#8211; zachycen\u00fdch probl\u00e9mov\u00fdch spojen\u00ed (Slowloris, Connection Exhaustion atd.)<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>572 784<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">-65,43&nbsp;%<\/td><\/tr><tr><td>Blokov\u00e1no pravidlem WAF<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>25&nbsp;872&nbsp;220<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">+142,66&nbsp;%<\/td><\/tr><tr><td>Dal\u0161\u00ed blokov\u00e1n\u00ed L7<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>5 321 633<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">-4,66 %<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>Tato \u010d\u00edsla jsou jen prvn\u00ed pokusy o \u00fatok. Jakmile se jedn\u00e1 o opakovan\u00e9 pokusy, kter\u00e9 naberou na s\u00edle (t\u0159eba des\u00edtky tis\u00edc probl\u00e9mov\u00fdch p\u0159\u00edstup\u016f za minutu), tak IP adresa jde na blacklist. Je to v\u0161ak slo\u017eit\u011bj\u0161\u00ed, proto\u017ee k r\u016fzn\u00fdm IP se chov\u00e1me odli\u0161n\u011b (t\u0159eba mobiln\u00ed oper\u00e1tor dostane JavaScript redirekt anebo capchta). Stejn\u011b tak o odli\u0161n\u00fdm form\u00e1m \u00fatok\u016f.<\/p>\n\n\n\n<p>Co se t\u00fdk\u00e1 \u010d\u00edsel samotn\u00fdch, tak v\u011bt\u0161\u00ed mno\u017estv\u00ed L7 flood \u00fatok\u016f o 72 % vypad\u00e1 hroziv\u011b, ale ve skute\u010dnosti jeden L7 flood m\u016f\u017ee m\u00edt stovky tis\u00edc zablokovan\u00fdch request\u016f, ne\u017e se sepnou dal\u0161\u00ed ochrany. WEDOS Global Protection se dost\u00e1v\u00e1 do sv\u011bta a potk\u00e1v\u00e1me se se st\u00e1le v\u00edce &#8222;testy&#8220; na\u0161ich ochran. Nav\u00edc velk\u00e1 \u010d\u00e1st nov\u00fdch u\u017eivatel\u016f WGP jsou lid\u00e9, kte\u0159\u00ed jsou pod pravideln\u00fdmi \u00fatoky. <\/p>\n\n\n\n<p>Pro pokles \u00fatok\u016f typu Slowloris, Connection Exhaustion atd. aktu\u00e1ln\u011b nem\u00e1me vysv\u011btlen\u00ed. Uvid\u00edme p\u0159\u00ed\u0161t\u00ed m\u011bs\u00edc.<\/p>\n\n\n\n<p>N\u00e1r\u016fst o 142,66 % blokov\u00e1no na WAF je d\u016fsledek nasazen\u00ed ochran administrac\u00ed WordPress. V\u0161echny administrace WordPress jsou chr\u00e1n\u011bny dal\u0161\u00edm faktorem (captcha, JavaScript redirekt). T\u011bch 15M pokus\u016f jsou pokusy o prolomen\u00ed hesla, hled\u00e1n\u00ed zranitelnost\u00ed na p\u0159ihla\u0161ovac\u00edm formul\u00e1\u0159i atd. <\/p>\n\n\n\n<p>P\u0159\u00edsn\u011bj\u0161\u00ed pravidla na WAF jsou vid\u011bt i na statistice nejv\u011bt\u0161\u00edch chr\u00e1n\u011bn\u00fdch web\u016f. To, \u017ee nepou\u017e\u00edv\u00e1te WordPress, neznamen\u00e1, \u017ee se n\u011bkdo nepokou\u0161\u00ed \u00fato\u010dit anebo hledat zranitelnost jako by jste tam WordPress m\u011bli.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"887\" height=\"809\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230901-srpen-weby.png\" alt=\"\" class=\"wp-image-287272 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-weby.png 887w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-weby-300x274.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-weby-768x700.png 768w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 887px; --smush-placeholder-aspect-ratio: 887\/809;\" \/><figcaption class=\"wp-element-caption\">Statistiky nejv\u011bt\u0161\u00edch web\u016f chr\u00e1n\u011bn\u00fdch WEDOS Global Protection za srpen.<\/figcaption><\/figure>\n\n\n\n<p>Ve statistik\u00e1ch nejsou vid\u011bt v\u0161echny \u00fatoky na weby. Jsou to jen ty, kde p\u0159esn\u011b v\u00edme, \u017ee jde \u00fatok na konkr\u00e9tn\u00ed host, a kter\u00e9 do\u0161ly a\u017e na WAF. Mnohon\u00e1sobn\u011b v\u00edce toho skon\u010d\u00ed na blacklistech. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">L3\/L4<\/h3>\n\n\n\n<p>Samoz\u0159ejm\u011b na\u0161i z\u00e1kazn\u00edci jsou tak\u00e9 pod \u00fatoky klasick\u00fdmi L3\/L4 \u00fatoky. Nicm\u00e9n\u011b ve v\u011bt\u0161in\u011b p\u0159\u00edpad\u016f to nestoj\u00ed za \u0159e\u010d. Na\u0161e ochrany jsou stav\u011bny na \u00fatoky ve stovk\u00e1ch Gbps. V\u0161e pod 10 Gbps ani nepos\u00edl\u00e1 notifikaci technik\u016fm. V\u0161e \u0159e\u0161\u00ed automaty.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co jsou L3\/L4 \u00fatoky?<\/strong><\/p>\n\n\n\n<p>DDoS \u00fatoky na L3 a L4 vrstv\u011b se zam\u011b\u0159uj\u00ed na s\u00ed\u0165ovou a transportn\u00ed vrstvu a vyu\u017e\u00edvaj\u00ed r\u016fzn\u00e9 techniky, jak zahlcovat c\u00edlov\u00e9 servery nebo za\u0159\u00edzen\u00ed.<br><br>S\u00ed\u0165ov\u00e1 vrstva (L3) &#8211; zaji\u0161\u0165uje sm\u011brov\u00e1n\u00ed dat mezi r\u016fzn\u00fdmi s\u00edt\u011bmi pomoc\u00ed logick\u00fdch adres (IP).<br><br>Transportn\u00ed vrstva (L4) &#8211; zaji\u0161\u0165uje spolehliv\u00fd a \u0159\u00edzen\u00fd p\u0159enos dat mezi koncov\u00fdmi body pomoc\u00ed protokol\u016f jako TCP nebo UDP.<\/p>\n<\/div><\/div>\n\n\n\n<p>Jak vid\u00edte na grafu n\u00ed\u017ee, b\u011bhem srpna prob\u00edhaly opravdu zanedbateln\u00e9 DDoS \u00fatoky p\u0159es L3\/L4. Jen na kr\u00e1tk\u00fd okam\u017eik se jeden p\u0159ibl\u00ed\u017eil k 8 Gbps. C\u00edlem byl z\u00e1kazn\u00edk na na\u0161em webhostingu. <\/p>\n\n\n\n<p>Celkem jsme evidovali 6557 \u00fatok\u016f DDoS \u00fatok\u016f.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230901-srpen-l3-l4-attacks.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"545\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230901-srpen-l3-l4-attacks-1024x545.png\" alt=\"\" class=\"wp-image-285836 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-l3-l4-attacks-1024x545.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-l3-l4-attacks-300x160.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-l3-l4-attacks-768x409.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230901-srpen-l3-l4-attacks.png 1167w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/545;\" \/><\/a><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Nejsiln\u011bj\u0161\u00ed L7 DDoS<\/h2>\n\n\n\n<p>Ka\u017ed\u00fd m\u011bs\u00edc pro v\u00e1s p\u0159ipravujeme seznam nejsiln\u011bj\u0161\u00edch DDoS \u00fatok\u016f p\u0159es L7.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. \u00fatok na wedos.com &#8211; \u0161pi\u010dka 1,1M po\u017eadavk\u016f za minutu<\/h3>\n\n\n\n<p>Prvn\u00ed cenu za nejsiln\u011bj\u0161\u00ed DDoS ud\u011blujeme sami sob\u011b :). N\u011bkdo se rozhodl pozd\u011b v noci otestovat na\u0161\u00ed ochranu. Dal tomu 5 minut, b\u011bhem kter\u00fdch dok\u00e1zal protla\u010dit 4M request\u016f, ve \u0161pi\u010dce 1,15M z 1668 UIP. Jednalo se o oby\u010dejn\u00fd L7 flood. Nic zaj\u00edmav\u00e9ho ani slo\u017eit\u00e9ho na eliminaci. Na na\u0161em vlastn\u00edm webu nav\u00edc testujeme n\u011bkter\u00e9 pokro\u010dilej\u0161\u00ed metody filtrace.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"462\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz-1024x462.png\" alt=\"\" class=\"wp-image-287287 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz-1024x462.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz-300x135.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz-768x346.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz-1536x693.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230815-utoky-na-wedos-com-cz.png 1816w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/462;\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. \u00fatok na wedos.com &#8211; \u0161pi\u010dka 877K po\u017eadavk\u016f za minutu<\/h3>\n\n\n\n<p>A na druh\u00e9m m\u00edst\u011b je &#8230; ehm &#8230; zase my :). Koncem srpna n\u011bkdo zkusil na\u0161e ochrany t\u011bsn\u011b p\u0159ed p\u016flnoc\u00ed. \u00datok trval zhruba 4 minuty a b\u011bhem nich poslal \u00fato\u010dn\u00edk 3,5M request\u016f, ve \u0161pi\u010dce 877K, z celkem 3013 unik\u00e1tn\u00edch IP adres. Tento \u00fatok byl co do po\u010dtu pou\u017eit\u00fdch IP adres celkem slu\u0161n\u00fd. T\u011bch zaj\u00edmav\u00fdch v\u011bc\u00ed tam bylo v\u00edce, ale bohu\u017eel se o n\u011b pod\u011blit nem\u016f\u017eeme, proto\u017ee u\u017e z toho je firemn\u00ed know how \ud83d\ude14<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"372\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos-1024x372.png\" alt=\"\" class=\"wp-image-287299 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos-1024x372.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos-300x109.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos-768x279.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos-1536x558.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/20230831-utok-na-blog-wedos.png 1811w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/372;\" \/><\/a><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. \u00fatok na st\u00e1tn\u00ed infrastrukturu &#8211; \u0161pi\u010dka 205K po\u017eadavk\u016f za vte\u0159inu<\/h3>\n\n\n\n<p>Pokud sledujete na\u0161e \u00fa\u010dty na soci\u00e1ln\u00edch s\u00edt\u00edch anebo odeb\u00edr\u00e1te n\u00e1\u0161 newsletter, tak jste mohli zahl\u00e9dnout, \u017ee u n\u00e1s maj\u00ed weby i ministerstva (ne \u010desk\u00e1, ta z\u0159ejm\u011b preferuj\u00ed b\u00fdt offline, aby ud\u011blala radost rusk\u00e9 propagand\u011b).<\/p>\n\n\n\n<p>Jeden takov\u00fd web byl v srpnu pod \u00fatokem a nutno \u0159\u00edct, \u017ee to bylo opravdu zaj\u00edmav\u00e9 sledovat. P\u0159e\u0161li k n\u00e1m od americk\u00e9 konkurence, kter\u00e1 jim neum\u011bla nab\u00eddnout provoz <a href=\"https:\/\/www.wedos.com\/cs\/protection\/kompletni-cenik-b2b\/\" target=\"_blank\" rel=\"noopener\">pod vlastn\u00edm DNS, ASN a IP adresami<\/a> a tak\u00e9 \u00fapln\u011b nebyli spokojeni s L7 ochranou. <\/p>\n\n\n\n<p>\u00datok jako takov\u00fd siln\u00fd nebyl. Co je to \u0161pi\u010dka 205 tis\u00edc po\u017eadavk\u016f za vte\u0159inu a jen 242 UIP? Nicm\u00e9n\u011b bylo to \u00fapln\u011b n\u011bco jin\u00e9ho ne\u017e s \u010d\u00edm se b\u011b\u017en\u011b setk\u00e1v\u00e1me. \u00dato\u010dili \u00fapln\u011b jin\u00e9 rozsahy a jin\u00fdm zp\u016fsobem. R\u00e1di bychom se o tom rozepsali, ale firemn\u00ed know how&#8230;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"461\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/09\/utoky-na-statni-web-1-1024x461.png\" alt=\"\" class=\"wp-image-287317 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/utoky-na-statni-web-1-1024x461.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/utoky-na-statni-web-1-300x135.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/utoky-na-statni-web-1-768x346.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/utoky-na-statni-web-1-1536x691.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/09\/utoky-na-statni-web-1.png 1820w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/461;\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Z\u00e1v\u011br<\/h2>\n\n\n\n<p>Kdokoliv m\u016f\u017ee vyu\u017e\u00edvat WEDOS Global  Protection pro rychlej\u0161\u00ed na\u010d\u00edt\u00e1n\u00ed a ochranu sv\u00fdch web\u016f. Slu\u017ebu je mo\u017en\u00e9 pou\u017e\u00edvat bez nutnosti st\u011bhovat hardware anebo m\u011bnit poskytovatele webhostingu. Sta\u010d\u00ed nasm\u011b\u0159ovat dom\u00e9nu na DNS WEDOS Global a p\u0159idat dom\u00e9nu do <a href=\"https:\/\/client.wedos.global\/protection\/dashboard\" target=\"_blank\" rel=\"noopener\">administrace WEDOS Global Protection<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Druh\u00fd pr\u00e1zdninov\u00fd m\u011bs\u00edc rozhodn\u011b nebyl \u010das odpo\u010dinku. Jednak jsme pokra\u010dovali v budov\u00e1n\u00ed WEDOS Global, ale tak\u00e9 museli \u0159e\u0161it vzr\u016fstaj\u00edc\u00ed aktivitu n\u011bkter\u00fdch botnet\u016f, kter\u00e9 prim\u00e1rn\u011b nem\u011bly v \u00famyslu prov\u00e1d\u011bt DDoS \u00fatoky, ale hledaly zranitelnosti. Kdy\u017e se pak sesypaly v jeden okam\u017eik jejich requesty, tak n\u011bkter\u00e9 na\u0161e z\u00e1kazn\u00edky dok\u00e1zaly nemile potr\u00e1pit.<\/p>\n","protected":false},"author":9,"featured_media":287205,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[112],"tags":[204,203,122,200,186,177],"class_list":["post-278896","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost","tag-cache","tag-cdn","tag-ddos","tag-waf","tag-wedos-global","tag-wedos-global-protection"],"_links":{"self":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/278896","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/comments?post=278896"}],"version-history":[{"count":7,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/278896\/revisions"}],"predecessor-version":[{"id":311900,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/278896\/revisions\/311900"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media\/287205"}],"wp:attachment":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media?parent=278896"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/categories?post=278896"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/tags?post=278896"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}