Yes this will stop all automated processes including SE-spiders, but that is a small price to pay. And like dismounted mentioned, this is a solution only usable for a short time but most attacks don't run longer then a few days.
The story from yesterday did get a strange twist. After deploying the extra login trick, we decided to also ask the host to place us behind an extra firewall to further help mitigating the attack. At the time the server was placed behind the firewall, the server (with extra login) was under a high load, but forums where usable. During the day the forums became less and less responsive until they where almost unreachable by the nd of the day. Server load however was still low. After long time of troubleshooting we decided to remove the firewall again to see what happens. Guess what, serverload stayed within reasonable limits, forums where accessible at a good speed again. So in this case the firewall actually did make things worse instead of solving it (although the host doesn't want to admit this).
|