December 25, 2024 Attack Briefing: Largest DDoS Attack Record to Date
This article was last updated 196 days ago. The information in it may have developed or changed. If it is invalid, please leave a message in the comment section.
Article Summary
近日遭遇最大规模DDoS攻击,攻击聚焦于WordPress核心路径/wp-admin/admin-ajax.php,Cloudflare拦截了大部分流量,但内网WAF仍过滤了部分未达速率限制的请求。攻击统计显示Cloudflare未缓存请求与内网WAF记录存在数量级差异,可能因拦截机制或攻击重试导致。事件暴露当前防护配置容忍度过高,后续需优化速率限制策略,重新启用WAF并提升监控能力,以应对类似攻击。
Qwen3-14B · 2026-06-18

Attack Scale

From 3 to 6 a.m. today, we encountered a wave of DDoS attacks, which is the highest record so far and worth recording:

Number of attack requests:

image.png

Attack bandwidth:

image.png

Number of attackers:

image.png

Attacker source:

image.png

The top 3 IP addresses and number of attack requests initiated this time are:
image.png

Attack Types

This attack was a direct attack on the path "/wp-admin/admin-ajax.php", which really hurt me because the comment function of WordPress relies on ajax calls. I can't host a query on this path (otherwise I can't comment). The previous attack on my blog admin-ajax.php was mainly an indirect attack through TranslatePress to initiate ajax calls (see article:Home Data Center Series: Cracking the WordPress AJAX Protection Problem: Using Cloudflare Tunnel to "divide" normal website access and attack traffic), but I have already blocked that path. This time it was a direct attack, and most of it was blocked by Cloudflare:

image.png

However, there are still many attacks that do not reach the global rate limit and enter the intranet. These requests are filtered by the intranet WAF:

image.png

image.png

However, some requests still reached the origin server. The reason was that my tolerance for admin-ajax.php access was too high:

image.png

It seems that we can’t leave these openings anymore.


The "attack request count" and "attack bandwidth" mentioned earlier in the article both involve uncached "requests" or "bandwidth", which raises a question: why is there only 18.29k uncached requests in Cloudflare's statistics, but there are nearly 2 million requests on my intranet WAF? I think there are three possible reasons:

  • Cloudflare excludes requests that are blocked (e.g. triggering WAF rules, rate limiting, DDoS protection, etc.) from "uncached requests".
  • Attack tools may try the same resource (such as admin-ajax.php) multiple times, resulting in duplicate connections. For example, an attacker sends a request, receives a 429 or other restricted response, and the tool automatically retries. The origin server will record multiple times, but Cloudflare only counts the initial request.

This kind of details is not important.


Another 1: The statistics that can be viewed with a Cloudflare Free account are too few, which is quite annoying.

Another 2: The functions of the free intranet WAF are still too few. I previously removed the load balancing after the WAF because I felt it was a waste of resources, but now it seems that it is still necessary to add it.

Another 3: This time there was a problem with my blog, forcing me to spend 1 second restarting the docker of wordpress. I am an honest person and will never deny it, but it really doesn’t require much technical skills.

📌 Content Structure Hints:
This content belongs to "Blog Knowledge MapThis is part of the document; you can view the full content path here: Blog Knowledge Map .
View related categories · 3 matches
📎 Related Articles
Share this article
All blog content is original; please indicate the source when reprinting! The blog's RSS address is:https://blog.tangwudi.com/feed, welcome to subscribe; if necessary, you can joinTelegram GroupDiscuss the problem together.

Comments

  1. Windows Edge 131.0.0.0
    2 years ago
    2024-12-26 9:15:32

    Cloudflare is pretty powerful. If you switch to a domestic CDN, you can get a bill in minutes.

    • Owner
      Yawata
      Macintosh Chrome 131.0.0.0
      2 years ago
      2024-12-26 16:15:52

      Yes, if we follow the price of Tencent Cloud CDN, 20 yuan for 100G, that would be 1,000.

Send Comment Edit Comment


				
|´・ω・)ノ
ヾ(≧∇≦*)ゝ
(☆ω☆)
(╯‵□′)╯︵┴─┴
 ̄﹃ ̄
(/ω\)
∠(ᐛ 」∠)_
(๑•̀ㅁ•́ฅ)
→_→
୧(๑•̀⌄•́๑)૭
٩(ˊᗜˋ*)و
(ノ°ο°)ノ
(´இ皿இ`)
⌇●﹏●⌇
(ฅ´ω`ฅ)
(╯°A°)╯︵○○○
φ( ̄∇ ̄o)
ヾ(´・ ・`。)ノ"
( ง ᵒ̌ᵒ̌)ง⁼³₌₃
(ó﹏ò。)
Σ(っ°Д °;)っ
( ,,´・ω・)ノ"(´っω・`。)
╮(╯▽╰)╭
o(*////▽////*)q
>﹏<
( ๑´•ω•) "(ㆆᴗㆆ)
😂
😀
😅
😊
🙂
🙃
😌
😍
😘
😜
😝
😏
😒
🙄
😳
😡
😔
😫
😱
😭
💩
👻
🙌
🖕
👍
👫
👬
👭
🌚
🌝
🙈
💊
😶
🙏
🍦
🍉
😣
Source: github.com/k4yt3x/flowerhd
Emoticons
Emoji
Little Dinosaur
flower!
Previous
Next
       

👋 Welcome to "Invincible Personal Blog"“

This section will focus on long-term exploration in the following areas:

🧱 Building Personal Digital Infrastructure and Blog Systems
☁️ Cloudflare and Network Architecture Practices
🧠 Exploring AI and Knowledge Systems
🛡️ Network security and access optimization
🎵 Music and Sound Cognition
👁️ Cognitive Perspective and Worldview