{"id":529,"date":"2008-02-25T04:14:11","date_gmt":"2008-02-25T04:14:11","guid":{"rendered":"http:\/\/blografia.net\/vicm3\/?p=529"},"modified":"2008-02-25T04:14:11","modified_gmt":"2008-02-25T04:14:11","slug":"a-que-el-spam","status":"publish","type":"post","link":"https:\/\/blografia.net\/vicm3\/2008\/02\/a-que-el-spam\/","title":{"rendered":"A que el \u00b7$@! spam"},"content":{"rendered":"<p>En los comentarios, los bots exploiters y monadas asi&#8230; bueno a ver si le meto mas contenido despues, pero he estado jugando con la configuraci\u00f3n de lighttpd para evitar a estos jijos de la ma\u00f1ana.<br \/>\n[code=&#8217;Apache&#8217;]<br \/>\n# deny access for russian trackbacks&#8230; DONE.<br \/>\n$HTTP[\u00abquerystring\u00bb] =~ \u00abtrackback\u00bb {<br \/>\n                        url.access-deny = ( \u00ab\u00bb )<br \/>\n                                }<br \/>\n# forget that, get over with the perl bots<\/p>\n<p>$HTTP[\u00abuseragent\u00bb] =~ \u00ablibwww-\u00bb {<br \/>\n       url.access-deny = ( \u00ab\u00bb )<br \/>\n         }<br \/>\n# Now get evasive to avoid spam BOTS on comments (too many simultaneous conn)<br \/>\nevasive.max-conns-per-ip = 3<\/p>\n<p>[\/code]<\/p>\n<p>Tambien ya me deshice de los rusos.. leyendo un poco sobre las directivas (cosa que debi hacer desde el principio) ya vi todos los posibles valores de $HTTP y voila quedo resuelto el asunto de los trackbacks. (update 4:37am)<\/p>\n<p>Update (1\/3\/08 12:43pm)<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/ociologos.org\/albums\/album47\/memory_day_002.png\"> <\/p>\n<p>Uso de memoria actual<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/ociologos.org\/albums\/album47\/memory_week_002.png\"><\/p>\n<p>Uso de memoria en la semana, se puede ver que con las reglas que a\u00f1adi, mejoramos el uso de memoria y por ende de todos los servicios, es interesante saber que enero y febrero fueron cuando m\u00e1s nos pegar\u00f3n, aun cuando lo venian haciendo desde diciembre. cerca del final (dia 24) hay un pico en el uso de memoria, esto debido a que quite las reglas de iptables que estaban practicamente bloqueando tres clases C Rusas (y que no estaban funcionando, muy bien).<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/ociologos.org\/albums\/album47\/memory_month_001.png\"><\/p>\n<p>Uso de memoria en el mes, en la semana 8 fue cuando recibimos m\u00e1s peticiones de spam, vease el uso del swap de manera constante. !Total que la cosa ya ha esta funcionando mejor!<\/p>\n<p>Por ahi debo de poner la grafica de cuando estabamos usando innodb y veran que 256MB apenas nos alcanzaban y teniamos picos que pegaban no solo en el swap, ademas llegabamos a usar 386MB de memoria commited&#8230; lo cual claro, impactaba en el desempe\u00f1o y peor aun nos ponia como malos usuarios de nuestro vps.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>En los comentarios, los bots exploiters y monadas asi&#8230; bueno a ver si le meto mas contenido despues, pero he estado jugando con la configuraci\u00f3n de lighttpd para evitar a estos jijos de la ma\u00f1ana. [code=&#8217;Apache&#8217;] # deny access for &hellip; <a href=\"https:\/\/blografia.net\/vicm3\/2008\/02\/a-que-el-spam\/\">Sigue leyendo <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1],"tags":[],"class_list":["post-529","post","type-post","status-publish","format-standard","hentry","category-sin-categoria"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":533,"url":"https:\/\/blografia.net\/vicm3\/2008\/03\/y-seguimos-con-los-bots-exploiters\/","url_meta":{"origin":529,"position":0},"title":"Y seguimos con los bots exploiters","author":"vicm3","date":"6 marzo, 2008","format":false,"excerpt":"Para variar los exploiters automatizados siguen usando libwww-perl... bueno en lighttpd ya lo resolvi, anoche cai en cuenta que tambien en apache estaba teniendo muchas peticiones de estas... y todavia tengo 3 apaches en maquinas relativamente grandes, pero me parece que es un desperdicio de conexiones para la mas peque\u00f1a\u2026","rel":"","context":"En \u00abSin categor\u00eda\u00bb","block_context":{"text":"Sin categor\u00eda","link":"https:\/\/blografia.net\/vicm3\/category\/sin-categoria\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":240,"url":"https:\/\/blografia.net\/vicm3\/2006\/02\/para_lo_del_spam_en_referer\/","url_meta":{"origin":529,"position":1},"title":"Para lo del spam en referer","author":"vicm3","date":"16 febrero, 2006","format":false,"excerpt":"Tal cual dije por ahi habia una solucion sencilla y elegante y ademas correcta (de esas casi no hay) .htaccess [code='Apache'] RewriteEngine On #only include this line once to enable the rewriting engine deny from 84.174.72.102 deny from 217.185.183.70 deny from 205.234.145.222 deny from 217.16.124.164 deny from 81.214.106.217 RewriteCond %{HTTP_REFERER}\u2026","rel":"","context":"En \u00abSin categor\u00eda\u00bb","block_context":{"text":"Sin categor\u00eda","link":"https:\/\/blografia.net\/vicm3\/category\/sin-categoria\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":277,"url":"https:\/\/blografia.net\/vicm3\/2006\/04\/mod_security-2\/","url_meta":{"origin":529,"position":2},"title":"Mod_security","author":"vicm3","date":"26 abril, 2006","format":false,"excerpt":"En algun momento mencione algo de esto... y la razon de por que lo estaba poniendo en mis maquinas... un buen ejemplo paso hace poco que no tenia oportunidad de actualizar una aplicaci\u00f3n pero existia una manera de explotarla pero yo no podia parcharla hasta estar seguro, esto me planteaba\u2026","rel":"","context":"En \u00abSin categor\u00eda\u00bb","block_context":{"text":"Sin categor\u00eda","link":"https:\/\/blografia.net\/vicm3\/category\/sin-categoria\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1068,"url":"https:\/\/blografia.net\/vicm3\/2013\/06\/legacy-code-everywhere\/","url_meta":{"origin":529,"position":3},"title":"Legacy code everywhere","author":"vicm3","date":"19 junio, 2013","format":false,"excerpt":"From last weekend our blog lacobachab where not updating their feed, as I removed and updated wp-cache info, most probably I removed redundant entries on .htaccess, BUT looks like removed the correct ones and left the wrong ones, tip if you don't know if your .htaccess mod_rewrite rules are OK,\u2026","rel":"","context":"En \u00abDebraye\u00bb","block_context":{"text":"Debraye","link":"https:\/\/blografia.net\/vicm3\/category\/debraye\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1691,"url":"https:\/\/blografia.net\/vicm3\/2016\/11\/automagic-moodle-update\/","url_meta":{"origin":529,"position":4},"title":"Automagic Moodle update","author":"vicm3","date":"14 noviembre, 2016","format":false,"excerpt":"Well its monday so semi auto magic roll of patches on CentOS via yum-cron on Debian broken for some dumb and strong firewall rules but applied via unattended updates now done through a ssh tunnel using tsocks, been thinking on create a permanent tunnel or one based on apt.conf and\u2026","rel":"","context":"En \u00abDebraye\u00bb","block_context":{"text":"Debraye","link":"https:\/\/blografia.net\/vicm3\/category\/debraye\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1537,"url":"https:\/\/blografia.net\/vicm3\/2016\/01\/bits-of-code-php-and-self-signed-cert-on-moodle\/","url_meta":{"origin":529,"position":5},"title":"Bits of code, php and self signed cert on Moodle","author":"vicm3","date":"22 enero, 2016","format":false,"excerpt":"And a hack, if you happen to have a Moodle 2.6.x with phpmailer old library and you had php5.6.x you may find if you use ssl\/tls to send mail that now php is strictier with self signed certificates, well there are good documentation on php.net about [1] and [2] but\u2026","rel":"","context":"En \u00abEducaci\u00f3n\u00bb","block_context":{"text":"Educaci\u00f3n","link":"https:\/\/blografia.net\/vicm3\/category\/educacion\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/posts\/529","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/comments?post=529"}],"version-history":[{"count":0,"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/posts\/529\/revisions"}],"wp:attachment":[{"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/media?parent=529"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/categories?post=529"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blografia.net\/vicm3\/wp-json\/wp\/v2\/tags?post=529"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}