You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

NGINX:如何处理无条件全局重定向服务器上的恶意虚假流量?

Handling Malicious Traffic on Nginx 1.13.8 (HTTP to HTTPS Redirect)

Hey Austin, sorry to hear you're dealing with all that annoying malicious fake traffic hitting your 80 port. Let's break down some practical, actionable steps to mitigate this while keeping your legitimate HTTP-to-HTTPS redirect working for real users.

1. Rate Limit Requests to Port 80

First, leverage Nginx's built-in limit_req module to throttle excessive requests from the same IP. This stops bots from spamming your 80 port with hundreds of requests per second.

Add this to your http block (outside any server blocks) to define a rate-limiting zone:

http {
    # ... your existing config ...
    limit_req_zone $binary_remote_addr zone=port80_limit:10m rate=5r/m;
    # 10MB zone to store IP tracking data, max 5 requests per minute per IP
}

Then apply this limit to your port 80 server block:

server {
    listen 80;
    server_name yourdomain.com www.yourdomain.com;

    # Apply rate limiting
    limit_req zone=port80_limit burst=2 nodelay;
    # Burst allows 2 extra requests before blocking; nodelay rejects excess immediately

    # Redirect legitimate requests to HTTPS
    return 301 https://$host$request_uri;

    # Drop excessive/malicious requests without sending a response
    limit_req_status 444;
}

The 444 status code tells Nginx to close the connection immediately, wasting far less of your server's resources than sending a redirect to bots.

2. Filter Malicious User Agents & Invalid Requests

Most bots use obvious, non-standard User-Agents (like sqlmap, nikto, or generic "scanner" labels). You can block these outright on port 80, along with requests that don't target your actual domain.

Add these checks inside your port 80 server block:

server {
    listen 80;
    server_name yourdomain.com www.yourdomain.com;

    # Block known malicious User-Agents (adjust regex to match your logs)
    if ($http_user_agent ~* (sqlmap|nikto|nmap|scanner|crawl|spider|bot)) {
        return 444;
    }

    # Block requests without a valid Host header (common in IP-only scans)
    if ($host = "") {
        return 444;
    }

    # ... rate limit and redirect config ...
}

Check your Nginx access logs to identify specific UA strings that are flooding your server, then add them to the regex pattern.

3. Enforce HSTS to Reduce Port 80 Traffic Over Time

HTTP Strict Transport Security (HSTS) tells browsers to always use HTTPS for your domain, even if the user types http://. This cuts down on legitimate port 80 requests over time, and reduces the chance of users falling for HTTP-based attacks.

Add this to your port 443 server block:

server {
    listen 443 ssl;
    server_name yourdomain.com www.yourdomain.com;

    # ... your existing SSL config (certificates, protocols, etc.) ...

    # Enable HSTS
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
    # Max-age = 1 year; includeSubDomains applies the rule to all subdomains
}

Note: Once HSTS is set, browsers will ignore HTTP requests for your domain until the max-age expires, so make sure your HTTPS setup is stable before enabling this.

4. Ban Repeatedly Malicious IPs

If you're seeing repeated attacks from specific IPs or ranges, you can block them directly in Nginx.

Add this to your http block or port 80 server block:

# Block a single malicious IP
deny 192.168.1.100;

# Block an entire suspicious IP range
deny 10.0.0.0/8;

For automated IP banning, use fail2ban to monitor your Nginx access logs. Configure it to detect repeated malicious requests (like excessive 444 responses) and automatically add IPs to your firewall blocklist (works with ufw, iptables, etc.).

5. Optional: Minimize Port 80 Exposure

If most of your users already use HTTPS (thanks to HSTS), you could take a more aggressive approach: only respond to requests for your actual domain, and drop all other traffic to port 80.

Modify your port 80 config like this:

# Catch-all server block for IP-only or unknown domain requests
server {
    listen 80 default_server;
    return 444;
}

# Only handle requests for your legitimate domain
server {
    listen 80;
    server_name yourdomain.com www.yourdomain.com;
    # Apply rate limits, UA filters, and redirect to HTTPS
    limit_req zone=port80_limit burst=2 nodelay;
    if ($http_user_agent ~* (malicious-ua-patterns)) {
        return 444;
    }
    return 301 https://$host$request_uri;
}

This way, any request targeting your server's IP directly (not your domain) gets dropped immediately, stopping IP-based scans cold.

All these steps work seamlessly with Nginx 1.13.8 (since limit_req and HSTS support are available in much older versions). Start with rate limiting and UA filtering first, then add HSTS once you're confident in your HTTPS setup. Check your access logs regularly to adjust the rules as new malicious patterns emerge.

内容的提问来源于stack exchange,提问作者Austin Hemmelgarn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:33:55