部署在Nginx代理后的Node.js应用出现可疑请求,是否为黑客攻击?
Is That POST Request a Hacker Attack?
Hey there! Let's unpack this request and figure out what's going on.
First, let's highlight the key log entry you shared:
[30/Aug/2020:05:42:11 GMT-0300] "POST /api/jsonws/invoke" 404 136 - 2.591 ms
What's /api/jsonws/invoke?
This endpoint is a standard JSON Web Service entry point for Liferay Portal, a widely used enterprise CMS. The fact that someone's targeting this path tells us this is almost certainly an automated scan—think bots or script kiddies poking around for common, potentially vulnerable services.
Is this an "attack"?
Not exactly—yet. Here's the breakdown:
- This is a probing/scanning request: The sender is checking if your server runs Liferay, in case there are unpatched vulnerabilities they could exploit later.
- The 404 status code is good news: Your server doesn't have this endpoint, so the scan didn't find anything to target. No immediate harm was done.
- That said, this is a red flag: Your server is now on the radar of automated scanning tools. It's likely you'll see more of these probing requests over time.
What should you do next?
To harden your setup and prevent future issues:
- Block repeat offenders: Use tools like
fail2banwith Nginx to automatically IP-ban hosts that send multiple suspicious requests. - Filter common scan paths: Add Nginx rules to block requests targeting known non-existent endpoints (like this Liferay path) before they reach your Node.js app.
- Audit your exposed endpoints: Make sure your Node.js apps only expose the APIs they need, and all endpoints have proper authentication/authorization.
- Consider a WAF: A Web Application Firewall can help filter out automated scans and common attack patterns before they hit your server.
内容的提问来源于stack exchange,提问作者Luiz Alves
相关产品推荐
相关产品推荐

