{"id":88670,"date":"2022-01-20T11:33:20","date_gmt":"2022-01-20T10:33:20","guid":{"rendered":"https:\/\/blog.wedos.cz\/?p=88670"},"modified":"2022-02-08T09:59:11","modified_gmt":"2022-02-08T08:59:11","slug":"zacinaji-se-objevovat-pripady-vydirani-ddos-utoky-na-aplikacni-vrstve","status":"publish","type":"post","link":"https:\/\/blog.wedos.com\/cs\/zacinaji-se-objevovat-pripady-vydirani-ddos-utoky-na-aplikacni-vrstve","title":{"rendered":"Za\u010d\u00ednaj\u00ed se objevovat p\u0159\u00edpady vyd\u00edr\u00e1n\u00ed DDoS \u00fatoky na aplika\u010dn\u00ed vrstv\u011b"},"content":{"rendered":"\n<p>Vyd\u00edr\u00e1n\u00ed DDoS \u00fatokem nen\u00ed nic nov\u00e9ho. Velk\u00e9 botnety dok\u00e1\u017eou prov\u00e9st v dne\u0161n\u00ed dob\u011b pom\u011brn\u011b siln\u00fd \u00fatok, kter\u00fd bez probl\u00e9m\u016f ucpe i n\u011bkolik 100 Gbps tras (<a href=\"https:\/\/blog.wedos.cz\/jak-probihal-zrejme-nejsilnejsi-ddos-utok-v-cesku\" target=\"_blank\" rel=\"noopener\">ji\u017e jsme se s t\u00edm setkali<\/a>). Na\u0161t\u011bst\u00ed jsou pom\u011brn\u011b vz\u00e1cn\u00e9, proto\u017ee jsou drah\u00e9. Se st\u0159edn\u00edmi \u00fatoky (nad 10 Gbps) se setk\u00e1v\u00e1me u\u017e \u010dast\u011bji (i n\u011bkolikr\u00e1t za m\u011bs\u00edc). A men\u0161\u00ed (pod 10 Gbps) jsou t\u00e9m\u011b\u0159 na denn\u00edm po\u0159\u00e1dku. Jen\u017ee tento klasick\u00fd druh \u00fatoku hrubou silou (objemem dat anebo po\u010dtem paket\u016f), se pom\u011brn\u011b dob\u0159e detekuje a filtruje. Hor\u0161\u00ed je to s \u00fatoky na aplika\u010dn\u00ed vrstv\u011b, takov\u00e9 kter\u00e9 se sna\u017e\u00ed tv\u00e1\u0159it jako b\u011b\u017en\u00e1 n\u00e1v\u0161t\u011bvnost.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>\u00datok na aplika\u010dn\u00ed vrstv\u011b (tak\u00e9 ozna\u010dovan\u00fd jako Layer 7 attack) je vesm\u011bs velice jednoduch\u00fd, ale p\u0159esto nen\u00ed snadn\u00e9 jej ihned detekovat a zabr\u00e1nit mu. M\u016f\u017ee se jednat o opakovan\u00e9 vol\u00e1n\u00ed n\u011bjak\u00e9 konkr\u00e9tn\u00ed str\u00e1nky, kdy vs\u00e1z\u00ed \u00fato\u010dn\u00edk na to, \u017ee vygeneruje v\u00edce dotaz\u016f, ne\u017e c\u00edlov\u00fd server zvl\u00e1dne zpracovat anebo vol\u00e1n\u00ed mohou b\u00fdt rozlo\u017eena na v\u00edce str\u00e1nek s c\u00edlem znesnadnit detekci, p\u0159\u00edpadn\u011b hledat necachovan\u00fd obsah (tento druh \u00fatoku jsme popsali v \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/prichazi-vlna-novych-a-zakernych-utoku-a-wedos-je-na-ne-pripraveny\" target=\"_blank\" rel=\"noopener\">P\u0159ich\u00e1z\u00ed vlna nov\u00fdch a z\u00e1ke\u0159n\u00fdch \u00fatok\u016f a WEDOS je na n\u011b p\u0159ipraven\u00fd<\/a>). <\/p>\n\n\n\n<p>V prvn\u00ed p\u0159\u00edpad\u011b, kdy je \u00fatok sm\u011b\u0159ovan\u00fd na jednu konkr\u00e9tn\u00ed str\u00e1nku, jsou n\u00e1klady pro \u00fato\u010dn\u00edka ni\u017e\u0161\u00ed, tak\u017ee takov\u00fdch \u00fatok\u016f m\u016f\u017ee prov\u00e1d\u011bt n\u011bkolik nar\u00e1z. Kdy\u017e si to p\u011bkn\u011b zautomatizuje a spoj\u00ed s vyd\u00edr\u00e1n\u00edm, tak si z\u0159ejm\u011b p\u0159ijde i na p\u011bkn\u00e9 pen\u00edze. Chcete v\u011bd\u011bt, jak to prob\u00edh\u00e1?<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Jak chod\u00ed \u017e\u00e1dosti o v\u00fdpaln\u00e9<\/h2>\n\n\n\n<p>Z\u00e1kazn\u00edk v\u011bt\u0161inou netu\u0161\u00ed, co se d\u011bje. V tomto konkr\u00e9tn\u00edm p\u0159\u00edpad\u011b n\u00e1m z\u00e1kazn\u00edk prost\u011b napsal na podporu, \u017ee mu nejde web (eshop). Podpora to p\u0159edala technikovi, kter\u00fd u\u017e mu za cca 20 minut odepsal, \u017ee jsou na n\u011bj vedeny \u00fatoky, kter\u00e9 ve \u0161pi\u010dk\u00e1ch dosahuj\u00ed 50 tis\u00edc request\u016f (dotaz\u016f na server) za 30 vte\u0159in. Vzhledem k z\u00e1va\u017enosti \u00fatoku a d\u00edky tomu, \u017ee m\u011bl z\u00e1kazn\u00edk DNS veden\u00e9 u n\u00e1s, jsme mu rovnou v kooperaci s kolegy, co vyv\u00edj\u00ed na\u0161i novou ochranu WEDOS Global Protection, rovnou nastavili.<\/p>\n\n\n\n<p>Z\u00e1kazn\u00edk netrp\u011bliv\u011b p\u00ed\u0161e, co s t\u00edm m\u016f\u017ee s\u00e1m d\u011blat. Do komunikace se vkl\u00e1d\u00e1 n\u00e1\u0161 \u0161\u00e9f a vysv\u011btluje mu, \u017ee nic. Objem request\u016f je tak velk\u00fd, \u017ee z\u00e1kazn\u00edk nem\u016f\u017ee ud\u011blat nic. P\u0159ed\u00e1 mu dal\u0161\u00ed statistiky a tak\u00e9 kam \u00fatok sm\u011b\u0159uje. <\/p>\n\n\n\n<p>Ve spolupr\u00e1ci se sv\u00fdm v\u00fdvoj\u00e1\u0159em se z\u00e1kazn\u00edk pokus\u00ed odstranit str\u00e1nku, na kterou je \u00fatok veden. To vede k velk\u00e9mu mno\u017estv\u00ed chyb 404 (str\u00e1nka neexistuje). Ty server odbavuje l\u00e9pe, ale jednak to ne\u0159e\u0161\u00ed \u00fatok samotn\u00fd (\u00fato\u010dn\u00edk m\u016f\u017ee URL op\u011bt zm\u011bnit) a tak\u00e9 webserver st\u00e1le mus\u00ed \u0159e\u0161it p\u0159ipojen\u00ed. <\/p>\n\n\n\n<p>V dal\u0161\u00ed konverzaci je\u0161t\u011b \u0161\u00e9f vysv\u011btluje z\u00e1kazn\u00edkovi, \u017ee to nen\u00ed ni\u010d\u00ed vina a s\u00e1m to opravdu nem\u016f\u017ee vy\u0159e\u0161it, <strong>&#8222;prost\u011b si na n\u011bj n\u011bkdo zasedl&#8220;<\/strong>. <\/p>\n\n\n\n<p>Z\u00e1kazn\u00edk na to reaguje, p\u0159eposl\u00e1n\u00edm vyd\u011bra\u010dsk\u00e9ho e-mailu, kter\u00fd mu ten den dorazil. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>P\u0159edm\u011bt: DDoS<\/p><\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>Hey,<br>as a ransom we want $3000 in Bitcoin for stopping all DDoS attacks.<br>After<br>payment, your service will resume as it was automatically.<br>BTC-Wallet: *****************************************<br>Thank you for your attention and have a nice rest of the day,<br>Dark Side<\/p><\/blockquote>\n\n\n\n<p>Na to mu \u0161\u00e9f p\u00ed\u0161e, \u017ee nem\u00e1 rozhodn\u011b nic platit. Na\u0161e ochrana to vy\u0159e\u0161\u00ed.<\/p>\n\n\n\n<p>Mimochodem v p\u016fvodn\u00ed konverzaci s podporou zm\u00ednil, \u017ee se jednalo o opakovan\u00fd v\u00fdpadek. Zkusili jsme pro \u00fa\u010dely tohoto \u010dl\u00e1nku dohledat statistiky na serveru a na\u0161li jsme p\u0159et\u00ed\u017een\u00ed webhostingu p\u0159esn\u011b o t\u00fdden p\u0159edt\u00edm. To vedlo k \u0159ad\u011b chyb 503. Tehdy to technici nijak dopodrobna nezkoumali. Vypadalo to na nezvl\u00e1dnutou n\u00e1razovou n\u00e1v\u0161t\u011bvnost, a tak byl z\u00e1kazn\u00edk p\u0159esunut na speci\u00e1ln\u00ed server pro &#8222;p\u0159et\u011b\u017eova\u010de&#8220;, aby se to nedotklo ostatn\u00edch z\u00e1kazn\u00edk\u016f na stejn\u00e9m fyzick\u00e9m serveru. <\/p>\n\n\n\n<p>I vzhledem k tomu, musel \u00fato\u010dn\u00edk tentokr\u00e1t o dost p\u0159itvrdit. Proto\u017ee tyto servery jsou optimalizovan\u00e9 pr\u00e1v\u011b na n\u00e1razovou n\u00e1v\u0161t\u011bvnost. Pokud m\u00e1 z\u00e1kazn\u00edk dob\u0159e optimalizovan\u00fd web (vyu\u017e\u00edv\u00e1 cache atd.), tak ustoj\u00ed opravdu hodn\u011b (p\u00e1r p\u0159\u00edklad\u016f najdete v \u010dl\u00e1nku <a href=\"https:\/\/blog.wedos.cz\/20-webu-s-nejvetsi-navstevnosti-na-nolimit-nolimit-extra-a-wms-za-24-hodin-v-utery-18-01-2022\" target=\"_blank\" rel=\"noopener\">20 web\u016f s nejv\u011bt\u0161\u00ed n\u00e1v\u0161t\u011bvnost\u00ed na NoLimit, NoLimit Extra a WMS<\/a>). <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Anatomie \u00fatoku<\/h2>\n\n\n\n<p>\u00datok je opravdu jednoduch\u00fd. N\u00e1razov\u011b v kr\u00e1tk\u00fdch intervalech je vol\u00e1na jedna konkr\u00e9tn\u00ed URL c\u00edlov\u00e9ho webu. \u0160kodliv\u00fd provoz jde z napaden\u00fdch za\u0159\u00edzen\u00ed p\u0159es HTTP z mnoha IP adres. \u00datok tedy prov\u00e1d\u00ed n\u011bjak\u00fd v\u011bt\u0161\u00ed botnet. Kdy\u017e \u00fato\u010dn\u00edk zjist\u00ed, \u017ee je web nedostupn\u00fd, tak chvilku p\u0159estane. Pot\u00e9, co web nab\u011bhne \u00fatok opakuje. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"274\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody-1024x274.png\" alt=\"\" class=\"wp-image-88679 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody-1024x274.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody-300x80.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody-768x205.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody-1536x410.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-hosting-stavove-kody.png 1755w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/274;\" \/><\/a><figcaption>Statistiky z webserveru pro napaden\u00fd web.<\/figcaption><\/figure>\n\n\n\n<p>Z\u00e1kazn\u00edk se n\u00e1m na\u0161t\u011bst\u00ed ozval brzy a v pr\u00e1ci u po\u010d\u00edta\u010de byli i kolegov\u00e9, kte\u0159\u00ed vyv\u00edj\u00ed ochranu WEDOS Global Protection. Rychle jej p\u0159idali mezi chr\u00e1n\u011bn\u00e9 weby a upravili DNS z\u00e1znam, aby provoz \u0161el p\u0159es ochranu. Okam\u017eit\u011b na to za\u010dali zachyt\u00e1vat \u00fatoky.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"171\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana-1024x171.png\" alt=\"\" class=\"wp-image-88685 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana-1024x171.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana-300x50.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana-768x128.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana-1536x257.png 1536w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-time-series-ochrana.png 1704w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/171;\" \/><\/a><figcaption>Statistiky z ochrany WEDOS Global Protection<\/figcaption><\/figure>\n\n\n\n<p>Jak vid\u00edte, tak b\u011bhem 1 minuty ve \u0161pi\u010dce p\u0159i\u0161lo p\u0159es 91 tis\u00edc z\u00e1vadn\u00fdch request\u016f na c\u00edlovou str\u00e1nku, kterou ochrana zastavila.<\/p>\n\n\n\n<p>Kolegov\u00e9 si s t\u00edm trochu hr\u00e1li a zkou\u0161eli tam, jak tento druh \u00fatoku, co mo\u017en\u00e1 nejl\u00e9pe filtrovat. St\u0159\u00eddali tam r\u016fzn\u00e9 formy p\u0159ek\u00e1\u017eek pro \u00fato\u010dn\u00edka (cookie, redirect, captcha) a trochu to optimalizovali. Sta\u010dilo v\u0161ak trochu povolit uzdu a i t\u011bch &#8222;p\u00e1r&#8220; set request\u016f co za minutu pro\u0161lo, dok\u00e1zalo nap\u00e1chat \u0161kody. <\/p>\n\n\n\n<p><strong>N\u00e1sleduj\u00edc\u00ed statistiky jsou z dat webserveru. Tedy to, co se do logu zapsalo p\u0159ed nasazen\u00edm ochrany a to co pro\u0161lo, kdy\u017e kolegov\u00e9 kalibrovali ochranu. P\u0159ed t\u00edm v\u0161\u00edm nav\u00edc je\u0161t\u011b stoj\u00ed n\u00e1\u0161 velk\u00fd filtr, kter\u00fd blokuje IP adresy se \u0161patnou reputac\u00ed, kter\u00fdch jsou tam stovky tis\u00edc.<\/strong><\/p>\n\n\n\n<p>V tomto p\u0159\u00edpad\u011b to byl sp\u00ed\u0161e takov\u00fd n\u00edzkorozpo\u010dtov\u00fd \u00fatok. Jednotliv\u00e9 requesty se nesna\u017eily nijak maskovat. Sice generovali v hlavi\u010dce r\u016fzn\u00e9 prohl\u00ed\u017ee\u010de a opera\u010dn\u00ed syst\u00e9my, ale hned podle n\u011bkolika indici\u00ed se dalo poznat, \u017ee jsou to \u00fatoky a ne re\u00e1ln\u00fd provoz. Daly by se tedy zastavit i p\u0159es IDS\/IPS ochranu s vhodnou konfigurac\u00ed. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-hlavicka.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1024\" height=\"654\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-hlavicka-1024x654.png\" alt=\"\" class=\"wp-image-88691 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-hlavicka-1024x654.png 1024w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-hlavicka-300x191.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-hlavicka-768x490.png 768w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-hlavicka.png 1233w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1024px; --smush-placeholder-aspect-ratio: 1024\/654;\" \/><\/a><figcaption>Hlavi\u010dky request\u016f \u00fatoku podle po\u010dtu a unik\u00e1tn\u00edch IP.<\/figcaption><\/figure>\n\n\n\n<p>Co se t\u00fdk\u00e1 zdroje \u00fatoku, tak v\u011bt\u0161ina \u00fato\u010d\u00edc\u00edch IP adres byla z Asie a Ameriky. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-kontinent.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"1021\" height=\"262\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-kontinent.png\" alt=\"\" class=\"wp-image-88697 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-kontinent.png 1021w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-kontinent-300x77.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-kontinent-768x197.png 768w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 1021px; --smush-placeholder-aspect-ratio: 1021\/262;\" \/><\/a><figcaption>Rozd\u011blen\u00ed \u00fatok\u016f podle kontinent\u016f.<\/figcaption><\/figure>\n\n\n\n<p>Sami byste si je blokovat nezvl\u00e1dli (nap\u0159\u00edklad p\u0159es .htacces). \u00dato\u010dn\u00edk se sna\u017eil prov\u00e9st \u00fatok v\u017edy v jeden okam\u017eik. Bylo to sp\u00ed\u0161e n\u011bco jako 10 vte\u0159in \u00fatok, 50 vte\u0159in pauza. Takov\u00fd test, jestli web \u017eije. A opakovat.<\/p>\n\n\n\n<p>Samoz\u0159ejm\u011b spr\u00e1vci serveru maj\u00ed v\u00edce mo\u017enost\u00ed jak blokovat rychle cel\u00e9 IP rozsahy. Nicm\u00e9n\u011b pokud je s v\u00e1mi na serveru v\u00edce z\u00e1kazn\u00edk\u016f, tak jim rozhodn\u011b necht\u011bj\u00ed od\u0159\u00edznout dlouhodob\u011b Evropu. Zvl\u00e1\u0161t\u011b st\u00e1ty jako Slovensko a Polsko.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-evropa.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"997\" height=\"827\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-evropa.png\" alt=\"\" class=\"wp-image-88702 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-evropa.png 997w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-evropa-300x249.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-tabulka-zdroj-utoku-evropa-768x637.png 768w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 997px; --smush-placeholder-aspect-ratio: 997\/827;\" \/><\/a><figcaption>Rozd\u011blen\u00ed \u00fatok\u016f podle st\u00e1t\u016f v Evrop\u011b.<\/figcaption><\/figure>\n\n\n\n<p>Nicm\u00e9n\u011b i pokud byste od\u0159\u00edzli naprosto v\u0161echno a nechali tam jen \u010ceskou republiku, tak si stejn\u011b nepom\u016f\u017eete. Jak vid\u00edte na n\u00e1sleduj\u00edc\u00edm grafu, \u00fatoky \u0161ly i p\u0159es \u010desk\u00e9 IP adresy a bylo jich dost. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-ip-ceske.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"866\" height=\"567\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/utok-na-web-18-ip-ceske.png\" alt=\"\" class=\"wp-image-88707 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-ip-ceske.png 866w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-ip-ceske-300x196.png 300w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/utok-na-web-18-ip-ceske-768x503.png 768w\" data-sizes=\"(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 866px; --smush-placeholder-aspect-ratio: 866\/567;\" \/><\/a><figcaption>Rozd\u011blen\u00ed \u00fatok\u016f podle IP adres v \u010cR<\/figcaption><\/figure>\n\n\n\n<p>Proj\u00edt si je m\u016f\u017eete na <a href=\"https:\/\/www.abuseipdb.com\/check\/\" target=\"_blank\" rel=\"noopener\">abuseipdb.com\/check\/<\/a> jedn\u00e1 se p\u0159ev\u00e1\u017en\u011b o IP adresy \u010desk\u00fdch internetov\u00fdch poskytovatel\u016f, kter\u00e9 jsou \u010dasto reportovan\u00e9, \u017ee z nich chod\u00ed \u00fatoky.<\/p>\n\n\n\n<figure class=\"wp-block-gallery columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\"><ul class=\"blocks-gallery-grid\"><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-1.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"502\" height=\"348\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-1.png\" alt=\"\" data-id=\"88727\" data-full-url=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-1.png\" data-link=\"https:\/\/blog.wedos.cz\/?attachment_id=88727\" class=\"wp-image-88727 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-1.png 502w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-1-300x208.png 300w\" data-sizes=\"(max-width: 502px) 100vw, 502px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 502px; --smush-placeholder-aspect-ratio: 502\/348;\" \/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-e1642672175603.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"511\" height=\"397\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-e1642672546718.png\" alt=\"\" data-id=\"88721\" data-full-url=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-e1642672175603.png\" data-link=\"https:\/\/blog.wedos.cz\/?attachment_id=88721\" class=\"wp-image-88721 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-e1642672546718.png 511w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-e1642672546718-300x233.png 300w\" data-sizes=\"(max-width: 511px) 100vw, 511px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 511px; --smush-placeholder-aspect-ratio: 511\/397;\" \/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-3.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"511\" height=\"358\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-3.png\" alt=\"\" data-id=\"88735\" data-full-url=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-3.png\" data-link=\"https:\/\/blog.wedos.cz\/?attachment_id=88735\" class=\"wp-image-88735 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-3.png 511w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-3-300x210.png 300w\" data-sizes=\"(max-width: 511px) 100vw, 511px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 511px; --smush-placeholder-aspect-ratio: 511\/358;\" \/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-2.png\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" width=\"517\" height=\"353\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-2.png\" alt=\"\" data-id=\"88731\" data-full-url=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/obrazek-2.png\" data-link=\"https:\/\/blog.wedos.cz\/?attachment_id=88731\" class=\"wp-image-88731 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-2.png 517w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/obrazek-2-300x205.png 300w\" data-sizes=\"(max-width: 517px) 100vw, 517px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 517px; --smush-placeholder-aspect-ratio: 517\/353;\" \/><\/a><\/figure><\/li><\/ul><\/figure>\n\n\n\n<p>Mo\u017en\u00e1 si \u0159\u00edk\u00e1te, \u017ee takov\u00e9to IP adresy by bylo nejlep\u0161\u00ed n\u011bjak permanentn\u011b omezit, kdy\u017e z nich chod\u00ed \u00fatoky na v\u0161echny strany. Jenom\u017ee za nimi m\u016f\u017ee klidn\u011b b\u00fdt jeden panel\u00e1k, ulice anebo i cel\u00e9 m\u011bsto. Tak\u00e9 m\u016f\u017ee b\u00fdt IP adresa dynamicky p\u0159id\u011blov\u00e1na.  Pokud ji tedy n\u011bjak z\u00e1sadn\u011b omez\u00edte, tak to bude m\u00edt dopad na ostatn\u00ed. P\u0159ijdou o n\u00e1v\u0161t\u011bvn\u00edky, z\u00e1kazn\u00edky anebo nebudou moct poskytnout sjednanou slu\u017ebu. S banov\u00e1n\u00edm a omezov\u00e1n\u00edm IP adres to nen\u00ed tak jednoduch\u00e9.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Jak\u00e9 budeme m\u00edt \u0159e\u0161en\u00ed pro tyto probl\u00e9mov\u00e9 \u00fatoky?<\/h2>\n\n\n\n<p>Prozat\u00edm ide\u00e1ln\u00ed \u0159e\u0161en\u00ed hled\u00e1me. Zat\u00edm to vypad\u00e1 na kombinaci cookie\/p\u0159esm\u011brov\u00e1n\u00ed v p\u0159\u00edpad\u011b, \u017ee probl\u00e9mov\u00e1 IP adresa a request z n\u00ed bude vykazovat podez\u0159el\u00e9 chov\u00e1n\u00ed, p\u0159\u00edpadn\u011b bude m\u00edt podez\u0159elou hlavi\u010dku. Pak by p\u0159\u00edchoz\u00ed na v\u00e1\u0161 web 1x uvid\u011bl n\u00e1sleduj\u00edc\u00ed str\u00e1nku, kde by do\u0161lo k rychl\u00e9mu p\u0159esm\u011brov\u00e1n\u00ed. \u00datok by t\u00edmto nepro\u0161el.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" width=\"685\" height=\"624\" data-src=\"https:\/\/blog.wedos.cz\/wp-content\/uploads\/2022\/01\/wedos-global-protection-presmerovani.png\" alt=\"\" class=\"wp-image-88760 lazyload\" data-srcset=\"https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/wedos-global-protection-presmerovani.png 685w, https:\/\/blog.wedos.com\/wp-content\/uploads\/2022\/01\/wedos-global-protection-presmerovani-300x273.png 300w\" data-sizes=\"(max-width: 685px) 100vw, 685px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 685px; --smush-placeholder-aspect-ratio: 685\/624;\" \/><\/figure>\n\n\n\n<p>Podle n\u00e1s je to dobr\u00fd kompromis. Nejlep\u0161\u00ed na tom je, \u017ee takto budeme moct k v\u00e1m pou\u0161t\u011bt i jinak obecn\u011b probl\u00e9mov\u00e9 IP adresy, jako jsou nap\u0159\u00edklad exit TOR nody. Ty maj\u00ed slou\u017eit k anonymn\u00edmu proch\u00e1zen\u00ed webu, ale ve v\u011bt\u0161in\u011b p\u0159\u00edpad\u016f jsou s nimi jen probl\u00e9my, proto\u017ee je n\u011bkdo zneu\u017e\u00edv\u00e1 k \u00fatok\u016fm. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Z\u00e1v\u011br<\/h2>\n\n\n\n<p><strong>Podobn\u00fdch \u00fatok\u016f bude p\u0159ib\u00fdvat.<\/strong> Je t\u0159eba se na to p\u0159ipravit. Na rozd\u00edl od ransomware, kde dojde k za\u0161ifrov\u00e1n\u00ed va\u0161ich dat v\u011bt\u0161inou va\u0161\u00ed vinnou, tak v tomto p\u0159\u00edpad\u011b nemus\u00edte nic ud\u011blat \u0161patn\u011b. \u00dato\u010dn\u00edci si v\u00e1s ani nemus\u00ed vytipovat. Prost\u011b jejich robot najde aktivn\u00ed eshop, zjist\u00ed e-mail, vytvo\u0159\u00ed unik\u00e1tn\u00ed BTC pen\u011b\u017eenku, po\u0161le v\u00e1m v\u00fdhru\u017en\u00fd e-mail a rozjede \u00fatok. Do toho v\u00e1m ten vyd\u011bra\u010dsk\u00fd e-mail spadne do spamu a u\u017e netu\u0161\u00edte v\u016fbec nic.<\/p>\n\n\n\n<p>V\u011b\u0159\u00edme, \u017ee n\u011b\u017e se tento trend rozjede naplno, tak u\u017e budeme m\u00edt ochranu spu\u0161t\u011bnou, odlad\u011bnou a nasazenou \ud83d\ude42<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Vyd\u00edr\u00e1n\u00ed DDoS \u00fatokem nen\u00ed nic nov\u00e9ho. Velk\u00e9 botnety dok\u00e1\u017eou prov\u00e9st v dne\u0161n\u00ed dob\u011b pom\u011brn\u011b siln\u00fd \u00fatok, kter\u00fd bez probl\u00e9m\u016f ucpe i n\u011bkolik 100 Gbps tras (ji\u017e jsme se s t\u00edm setkali). Na\u0161t\u011bst\u00ed jsou pom\u011brn\u011b vz\u00e1cn\u00e9, proto\u017ee jsou drah\u00e9. Se st\u0159edn\u00edmi \u00fatoky (nad 10 Gbps) se setk\u00e1v\u00e1me u\u017e \u010dast\u011bji (i n\u011bkolikr\u00e1t za m\u011bs\u00edc). A men\u0161\u00ed (pod &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.wedos.com\/cs\/zacinaji-se-objevovat-pripady-vydirani-ddos-utoky-na-aplikacni-vrstve\" class=\"more-link\">Pokra\u010dovat ve \u010dten\u00ed<span class=\"screen-reader-text\"> &#8222;Za\u010d\u00ednaj\u00ed se objevovat p\u0159\u00edpady vyd\u00edr\u00e1n\u00ed DDoS \u00fatoky na aplika\u010dn\u00ed vrstv\u011b&#8220;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":88778,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[112],"tags":[149,122,180,182,177],"class_list":["post-88670","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezpecnost","tag-botnet","tag-ddos","tag-kyberbezpecnost","tag-layer-7-attack","tag-wedos-global-protection"],"_links":{"self":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/88670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/comments?post=88670"}],"version-history":[{"count":10,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/88670\/revisions"}],"predecessor-version":[{"id":89256,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/88670\/revisions\/89256"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media\/88778"}],"wp:attachment":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media?parent=88670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/categories?post=88670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/tags?post=88670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}