{"id":307521,"date":"2023-10-19T13:36:16","date_gmt":"2023-10-19T11:36:16","guid":{"rendered":"https:\/\/blog.wedos.cz\/?p=307521"},"modified":"2023-10-19T13:36:21","modified_gmt":"2023-10-19T11:36:21","slug":"waf-report-z-wedos-global-protection-za-zari-2023","status":"publish","type":"post","link":"https:\/\/blog.wedos.com\/cs\/waf-report-z-wedos-global-protection-za-zari-2023","title":{"rendered":"WAF report z WEDOS Global Protection za z\u00e1\u0159\u00ed 2023"},"content":{"rendered":"\n<p>V z\u00e1\u0159\u00ed jsme oproti pr\u00e1zdninov\u00fdm m\u011bs\u00edc\u016fm zaznamenali i vzr\u016fstaj\u00edc\u00ed po\u010det \u00fatok\u016f. V dne\u0161n\u00edm reportu se pod\u00edv\u00e1me po del\u0161\u00ed dob\u011b na &#8222;siln\u011bj\u0161\u00ed&#8220; DDoS \u00fatoky na L3\/L4 a zat\u00edm z\u0159ejm\u011b na nejsiln\u011bj\u0161\u00ed L7 DDoS \u00fatok co do po\u010dtu po\u017eadavk\u016f za minutu. Samoz\u0159ejm\u011b probereme i budov\u00e1n\u00ed WEDOS Global Protection a na \u010dem aktu\u00e1ln\u011b pracujeme.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>I v z\u00e1\u0159\u00ed pokra\u010dovala v\u00fdznamn\u00e1 aktivita botnet\u016f, kter\u00e9 se zam\u011b\u0159ily na hled\u00e1n\u00ed zranitelnost\u00ed na webech a v obl\u00edben\u00fdch redak\u010dn\u00edch syst\u00e9mech. Velmi v\u00fdrazn\u00fd byl botnet prov\u00e1d\u011bj\u00edc\u00ed \u00fatoky z mobiln\u00edch za\u0159\u00edzen\u00ed v P\u00e1kist\u00e1nu. Byly dny, kdy tento botnet provedl i stovky tis\u00edc po\u017eadavk\u016f. Nicm\u00e9n\u011b p\u0159i t\u011bchto po\u010dtech u\u017e se na omezenou dobu aktivuj\u00ed blacklisty, tak\u017ee v re\u00e1lu bychom se dostali k jednotk\u00e1m milion\u016f.<\/p>\n\n\n\n<p>Jen pro zaj\u00edmavost, n\u011bkter\u00e9 dny byl jedn\u00edm z nej\u010dast\u011bji volan\u00fdch soubor\u016f <strong>xmlrpc.php<\/strong>. Co\u017e je obrovsk\u00e9 l\u00e1kadlo pro \u00fato\u010dn\u00edky. \u010casto zkou\u0161\u00ed existenci xmlrpc.php, i kdy\u017e na webu nem\u00e1te WordPress.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je xmlrp.php?<\/strong><\/p>\n\n\n\n<p>Soubor xmlrpc.php ve WordPress slou\u017e\u00ed k poskytov\u00e1n\u00ed rozhran\u00ed XML-RPC, co\u017e je protokol, kter\u00fd umo\u017e\u0148uje komunikaci mezi WordPress a jin\u00fdmi syst\u00e9my. P\u0159esto\u017ee je tento soubor d\u016fle\u017eit\u00fd pro n\u011bkter\u00e9 funkce, m\u016f\u017ee b\u00fdt tak\u00e9 zraniteln\u00fd v\u016f\u010di \u00fatok\u016fm, pokud nen\u00ed spr\u00e1vn\u011b zabezpe\u010den.<\/p>\n\n\n\n<p>\u00dato\u010dn\u00edci mohou vyu\u017e\u00edvat xmlrpc.php k proveden\u00ed brute force \u00fatok\u016f na p\u0159ihla\u0161ovac\u00ed \u00fadaje. XML-RPC umo\u017e\u0148uje \u00fato\u010dn\u00edk\u016fm odeslat mnoho p\u0159ihla\u0161ovac\u00edch pokus\u016f v jedn\u00e9 \u017e\u00e1dosti, co\u017e je \u010din\u00ed efektivn\u011bj\u0161\u00edmi p\u0159i h\u00e1d\u00e1n\u00ed hesel.<\/p>\n\n\n\n<p>xmlrpc.php m\u016f\u017ee b\u00fdt tak\u00e9 zneu\u017eit k prov\u00e1d\u011bn\u00ed DDoS \u00fatok\u016f, kter\u00e9 p\u0159et\u011b\u017euj\u00ed server t\u00edm, \u017ee generuj\u00ed obrovsk\u00e9 mno\u017estv\u00ed po\u017eadavk\u016f, co\u017e m\u016f\u017ee v\u00e9st k p\u00e1du nebo zpomalen\u00ed webu.<\/p>\n\n\n\n<p>Pokud jsou na WordPress zranitelnosti, \u00fato\u010dn\u00edci mohou vyu\u017e\u00edt xmlrpc.php k vzd\u00e1len\u00e9mu spu\u0161t\u011bn\u00ed \u0161kodliv\u00e9ho k\u00f3du.<\/p>\n\n\n\n<p>\u00dato\u010dn\u00edci mohou tak\u00e9 zneu\u017e\u00edvat funkce XML-RPC k prov\u00e1d\u011bn\u00ed ne\u017e\u00e1douc\u00edch akc\u00ed jako je publikov\u00e1n\u00ed spamov\u00fdch p\u0159\u00edsp\u011bvk\u016f nebo koment\u00e1\u0159\u016f.<\/p>\n<\/div><\/div>\n\n\n\n<p>Samoz\u0159ejm\u011b nechyb\u011bly ani pokusy o hled\u00e1n\u00ed zranitelnost\u00ed prost\u0159ednictv\u00edm SQLi \u00fatok\u016f. V tom byl velice aktivn\u00ed hlavn\u011b p\u00e1kist\u00e1nsk\u00fd mobiln\u00ed botnet. Nicm\u00e9n\u011b nepolevovaly ani dal\u0161\u00ed botnety z dal\u0161\u00edch zem\u00ed jako t\u0159eba \u010c\u00edna. Ty jsou charakteristick\u00e9 hlavn\u011b pou\u017e\u00edv\u00e1n\u00edm IPv6. V \u010c\u00edn\u011b se hojn\u011b vyu\u017e\u00edv\u00e1 IPv6, tak\u017ee je t\u0159eba d\u00e1vat si pozor i na to. \u0158ada mobiln\u00edch oper\u00e1tor\u016f p\u0159id\u011bluje novou IPv6 po p\u0159ipojen\u00ed do s\u00edt\u011b, tak\u017ee standardn\u00ed \u0159e\u0161en\u00ed na principu fail2ban nemus\u00ed b\u00fdt pro jednotliv\u00e9 IPv6 ide\u00e1ln\u00ed.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je to SQLi?<\/strong><\/p>\n\n\n\n<p>SQLi (SQL injection), je typ \u00fatoku sm\u011b\u0159uj\u00edc\u00ed na datab\u00e1ze. P\u0159i tomto \u00fatoku se nepovolen\u00e9 SQL p\u0159\u00edkazy vkl\u00e1daj\u00ed do vstupn\u00edch pol\u00ed aplikace s c\u00edlem manipulovat nebo z\u00edskat p\u0159\u00edstup k datab\u00e1zi. Kdy\u017e aplikace neov\u011b\u0159uje a nespr\u00e1vn\u011b zpracov\u00e1v\u00e1 u\u017eivatelsk\u00fd vstup, m\u016f\u017ee to \u00fato\u010dn\u00edkovi umo\u017enit spustit vlastn\u00ed SQL k\u00f3d v datab\u00e1zi. D\u016fsledky SQLi mohou zahrnovat naru\u0161en\u00ed integrity dat, ztr\u00e1tu dat, z\u00edsk\u00e1n\u00ed citliv\u00fdch informac\u00ed a v n\u011bkter\u00fdch p\u0159\u00edpadech i \u00fapln\u00e9 ovl\u00e1dnut\u00ed datab\u00e1ze \u010di hostitelsk\u00e9ho syst\u00e9mu.<\/p>\n<\/div><\/div>\n\n\n\n<p>Co se t\u00fdk\u00e1 obl\u00edben\u00fdch L7 DDoS \u00fatok\u016f, tak tam jsme \u017e\u00e1dn\u00fd nov\u00fd trend nezaznamenali. Opakuje se po\u0159\u00e1d to sam\u00e9, co u\u017e jsme vid\u011bli, a na co jsme p\u0159ipraveni. Nicm\u00e9n\u011b je nutn\u00e9 podotknout, \u017ee \u00fatoky jsou intenzivn\u011bj\u0161\u00ed, zvl\u00e1\u0161t\u011b pokud jsou vedeny z napaden\u00fdch server\u016f. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">WEDOS Global<\/h2>\n\n\n\n<p>WEDOS Global je na\u0161e celosv\u011btov\u00e1 infrastruktura postaven\u00e1 na BGP Anycast a reverzn\u00edch proxy. Hlavn\u00ed my\u0161lenka je stahovat si p\u0159es BGP n\u00e1v\u0161t\u011bvnost z okol\u00ed do lokalit, kde m\u00e1me n\u00e1\u0161 hardware s reverzn\u00edmi proxy, a tam s provozem d\u00e1le pracovat. V ka\u017ed\u00e9 lokalit\u011b jej tak filtrujeme, cachujeme, um\u00edme p\u0159ekl\u00e1dat protokol (HTTP\/1.1 na HTTP\/3) anebo poskytnout IPv6, i kdy\u017e jej na webhostingu\/serveru nem\u00e1te.<\/p>\n\n\n\n<p>V podstat\u011b reverzn\u00ed proxy mohou d\u011blat cokoliv a to decentralizovan\u011b po cel\u00e9m sv\u011bt\u011b, doslova za rohem od n\u00e1v\u0161t\u011bvn\u00edka. Experimentujeme s \u0159adou v\u011bc\u00ed, kter\u00e9 v\u00e1\u0161 web posunou na novou \u00farove\u0148 a to bez nutnosti cokoliv upravovat na va\u0161em serveru. Sta\u010d\u00ed jen nasm\u011brovat dom\u00e9nu pomoc\u00ed DNS a to je v\u0161e.<\/p>\n\n\n\n<p>Tento report ale nen\u00ed o tom, jak v\u00e1m zrychl\u00edme web, anebo vy\u0159e\u0161\u00edme n\u011bkter\u00e9 technick\u00e9 nedostatky. To si nech\u00e1me na samostatn\u00fd \u010dl\u00e1nek \ud83d\ude42<\/p>\n\n\n\n<p>WEDOS Global jako celosv\u011btov\u00e1 s\u00ed\u0165 mus\u00ed b\u00fdt hlavn\u011b rychl\u00e1. K tomu pot\u0159ebujeme b\u00fdt v d\u016fle\u017eit\u00fdch lokalit\u00e1ch, propojit se do hlavn\u00edch v\u00fdm\u011bnn\u00fdch uzl\u016f (IXP) a poladit peering, aby v\u0161echna data putovala v\u017edy nejkrat\u0161\u00ed cestou.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je to IXP peering?<\/strong><\/p>\n\n\n\n<p>Peering je dohoda mezi dv\u011bma poskytovateli internetov\u00fdch slu\u017eeb (ISP), kter\u00e1 umo\u017e\u0148uje, aby jejich s\u00ed\u0165ov\u00fd provoz proch\u00e1zel p\u0159\u00edmo mezi nimi, ani\u017e by musel proj\u00edt t\u0159et\u00ed stranou. <\/p>\n\n\n\n<p>Tento p\u0159\u00edm\u00fd p\u0159enos dat m\u016f\u017ee zv\u00fd\u0161it rychlost a spolehlivost internetov\u00e9ho p\u0159ipojen\u00ed, proto\u017ee \u00fadaje nemus\u00ed cestovat tak daleko nebo p\u0159es dal\u0161\u00ed r\u016fzn\u00e9 s\u00edt\u011b. Tak\u00e9 to m\u016f\u017ee sn\u00ed\u017eit n\u00e1klady, proto\u017ee ob\u011b strany se mohou vyhnout poplatk\u016fm, kter\u00e9 by jinak mohly platit t\u0159et\u00edm stran\u00e1m za p\u0159enos dat.<\/p>\n\n\n\n<p>Peering obvykle prob\u00edh\u00e1 na tzv. internetov\u00fdch v\u00fdm\u011bnn\u00fdch bodech (IXP), kde m\u016f\u017ee mnoho ISP propojit sv\u00e9 s\u00edt\u011b dohromady.<\/p>\n<\/div><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Nov\u00e9 lokality<\/h3>\n\n\n\n<p>V z\u00e1\u0159\u00ed jsme p\u0159idali novou lokalitu Irsko (Dublin). V nov\u00e9 lokalit\u011b m\u00e1me 45 na\u0161ich vlastn\u00edch fyzick\u00fdch server\u016f, 3 switche a&nbsp;domluvenou konektivitu 100 Gbps s&nbsp;mo\u017enost\u00ed \u0161k\u00e1lov\u00e1n\u00ed. V\u0161e je tak\u00e9 p\u0159ipraveno na p\u0159\u00edpadn\u00e9 propojen\u00ed do lok\u00e1ln\u00edch s\u00edt\u00ed p\u0159es p\u0159edsazen\u00fd switch Arista, pokud to v&nbsp;budoucnu zlep\u0161\u00ed kvalitu slu\u017eeb, anebo pokud v&nbsp;Irsku budeme m\u00edt v\u011bt\u0161\u00ed po\u010det m\u00edstn\u00edch z\u00e1kazn\u00edk\u016f.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-blog-wedos wp-block-embed-blog-wedos\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/blog.wedos.cz\/spusteni-nove-lokality-wedos-global-v-irsku\n<\/div><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Nov\u00e9 propoje (peeringy)<\/h3>\n\n\n\n<p>Koncem srpna jsme spustili nov\u00fd propoj (peering) do LINX (London Internet Exchange) viz. \u010dl\u00e1nek na blogu <a href=\"https:\/\/blog.wedos.cz\/nove-prime-propojeni-s-linx-posiluje-nasi-celosvetovou-infrastrukturu-wedos-global\" target=\"_blank\" rel=\"noopener\">Nov\u00e9 p\u0159\u00edm\u00e9 propojen\u00ed s LINX posiluje na\u0161i celosv\u011btovou infrastrukturu WEDOS Global<\/a>. B\u011bhem z\u00e1\u0159\u00ed jsme detailn\u011b analyzovali provoz a postupn\u011b v\u0161e ladili ke spokojenosti na\u0161ich z\u00e1kazn\u00edk\u016f.<\/p>\n\n\n\n<p>Dal\u0161\u00ed propoj, kter\u00fd jsme realizovali, je do Netnod. Jedn\u00e1 se o v\u00fdznamn\u00e9 IXP sdru\u017euj\u00edc\u00ed ISP ze seversk\u00fdch zem\u00ed. Propojili jsme se do Netnode v lokalit\u011b \u0160v\u00e9dsko a Finsko. <\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-blog-wedos wp-block-embed-blog-wedos\"><div class=\"wp-block-embed__wrapper\">\nhttps:\/\/blog.wedos.cz\/wedos-global-se-propojil-do-ixp-netnod-bude-tak-rychlejsi-pro-uzivatele-ze-severskych-statu\n<\/div><\/figure>\n\n\n\n<p>I d\u00edky t\u011bmto propoj\u016fm se WEDOS Global podle nez\u00e1visl\u00e9ho m\u011b\u0159en\u00ed mezi celosv\u011btov\u00fdmi DNS usadil v TOP 25 na sv\u011bt\u011b a v TOP 10 v Evrop\u011b. My si ale v\u011b\u0159\u00edme a TOP 5 v Evrop\u011b d\u00e1me do p\u00e1r m\u011bs\u00edc\u016f \ud83d\ude42<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"block-cf8be3ad-2224-472b-a4bd-d94ca3c9f21c\">Chcete se o WEDOS Global dozv\u011bd\u011bt v\u00edce?<\/h3>\n\n\n\n<p id=\"block-7a0e9de9-994a-4368-83c1-98199a50b21d\">Pokud v\u00e1s zaj\u00edm\u00e1 WEDOS Global a r\u00e1di byste se dozv\u011bd\u011bli v\u00edce o pokro\u010dil\u00fdch technologi\u00edch kter\u00e9 pou\u017e\u00edv\u00e1me, tak pro hlub\u0161\u00ed a detailn\u00ed pohled do technologick\u00e9 architektury, na n\u00ed\u017e je postavena infrastruktura WEDOS Global, v\u00e1m doporu\u010dujeme poslechnout si na\u0161i p\u0159edn\u00e1\u0161ku z konference Kubernetes Community Days Czech &amp; Slovak 2023. Tuto odbornou prezentaci vedli dva kolegov\u00e9, kte\u0159\u00ed hraj\u00ed kl\u00ed\u010dovou roli ve v\u00fdvoji WEDOS Global.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"Glob\u00e1ln\u00ed Kubernetes infrastruktura, jej\u00ed v\u00fdvoj a \u00fadr\u017eba-WEDOS Global - Jakub Sassmann a Martin Du\u0161ek\" width=\"525\" height=\"295\" data-src=\"https:\/\/www.youtube.com\/embed\/siA5YFE5N4E?start=25&#038;feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" class=\"lazyload\" data-load-mode=\"1\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">WEDOS Global Protection<\/h2>\n\n\n\n<p>WEDOS Global Protection je prvn\u00ed slu\u017eba spu\u0161t\u011bn\u00e1 na infrastruktu\u0159e WEDOS Global. Jej\u00ed prim\u00e1rn\u00ed \u00fa\u010del je ochr\u00e1nit v\u00e1\u0161 web p\u0159ed \u0161irokou \u0161k\u00e1lou kybernetick\u00fdch \u00fatok\u016f a to bez ohledu na to,  jak jsou rozs\u00e1hl\u00e9. Z\u00e1rove\u0148 je kladen d\u016fraz, aby u\u017eivatel nemusel nic nastavovat. Ochrany se p\u0159izp\u016fsob\u00ed n\u00e1v\u0161t\u011bvnosti webu a jsou schopn\u00e9 velice rychle reagovat na anom\u00e1lie.<\/p>\n\n\n\n<p>Na rozd\u00edl od konkuren\u010dn\u00edch \u0159e\u0161en\u00ed nav\u00edc m\u00e1me p\u0159\u00edstup k \u0161irok\u00e9 \u0161k\u00e1le dat a mo\u017enost\u00ed jak \u00fatok eliminovat. Jednotliv\u00e9 lokality mohou p\u0159istupovat k \u00fatok\u016fm odli\u0161n\u011b, \u00fato\u010dn\u00edci jsou velice omezen\u00ed p\u0159i pou\u017e\u00edv\u00e1n\u00ed podvr\u017een\u00fdch IP adres, ochrana u n\u00e1s neznamen\u00e1 jen blokovat p\u0159\u00edstup, m\u016f\u017eeme prov\u00e9st test pomoc\u00ed p\u0159esm\u011brov\u00e1n\u00ed, anebo captcha, anebo podez\u0159el\u00e9mu provozu vr\u00e1tit v\u017edy cachovanou verzi str\u00e1nky. <\/p>\n\n\n\n<p>WEDOS Global Protection je postaven na na\u0161ich datech a zku\u0161enostech, kter\u00e9 jsme nasb\u00edrali za 13 let provozov\u00e1n\u00ed stovek tis\u00edc webov\u00fdch str\u00e1nek. V\u00edme, co vad\u00ed majitel\u016fm web\u016f, co hosting\u016fm, a co provozovatel\u016fm infrastruktury a kdy je t\u0159eba zakro\u010dit.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">WordPress plugin &#8211; WEDOS Global Protection<\/h3>\n\n\n\n<p>A to je i d\u016fvod, pro\u010d jsme se pustili do tvorby na\u0161eho ofici\u00e1ln\u00ed pluginu pro WordPress. Ten u\u017e najdete i v repozit\u00e1\u0159i WordPress a tak\u00e9 ve va\u0161\u00ed instalaci WordPress. Pom\u016f\u017ee v\u00e1m s aktivac\u00ed WEDOS Global Protection pro va\u0161\u00ed dom\u00e9nu. Do budoucna p\u0159ipravujeme dal\u0161\u00ed roz\u0161\u00ed\u0159en\u00ed a pokro\u010dil\u00e9 funkce.<\/p>\n\n\n\n<p>Jak jej nainstalovat?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sta\u010d\u00ed v lev\u00e9m menu zvolit Pluginy -&gt; Instalace plugin\u016f.<\/li>\n\n\n\n<li>V prav\u00e9m rohu do vyhled\u00e1v\u00e1n\u00ed zadejte WEDOS.<\/li>\n\n\n\n<li>Objev\u00ed se v\u00e1m WEDOS Global Protection a WEDOS OnLine monitoring.<\/li>\n\n\n\n<li>Zvolte u WEDOS Global Protection <strong>Instalovat<\/strong>.<\/li>\n\n\n\n<li>Pot\u00e9 n\u00e1sledujte instrukce pro z\u0159\u00edzen\u00ed \u00fa\u010dtu a aktivaci slu\u017eby.<\/li>\n<\/ul>\n\n\n\n<p>Pokud v\u00e1s zaj\u00edm\u00e1 i plugin WEDOS OnLine monitoring, tak v\u00edce se o n\u011bm dozv\u00edte na <a href=\"https:\/\/cs.wordpress.org\/plugins\/wedos-online-monitoring\/\" target=\"_blank\" rel=\"noopener\">cs.wordpress.org\/plugins\/wedos-online-monitoring<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Od mal\u00fdch po\u017eadavk\u016f k velk\u00fdm odhalen\u00edm: S\u00edla agregace dat<\/h2>\n\n\n\n<p>Data jsou nejsiln\u011bj\u0161\u00edm n\u00e1strojem v boji proti kybernetick\u00fdm hrozb\u00e1m. D\u00edky na\u0161im pokro\u010dil\u00fdm metod\u00e1m agregace dat jsme schopni odhalovat hrozby skryt\u00e9 v zd\u00e1nliv\u011b nev\u00fdznamn\u00fdch po\u017eadavc\u00edch. V \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/jak-vyuzivame-agregaci-dat-k-hledani-utoku\" target=\"_blank\" rel=\"noopener\">Jak vyu\u017e\u00edv\u00e1me agregaci dat k hled\u00e1n\u00ed \u00fatok\u016f<\/a> v\u00e1m uk\u00e1\u017eeme, jak tato technika pom\u00e1h\u00e1 chr\u00e1nit va\u0161e weby.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Statistiky WEDOS Global Protection<\/h2>\n\n\n\n<p>V z\u00e1\u0159\u00ed narostl po\u010det u\u017eivatel\u016f WEDOS Global Protection na <strong>1 212<\/strong> (+8,5 %) a po\u010det chr\u00e1n\u011bn\u00fdch dom\u00e9n na <strong>5 021<\/strong> (+7,39 %). Jedn\u00e1 se o dom\u00e9ny druh\u00e9ho \u0159\u00e1du. Pokud na WEDOS Global Protection p\u0159id\u00e1te dom\u00e9nu, tak jsou automaticky chr\u00e1n\u011bny i subdom\u00e9ny.<\/p>\n\n\n\n<p>V z\u00e1\u0159\u00ed bylo zaznamen\u00e1no <strong>3 517 726 124<\/strong> (+33,01 %) po\u017eadavk\u016f z <strong>8 774 656<\/strong> (+3,3 %) unik\u00e1tn\u00edch IP adres, kter\u00e9 sm\u011b\u0159ovaly na chr\u00e1n\u011bn\u00e9 dom\u00e9ny. V pr\u016fm\u011bru za den odbavily proxy servery <strong>117&nbsp;257&nbsp;537<\/strong> po\u017eadavk\u016f. N\u00e1r\u016fst je zp\u016fsoben nov\u00fdmi z\u00e1kazn\u00edky (chr\u00e1n\u011bn\u00fdmi dom\u00e9nami), sez\u00f3nnost\u00ed (skon\u010dily pr\u00e1zdniny) a tak\u00e9 n\u00e1r\u016fstem L7 \u00fatok\u016f (zvl\u00e1\u0161t\u011b aktivitou p\u00e1kist\u00e1nsk\u00e9ho a \u010d\u00ednsk\u00e9ho mobiln\u00edho botnetu).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-1.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"524\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-1-1024x524.png\" alt=\"\" class=\"wp-image-311815 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-1-1024x524.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-1-300x153.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-1-768x393.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-1-1536x786.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-1.png 1842w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/524;\" \/><\/a><figcaption class=\"wp-element-caption\">Celkov\u00fd po\u010det request\u016f, kter\u00e9 se dostaly a\u017e k WEDOS Global Protection za z\u00e1\u0159\u00ed. 1. z\u00e1\u0159\u00ed je men\u0161\u00ed provoz z d\u016fvodu nekompletn\u00ed datov\u00e9 sady.<\/figcaption><\/figure>\n\n\n\n<p>N\u00e1r\u016fst oproti minul\u00e9mu m\u011bs\u00edci v \u010cR a SR je zp\u016fsoben hlavn\u011b sez\u00f3nnost\u00ed (konec pr\u00e1zdnin). U ostatn\u00edch zem\u00ed jsou to nav\u00edc \u00fatoky a nov\u00fd z\u00e1kazn\u00edci ze zahrani\u010d\u00ed, kte\u0159\u00ed maj\u00ed svou zahrani\u010dn\u00ed n\u00e1v\u0161t\u011bvnost.  U n\u011bkter\u00fdch zem\u00ed se po\u010det nav\u00fd\u0161il, proto\u017ee n\u00e1m p\u0159ib\u00fdvaj\u00ed weby zam\u011b\u0159en\u00e9 na hry a jejich hr\u00e1\u010di jsou z cel\u00e9ho sv\u011bta (zvl\u00e1\u0161t\u011b u mobiln\u00edch her).<\/p>\n\n\n\n<p>Co se t\u00fdk\u00e1 n\u00e1r\u016fstu z USA, tak to je hlavn\u011b zv\u00fd\u0161enou aktivitou robot\u016f (hlavn\u011b SEMrush a specifick\u00e9 IP adresy Amazon). SEMrush bota budeme muset vhodn\u00fdm zp\u016fsobem omezit, proto\u017ee n\u011bkter\u00fdm web\u016fm opravdu vad\u00ed. Amazon jede zv\u00fd\u0161en\u00e9 crawlov\u00e1n\u00ed ze 3 IP adres u\u017e od srpna, tam to budeme muset tak\u00e9 omezit (tyto 3 IP). Je toho v\u00edce. Robot\u016fm se m\u00e1me v pl\u00e1nu v\u011bnovat v \u0159\u00edjnu a rozhodnout se co d\u00e1l. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"818\" height=\"811\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn.png\" alt=\"\" class=\"wp-image-311819 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn.png 818w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn-300x297.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn-150x150.png 150w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn-768x761.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-a-asn-100x100.png 100w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 818px; --smush-placeholder-aspect-ratio: 818\/811;\" \/><\/a><figcaption class=\"wp-element-caption\">Odkud chod\u00ed p\u0159\u00edstupy na WEDOS Global Protection za z\u00e1\u0159\u00ed 2023.<\/figcaption><\/figure>\n\n\n\n<p>A co L7 \u00fatoky? Bylo v\u00edce \u00fatok\u016f na v\u00edce c\u00edl\u016f ne\u017e je obvykl\u00e9. N\u011bkter\u00e9 byly celkem siln\u00e9 (ve stovk\u00e1ch tis\u00edc request\u016f), co\u017e se prop\u00ed\u0161e do statistik. N\u00e1r\u016fst Slowloris, Connection Exhaustion atd. kompenzuje v\u00fdrazn\u00fd propad v srpnu. Blokov\u00e1no pravidlem WAF jsou z p\u0159ev\u00e1\u017en\u00e9 \u010d\u00e1sti \u00fatoky na WordPress a z men\u0161\u00ed \u010d\u00e1sti hled\u00e1n\u00ed obecn\u00fdch zranitelnost\u00ed. <\/p>\n\n\n\n<figure class=\"wp-block-table is-style-regular\"><table><tbody><tr><td>L7 DDoS &#8211; zachycen\u00fdch limitov\u00e1n\u00edm p\u0159\u00edstup\u016f (HTTP flood)<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>14&nbsp;295&nbsp;034<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">+142,86&nbsp;%<\/td><\/tr><tr><td>L7 DDoS &#8211; zachycen\u00fdch probl\u00e9mov\u00fdch spojen\u00ed (Slowloris, Connection Exhaustion atd.)<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>3 820 323<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">+566,97&nbsp;%<\/td><\/tr><tr><td>Blokov\u00e1no pravidlem WAF<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>26 112 821<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">+9,30&nbsp;%<\/td><\/tr><tr><td>Dal\u0161\u00ed blokov\u00e1n\u00ed L7<\/td><td class=\"has-text-align-right\" data-align=\"right\"><strong>6 145 289<\/strong><\/td><td class=\"has-text-align-right\" data-align=\"right\">+15,48 %<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">L7 \u00fatoky zastaven\u00e9 WGP, kter\u00e9 pro\u0161ly p\u0159es ostatn\u00ed ochrany.<\/figcaption><\/figure>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je L7 DDoS \u00fatok?<\/strong><\/p>\n\n\n\n<p>L7 DDoS \u00fatok je typ kybernetick\u00fdch \u00fatok\u016f na web anebo aplikaci, kter\u00fd pou\u017e\u00edv\u00e1 b\u011b\u017en\u00e9 internetov\u00e9 po\u017eadavky jako GET a POST. C\u00edlem je zpomalit anebo znep\u0159\u00edstupnit webovou str\u00e1nku anebo t\u0159eba API. <\/p>\n\n\n\n<p>\u00datoky na L7 jsou obt\u00ed\u017en\u011b odhaliteln\u00e9 a odli\u0161iteln\u00e9 od norm\u00e1ln\u00edho provozu, proto\u017ee pou\u017e\u00edvaj\u00ed stejn\u00e9 protokoly a metody jako legitimn\u00ed u\u017eivatel\u00e9. K jejich eliminaci je pot\u0159eba pou\u017e\u00edt speci\u00e1ln\u00ed n\u00e1stroje a techniky a d\u016fkladnou anal\u00fdzu s\u00ed\u0165ov\u00e9ho provozu.<\/p>\n<\/div><\/div>\n\n\n\n<p>Tato \u010d\u00edsla jsou jen prvn\u00ed pokusy o \u00fatok. Jakmile se jedn\u00e1 o opakovan\u00e9 pokusy, kter\u00e9 naberou na s\u00edle (t\u0159eba des\u00edtky tis\u00edc probl\u00e9mov\u00fdch p\u0159\u00edstup\u016f za minutu), tak IP adresa jde na blacklist. Je to v\u0161ak slo\u017eit\u011bj\u0161\u00ed, proto\u017ee k r\u016fzn\u00fdm IP se chov\u00e1me odli\u0161n\u011b (t\u0159eba mobiln\u00ed oper\u00e1tor dostane JavaScript redirekt anebo capcha). Stejn\u011b tak k odli\u0161n\u00fdm form\u00e1m \u00fatok\u016f.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co je WAF (Web Application Firewall)?<\/strong><\/p>\n\n\n\n<p>WAF (Web Application Firewall) je ochrana na na\u0161ich reverzn\u00edch proxy serverech, kter\u00e1 je um\u00edst\u011bna mezi \u00fato\u010dn\u00edkem a va\u0161\u00edm webem. V re\u00e1ln\u00e9m \u010dase proch\u00e1z\u00ed ka\u017ed\u00fd po\u017eadavek a hled\u00e1 v n\u011bm specifick\u00e9 znaky \u00fatoku anebo zneu\u017eit\u00ed bezpe\u010dnostn\u00ed d\u00edry. Pokud naraz\u00ed na podez\u0159el\u00fd po\u017eadavek, m\u016f\u017ee jej p\u0159esm\u011brovat na test (p\u0159esm\u011brov\u00e1n\u00ed, captcha) anebo zablokovat.<\/p>\n<\/div><\/div>\n\n\n\n<p>P\u0159\u00edsn\u011bj\u0161\u00ed ochrana WordPress web\u016f pomoc\u00ed WAF je vid\u011bt i na statistice nejv\u011bt\u0161\u00edch chr\u00e1n\u011bn\u00fdch web\u016f. Ty, kter\u00e9 pou\u017e\u00edvaj\u00ed WordPress, maj\u00ed v\u00edce zablokovan\u00fdch \u00fatok\u016f. Ov\u0161em nezapom\u00ednejte, \u017ee i kdy\u017e nepou\u017e\u00edv\u00e1te WordPress, neznamen\u00e1 to, \u017ee se n\u011bkdo nepokou\u0161\u00ed \u00fato\u010dit anebo hledat zranitelnost jako by jste tam WordPress m\u011bli, co\u017e zat\u011b\u017euje webserver.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-nejvetsi-weby.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"775\" height=\"799\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-nejvetsi-weby.png\" alt=\"\" class=\"wp-image-311895 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-nejvetsi-weby.png 775w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-nejvetsi-weby-291x300.png 291w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-isp-nejvetsi-weby-768x792.png 768w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 775px; --smush-placeholder-aspect-ratio: 775\/799;\" \/><\/a><figcaption class=\"wp-element-caption\">Nejv\u011bt\u0161\u00ed weby chr\u00e1n\u011bn\u00e9 WEDOS Global Protection podle po\u010dtu p\u0159\u00edstup\u016f za z\u00e1\u0159\u00ed.<\/figcaption><\/figure>\n\n\n\n<p>V z\u00e1\u0159\u00ed vzrostla aktivita \u00fato\u010dn\u00edk\u016f na v\u0161ech front\u00e1ch. Po del\u0161\u00ed dob\u011b se tak\u00e9 nenudila na\u0161e L3\/L4 DDoS ochrana. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">L3\/L4<\/h3>\n\n\n\n<p>Samoz\u0159ejm\u011b na\u0161i z\u00e1kazn\u00edci jsou tak\u00e9 pod klasick\u00fdmi L3\/L4 DDoS \u00fatoky. Nicm\u00e9n\u011b ve v\u011bt\u0161in\u011b p\u0159\u00edpad\u016f to nestoj\u00ed za \u0159e\u010d. Na\u0161e ochrany jsou stav\u011bny na \u00fatoky ve stovk\u00e1ch Gbps. V\u0161e pod 10 Gbps ani nepos\u00edl\u00e1 notifikaci technik\u016fm. V\u0161e \u0159e\u0161\u00ed automaty. V z\u00e1\u0159\u00ed v\u0161ak p\u00e1r notifikac\u00ed poslaly, abychom se ujistili, \u017ee je v\u0161e v po\u0159\u00e1dku.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide is-stacked-on-mobile is-vertically-aligned-center has-white-color has-vivid-cyan-blue-background-color has-text-color has-background\" style=\"grid-template-columns:20% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"385\" height=\"400\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png\" alt=\"\" class=\"wp-image-123898 size-full lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1.png 385w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/12\/ladik-rbt-1-289x300.png 289w\" data-sizes=\"(max-width: 385px) 100vw, 385px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 385px; --smush-placeholder-aspect-ratio: 385\/400;\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><strong>Co jsou L3\/L4 \u00fatoky?<\/strong><\/p>\n\n\n\n<p>DDoS \u00fatoky na L3 a L4 vrstv\u011b se zam\u011b\u0159uj\u00ed na s\u00ed\u0165ovou a transportn\u00ed vrstvu a vyu\u017e\u00edvaj\u00ed r\u016fzn\u00e9 techniky, jak zahlcovat c\u00edlov\u00e9 servery nebo za\u0159\u00edzen\u00ed.<br><br>S\u00ed\u0165ov\u00e1 vrstva (L3) &#8211; zaji\u0161\u0165uje sm\u011brov\u00e1n\u00ed dat mezi r\u016fzn\u00fdmi s\u00edt\u011bmi pomoc\u00ed logick\u00fdch adres (IP).<br><br>Transportn\u00ed vrstva (L4) &#8211; zaji\u0161\u0165uje spolehliv\u00fd a \u0159\u00edzen\u00fd p\u0159enos dat mezi koncov\u00fdmi body pomoc\u00ed protokol\u016f jako TCP nebo UDP.<\/p>\n<\/div><\/div>\n\n\n\n<p>Celkem jsme evidovali <strong>14 958<\/strong> (+128,13 %) DDoS \u00fatok\u016f. \u010c\u00e1ste\u010dn\u011b si to spojujeme i s na\u0161\u00ed ve\u0159ejnou nab\u00eddkou WEDOS Global Protection bank\u00e1m, kter\u00e9 \u010delily \u00fatok\u016fm hacktivistick\u00fdch skupin. N\u011bkdo si n\u00e1s prost\u011b cht\u011bl vyzkou\u0161et. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-l3-l4.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"493\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20231002-zari-l3-l4-1024x493.png\" alt=\"\" class=\"wp-image-311905 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-l3-l4-1024x493.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-l3-l4-300x145.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-l3-l4-768x370.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20231002-zari-l3-l4.png 1438w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/493;\" \/><\/a><figcaption class=\"wp-element-caption\">Tradi\u010dn\u00ed DDoS \u00fatoky za z\u00e1\u0159\u00ed.<\/figcaption><\/figure>\n\n\n\n<p>Tradi\u010dn\u00ed DDoS \u00fatoky prob\u00edhaj\u00ed trochu jinak. Je to v\u00edce druh\u016f \u00fatok\u016f nar\u00e1z. Tak\u017ee jednotliv\u00e9 \u00fatoky mohou m\u00edt t\u0159eba do 10 Gbps, ale ve v\u00fdsledku, kdy\u017e se to v\u0161echno spoj\u00ed, tak se dostanete k des\u00edtk\u00e1m anebo stovk\u00e1m Gbps. Pokud vezmeme nejsiln\u011bj\u0161\u00ed \u00fatok, tak vych\u00e1z\u00ed n\u00e1sledovn\u011b:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"508\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/L3-L4-utok-na-webhosting-20230918-1024x508.png\" alt=\"\" class=\"wp-image-311910 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/L3-L4-utok-na-webhosting-20230918-1024x508.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/L3-L4-utok-na-webhosting-20230918-300x149.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/L3-L4-utok-na-webhosting-20230918-768x381.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/L3-L4-utok-na-webhosting-20230918.png 1153w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/508;\" \/><\/figure>\n\n\n\n<p>\u00datok byl veden hrubou silou a&nbsp;celkem dos\u00e1hl ve \u0161pi\u010dce n\u011bco p\u0159es 30 Gbps a&nbsp;4,5 milion\u016f paket\u016f za vte\u0159inu. Shodou okolnost\u00ed v&nbsp;t\u00e9 dob\u011b prob\u00edhaly i&nbsp;dva men\u0161\u00ed \u00fatoky na 2 r\u016fzn\u00e1 VPS. Klidn\u011b to mohlo spolu souviset, ale tak\u00e9 nemuselo.<\/p>\n\n\n\n<p>Pro dne\u0161n\u00ed p\u0159ehled jsme v\u00e1m tak\u00e9 p\u0159ipravili tabulku nejsiln\u011bj\u0161\u00edch L3\/L4 jednotliv\u00fdch DDoS  \u00fatok\u016f za z\u00e1\u0159\u00ed 2023. \u00dato\u010dn\u00edci v\u011bt\u0161inou skl\u00e1daj\u00ed takov\u00e9to \u00fatoky do jednoho masivn\u00edho. <\/p>\n\n\n\n<figure class=\"wp-block-table is-style-regular\"><table><thead><tr><th class=\"has-text-align-center\" data-align=\"center\">vIP<\/th><th class=\"has-text-align-center\" data-align=\"center\">C\u00edl<\/th><th class=\"has-text-align-right\" data-align=\"right\">Paket\u016f ve \u0161pi\u010dce<\/th><th class=\"has-text-align-right\" data-align=\"right\">Bits\/s<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">2,0 M<\/td><td class=\"has-text-align-right\" data-align=\"right\">15,4 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">Webhosting<\/td><td class=\"has-text-align-right\" data-align=\"right\">1,9 M<\/td><td class=\"has-text-align-right\" data-align=\"right\">12,5 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">1,2 M<\/td><td class=\"has-text-align-right\" data-align=\"right\">12,2 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">Dedikovan\u00fd server<\/td><td class=\"has-text-align-right\" data-align=\"right\">1,2 M<\/td><td class=\"has-text-align-right\" data-align=\"right\">11,8 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">Infrastruktura<\/td><td class=\"has-text-align-right\" data-align=\"right\">1,1 M<\/td><td class=\"has-text-align-right\" data-align=\"right\">10,5 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">1,1 M<\/td><td class=\"has-text-align-right\" data-align=\"right\">10,2 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">633,8 k<\/td><td class=\"has-text-align-right\" data-align=\"right\">10,2 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">631,1 k<\/td><td class=\"has-text-align-right\" data-align=\"right\">10,0 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv6<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">599,1 k<\/td><td class=\"has-text-align-right\" data-align=\"right\">9,2 G<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">IPv4<\/td><td class=\"has-text-align-center\" data-align=\"center\">VPS<\/td><td class=\"has-text-align-right\" data-align=\"right\">599,1 k<\/td><td class=\"has-text-align-right\" data-align=\"right\">9,2 G<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Nejsiln\u011bj\u0161\u00ed L7 DDoS<\/h2>\n\n\n\n<p>Ka\u017ed\u00fd m\u011bs\u00edc pro v\u00e1s p\u0159ipravujeme seznam nejsiln\u011bj\u0161\u00edch DDoS \u00fatok\u016f p\u0159es L7.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. \u00fatok na wedos.com &#8211; \u0161pi\u010dka 2,1M po\u017eadavk\u016f za minutu<\/h2>\n\n\n\n<p>Koncem m\u011bs\u00edce jsme zaznamenali z\u0159ejm\u011b nejsiln\u011bj\u0161\u00ed n\u00e1razov\u00fd DDoS \u00fatok na n\u00e1\u0161 web a jeden z nejsiln\u011bj\u0161\u00edch L7 DDoS \u00fatok\u016f, kter\u00fd kdy \u0161el na WGP. Ve \u0161pi\u010dce to bylo p\u0159es 2,1M po\u017eadavk\u016f za minutu a \u00fatok byl veden z 4128 unik\u00e1tn\u00edch IP adres. Ochrana jej zvl\u00e1dla bez probl\u00e9m\u016f filtrovat. V logu jsme nena\u0161li \u017e\u00e1dnou chybu 502, 503 ani 504.  <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"424\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20230930-utok-na-wedos-com-1-1024x424.png\" alt=\"\" class=\"wp-image-311926 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230930-utok-na-wedos-com-1-1024x424.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230930-utok-na-wedos-com-1-300x124.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230930-utok-na-wedos-com-1-768x318.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230930-utok-na-wedos-com-1-1536x636.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230930-utok-na-wedos-com-1.png 1788w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/424;\" \/><\/figure>\n\n\n\n<p>Na n\u00e1\u0161 web pak \u0161ly v z\u00e1\u0159\u00ed  je\u0161t\u011b tyto zaj\u00edmav\u011bj\u0161\u00ed \u00fatoky:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Ve \u0161pi\u010dce 1,2M z 1286 UIP<\/li>\n\n\n\n<li>Ve \u0161pi\u010dce 879K z 2532 UIP<\/li>\n\n\n\n<li>Ve \u0161pi\u010dce 838K z 1516 UIP<\/li>\n<\/ul>\n\n\n\n<p>Kter\u00e9 by se um\u00edstili na dal\u0161\u00edch m\u00edstech. Nicm\u00e9n\u011b to by byla nuda \ud83d\ude42<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. \u00fatok na web sportovn\u00edho t\u00fdmu &#8211; 313 tis\u00edc po\u017eadavk\u016f ve \u0161pi\u010dce<\/h2>\n\n\n\n<p>Tohle n\u00e1s trochu p\u0159ekvapilo. Jeden sportovn\u00ed t\u00fdm se chystal na sv\u016fj velk\u00fd z\u00e1pas a propagace byla v pln\u00e9m proudu. N\u011bkdo se jim rozhodl to p\u0159ekazit men\u0161\u00edm DDoS \u00fatokem. Ve \u0161pi\u010dce to bylo 313 tis\u00edc po\u017eadavk\u016f za minutu. Celkem se \u00fatoku \u00fa\u010dastnilo 512 unik\u00e1tn\u00edch IP adres. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20230925-web-sportovniho-tymu-1024x377.png\" alt=\"\" class=\"wp-image-311936 lazyload\" style=\"--smush-placeholder-width: 674px; --smush-placeholder-aspect-ratio: 674\/248;width:674px;height:248px\" width=\"674\" height=\"248\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230925-web-sportovniho-tymu-1024x377.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230925-web-sportovniho-tymu-300x110.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230925-web-sportovniho-tymu-768x283.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230925-web-sportovniho-tymu-1536x565.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230925-web-sportovniho-tymu.png 1810w\" data-sizes=\"(max-width: 674px) 100vw, 674px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">3. \u00fatok na web politick\u00e9ho hnut\u00ed &#8211; 180 tis\u00edc po\u017eadavk\u016f ve \u0161pi\u010dce<\/h2>\n\n\n\n<p>Hostuje u n\u00e1s \u0159ada web\u016f politick\u00fdch stran, hnut\u00ed i jednotliv\u00fdch politik\u016f. Postupn\u011b jsme v\u011bt\u0161inu museli d\u00e1t za WGP, proto\u017ee dneska takov\u00fd web shod\u00ed pom\u011brn\u011b jednodu\u0161e i jeden \u00fato\u010dn\u00edk (sta\u010d\u00ed tis\u00edce po\u017eadavk\u016f za minutu).<\/p>\n\n\n\n<p>Nicm\u00e9n\u011b v tomto p\u0159\u00edpad\u011b to bylo o trochu siln\u011bj\u0161\u00ed. Jednalo se o dva samostatn\u00e9 \u00fatoky b\u011bhem jednoho dne. Siln\u011bj\u0161\u00ed m\u011bl 183 tis\u00edc po\u017eadavk\u016f ve \u0161pi\u010dce a \u0161el ze 133 unik\u00e1tn\u00edch IP adres. Druh\u00fd pak m\u011bl ve \u0161pi\u010dce 180 tis\u00edc po\u017eadavk\u016f za minutu a \u0161el ze 179 unik\u00e1tn\u00edch IP adres. <\/p>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"333\" data-id=\"313295\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti-1024x333.png\" alt=\"\" class=\"wp-image-313295 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti-1024x333.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti-300x98.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti-768x250.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti-1536x500.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-1-web-politickeho-hnuti.png 1816w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/333;\" \/><\/a><\/figure>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"334\" data-id=\"313293\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti-1024x334.png\" alt=\"\" class=\"wp-image-313293 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti-1024x334.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti-300x98.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti-768x250.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti-1536x501.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2023\/10\/20230922-2-web-politickeho-hnuti.png 1815w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/334;\" \/><\/a><\/figure>\n<\/figure>\n\n\n\n<p>Jak je vid\u011bt na grafech, tak prvn\u00ed \u00fatok rychle skon\u010dil ne\u00fasp\u011bchem. Druh\u00fd se pokou\u0161el &#8222;procpat&#8220; r\u016fzn\u00fdmi zp\u016fsoby, ale bez v\u011bt\u0161\u00edho \u00fasp\u011bchu. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Z\u00e1v\u011br<\/h2>\n\n\n\n<p>Po\u010det z\u00e1kazn\u00edk\u016f vyu\u017e\u00edvaj\u00ed WEDOS Global Protection roste, zvl\u00e1\u0161t\u011b t\u011bch, kte\u0159\u00ed aktu\u00e1ln\u011b n\u011bjak\u00fd probl\u00e9m s \u00fatoky  \u0159e\u0161\u00ed. Tak\u017ee p\u0159ib\u00fdv\u00e1 i \u00fatok\u016f. Obracej\u00ed se na n\u00e1s tak\u00e9 velk\u00e9 spole\u010dnosti a instituce. Tam to v\u0161ak je zat\u00edm hlavn\u011b o testov\u00e1n\u00ed a opatrn\u00e9mu p\u0159\u00edstupu obecn\u011b. V\u011b\u0159\u00edme, \u017ee za p\u00e1r t\u00fddn\u016f \u010di m\u011bs\u00edc\u016f na\u0161e slu\u017eby vyu\u017eij\u00ed, a pak se t\u0159eba \u00fatoky na n\u011b objev\u00ed i v t\u011bchto statistik\u00e1ch.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>V z\u00e1\u0159\u00ed jsme oproti pr\u00e1zdninov\u00fdm m\u011bs\u00edc\u016fm zaznamenali i vzr\u016fstaj\u00edc\u00ed po\u010det \u00fatok\u016f. V dne\u0161n\u00edm reportu se pod\u00edv\u00e1me po del\u0161\u00ed dob\u011b na &#8222;siln\u011bj\u0161\u00ed&#8220; DDoS \u00fatoky na L3\/L4 a zat\u00edm z\u0159ejm\u011b na nejsiln\u011bj\u0161\u00ed L7 DDoS \u00fatok co do po\u010dtu po\u017eadavk\u016f za minutu. Samoz\u0159ejm\u011b probereme i budov\u00e1n\u00ed WEDOS Global Protection a na \u010dem aktu\u00e1ln\u011b pracujeme.<\/p>\n","protected":false},"author":2,"featured_media":313326,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[112],"tags":[204,203,122,200,186,177],"class_list":["post-307521","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost","tag-cache","tag-cdn","tag-ddos","tag-waf","tag-wedos-global","tag-wedos-global-protection"],"_links":{"self":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/307521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/comments?post=307521"}],"version-history":[{"count":9,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/307521\/revisions"}],"predecessor-version":[{"id":331531,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/307521\/revisions\/331531"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media\/313326"}],"wp:attachment":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media?parent=307521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/categories?post=307521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/tags?post=307521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}