nolimitsandip
Newbie
- Nov 12, 2024
- 12
- 2
Hey everyone,
I’ve been running a movie downloading website for the past 3–4 months and have put in a lot of consistent effort to grow it — from refining small SEO details to regularly uploading new content. It’s been tough, but over time, I saw my hard work pay off. Just last week, my site reached #4 on Google for a competitive keyword, and I was finally seeing a solid amount of traffic.
But that success didn’t last long.
Yesterday, my site was hit by a massive DDoS attack — it looked highly targeted. The attacker flooded my server with requests to the homepage, all coming from multiple IPs with long (20+ character) random query strings added to the URL(check attachemnt for better understanding). I quickly enabled Cloudflare’s Under Attack Mode (UAM), which temporarily stopped the traffic spike.
Unfortunately, a couple of hours later, the attacker adapted and bypassed UAM somehow. My site went completely down again, despite UAM being active. The real damage was done: being offline for nearly a day completely tanked my Google ranking — from the top of the first page to not even showing up anymore.
I’m working on recovering the ranking and will definitely keep pushing forward. But realistically, I know this attacker — who I strongly suspect is a competitor — will likely strike again once I regain my first page ranking.
So this time, I want to be ready.
I have full logs of the attack from yesterday and I’m looking for someone with experience in Cloudflare WAF rules who can help analyze the pattern and guide me on exactly which rules to deploy to block this type of attack without accidentally blocking legitimate users.
I’ve read about WAF configurations and how they can help, but since the pattern isn’t 100% clear and I’m afraid of locking out real traffic, I’m hoping someone can take a look at my logs and advise me on:
If anyone here can help, I’d deeply appreciate it. I’m not looking for shortcuts — I’ve worked hard on this site and plan to keep pushing forward. I just want to make sure I’m prepared for the next wave and that I can keep my site up even if someone’s actively trying to take it down.
Thanks in advance to anyone who can lend their expertise or guide me in the right direction
I’ve been running a movie downloading website for the past 3–4 months and have put in a lot of consistent effort to grow it — from refining small SEO details to regularly uploading new content. It’s been tough, but over time, I saw my hard work pay off. Just last week, my site reached #4 on Google for a competitive keyword, and I was finally seeing a solid amount of traffic.
But that success didn’t last long.
Yesterday, my site was hit by a massive DDoS attack — it looked highly targeted. The attacker flooded my server with requests to the homepage, all coming from multiple IPs with long (20+ character) random query strings added to the URL(check attachemnt for better understanding). I quickly enabled Cloudflare’s Under Attack Mode (UAM), which temporarily stopped the traffic spike.
Unfortunately, a couple of hours later, the attacker adapted and bypassed UAM somehow. My site went completely down again, despite UAM being active. The real damage was done: being offline for nearly a day completely tanked my Google ranking — from the top of the first page to not even showing up anymore.
I’m working on recovering the ranking and will definitely keep pushing forward. But realistically, I know this attacker — who I strongly suspect is a competitor — will likely strike again once I regain my first page ranking.
So this time, I want to be ready.
I have full logs of the attack from yesterday and I’m looking for someone with experience in Cloudflare WAF rules who can help analyze the pattern and guide me on exactly which rules to deploy to block this type of attack without accidentally blocking legitimate users.
I’ve read about WAF configurations and how they can help, but since the pattern isn’t 100% clear and I’m afraid of locking out real traffic, I’m hoping someone can take a look at my logs and advise me on:
- What WAF rules (or combination of rules) I should deploy
- How to handle query string flooding with randomized patterns
- Best practices for preventing future UAM bypasses
- Tips for setting up rate limiting without hurting SEO or UX
If anyone here can help, I’d deeply appreciate it. I’m not looking for shortcuts — I’ve worked hard on this site and plan to keep pushing forward. I just want to make sure I’m prepared for the next wave and that I can keep my site up even if someone’s actively trying to take it down.
Thanks in advance to anyone who can lend their expertise or guide me in the right direction