{"id":275479,"date":"2016-03-04T09:58:02","date_gmt":"2016-03-04T06:58:02","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=275479"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=275479","title":{"rendered":"\u041a\u0430\u043a \u043c\u044b \u0431\u043e\u0440\u043e\u043b\u0438\u0441\u044c \u0441 \u043f\u0430\u0440\u0441\u0435\u0440\u0430\u043c\u0438"},"content":{"rendered":"<p>       <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/c55\/a04\/3dd\/c55a043ddd3b007885d70bc836a5729e.jpg\" alt=\"image\"\/><br \/>  \u041a\u043b\u044e\u0447\u0435\u0432\u044b\u0435 \u043c\u043e\u043c\u0435\u043d\u0442\u044b:<br \/>  * \u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 PTR \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439;<br \/>  * \u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 nginx \u0432 IfIsEvil-style \u0441 \u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u044f\u043c\u0438 map;<br \/>  * \u0418\u043c\u0435\u043d\u0430 location \u0432 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 map;<br \/>  * \u0423\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u0447\u0435\u0440\u0435\u0437 try_files \/nonexist $map_var.<\/p>\n<p>  \u041c\u043d\u043e\u0433\u0438\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u043d\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0435 \u0438 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0441\u0442\u0440\u0430\u0434\u0430\u044e\u0442 \u043e\u0442 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u043a\u0440\u043e\u043c\u0435 \u0436\u0438\u0432\u044b\u0445 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u0438\u0445 \u043f\u043e\u0441\u0435\u0449\u0430\u044e\u0442 \u0440\u0430\u0437\u043d\u043e\u043e\u0431\u0440\u0430\u0437\u043d\u044b\u0435 \u043f\u0430\u0440\u0441\u0435\u0440\u044b, \u0431\u043e\u0442\u044b \u0438 \u043f\u0440\u043e\u0447\u0438\u0435 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u043a\u0430\u043d\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u043d\u0435\u0441\u0443\u0442 \u043d\u0438\u043a\u0430\u043a\u043e\u0433\u043e \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0433\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0430, \u0430 \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u043e\u0437\u0434\u0430\u044e\u0442 \u043f\u0430\u0440\u0430\u0437\u0438\u0442\u043d\u044b\u0439 \u0442\u0440\u0430\u0444\u0438\u043a \u0438 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u043d\u0430, \u0438 \u0431\u0435\u0437 \u0442\u043e\u0433\u043e, \u043d\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u0443\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u0443. \u0412 \u0434\u0430\u043d\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u044f \u043d\u0435 \u0438\u043c\u0435\u044e \u0432\u0438\u0434\u0443 \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u044b\u0445 \u0431\u043e\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0445\u043e\u0442\u044c \u0438 \u0437\u0430\u0447\u0430\u0441\u0442\u0443\u044e \u043d\u0430\u0433\u0440\u0443\u0436\u0430\u044e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442 \u043d\u0435 \u043d\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043e, \u043d\u043e \u043f\u0440\u043e\u0441\u0442\u043e \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b \u043b\u044e\u0431\u043e\u043c\u0443 \u043f\u0440\u043e\u0435\u043a\u0442\u0443.<br \/>  \u041e\u0434\u0438\u043d \u0438\u0437 \u043d\u0430\u0448\u0438\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0440\u0435\u0433\u0443\u043b\u044f\u0440\u043d\u043e \u0438\u0441\u043f\u044b\u0442\u044b\u0432\u0430\u043b \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043b\u0430\u0432\u0438\u043d\u043e\u043e\u0431\u0440\u0430\u0437\u043d\u043e\u0433\u043e \u0440\u043e\u0441\u0442\u0430 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0441\u0443\u0442\u043e\u043a. \u041f\u0435\u0440\u0438\u043e\u0434\u0438\u0447\u0435\u0441\u043a\u0438, \u0440\u0430\u0437 \u0432 \u0441\u0443\u0442\u043a\u0438 \u0438 \u0447\u0430\u0449\u0435 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u043b\u0438 \u043d\u0430\u043f\u043b\u044b\u0432\u044b \u043f\u043e\u0441\u0435\u0449\u0435\u043d\u0438\u0439 \u0441\u043e \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c \u0440\u043e\u0441\u0442\u043e\u043c LA \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445. \u0411\u044b\u043b\u043e \u043f\u0440\u0438\u043d\u044f\u0442\u043e \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u043f\u043e\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0437\u0430\u0449\u0438\u0442\u0443 \u043e\u0442 \u043f\u0430\u0440\u0430\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430.<\/p>\n<p>  <a name=\"habracut\"><\/a><\/p>\n<h5><a href=\"http:\/\/centos-admin.ru\">\u041c\u044b<\/a> \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0438\u043b\u0438, \u0447\u0442\u043e \u0443 \u043f\u0430\u0440\u0430\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0438\u043c\u0435\u044e\u0442\u0441\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u044b\u0435 \u043f\u0430\u0442\u0442\u0435\u0440\u043d\u044b \u043f\u043e\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u0438 \u0441\u0432\u043e\u0439\u0441\u0442\u0432\u0430, \u0430 \u0438\u043c\u0435\u043d\u043d\u043e:<\/h5>\n<p>  * \u041f\u043e \u0438\u0441\u0442\u043e\u0447\u043d\u0438\u043a\u0443 \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u2013 \u043f\u043e\u0434\u0441\u0435\u0442\u0438 Amazon, Tor;<br \/>  * \u041f\u043e \u0442\u043e\u0447\u043a\u0430\u043c \u0432\u0445\u043e\u0434\u0430 \u2013 \u0431\u043e\u043b\u044c\u0448\u0438\u043d\u0441\u0442\u0432\u043e \u0437\u0430\u043f\u0440\u043e\u0441\u043e\u0432 \u043a \u0440\u0430\u0437\u0434\u0435\u043b\u0443 \u0442\u043e\u0432\u0430\u0440\u043e\u0432;<br \/>  * \u041f\u043e UserAgent \u2013 \u043e\u0441\u043d\u043e\u0432\u043d\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u0431\u043e\u0442\u043e\u0432 \u043e\u0442\u043f\u0440\u0430\u0432\u043b\u044f\u043b\u0438 UA \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u0438\u043a\u043e\u0432 Google, Yandex, Bing, \u043d\u043e \u043e\u0431\u044a\u0435\u043a\u0442\u0438\u0432\u043d\u043e \u043d\u0435 \u044f\u0432\u043b\u044f\u043b\u0438\u0441\u044c \u0438\u043c\u0438;<br \/>  * \u041f\u043e \u0440\u0435\u0444\u0435\u0440\u0435\u0440\u0443 \u2013 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u043c \u0440\u0435\u0444\u0435\u0440\u0435\u0440 \u0431\u044b\u043b \u043f\u0443\u0441\u0442\u043e\u0439.<\/p>\n<h5>\u0420\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043d\u043d\u044b\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438:<\/h5>\n<p>  * \u0412\u0440\u0443\u0447\u043d\u0443\u044e \u0434\u043e\u0431\u0430\u0432\u0438\u043b\u0438 \u0437\u0430\u0440\u0430\u043d\u0435\u0435 \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u044b\u0435 IP \u0432 \u0431\u0435\u043b\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a <br \/>  * \u0418 \u0440\u0430\u043d\u0435\u0435 \u0441\u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0435 IP \u2013 \u0432 \u0447\u0435\u0440\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a<br \/>  * \u041e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u0435 limit_req_zone \u0434\u043b\u044f \u0432\u0441\u0435\u0445, \u043a\u0440\u043e\u043c\u0435 \u0431\u0435\u043b\u044b\u0445 \u0441\u043f\u0438\u0441\u043a\u043e\u0432<br \/>  * \u041f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u0441 UA \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u0438\u043a\u043e\u0432 \u043d\u0430 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435 PTR-\u0437\u0430\u043f\u0438\u0441\u0438 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u043c PTR-\u0437\u0430\u043f\u0438\u0441\u044f\u043c \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u0438\u043a\u043e\u0432 \u0438 \u043f\u043e\u043c\u0435\u0449\u0430\u0435\u043c \u0432 \u0431\u0435\u043b\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0438\u0445 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 \u0438 \u0432\u0441\u0435\u0433\u0434\u0430 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u0435\u043c \u0438\u0445. <br \/>  * \u041f\u0440\u0438 \u043f\u043e\u0432\u044b\u0448\u0435\u043d\u0438\u0438 LA \u043f\u043e\u0440\u043e\u0433\u0430 \u00ab\u0410\u0442\u0430\u043a\u0430\u00bb:<br \/>  ** \u041d\u0435 \u043f\u0440\u043e\u0448\u0435\u0434\u0448\u0438\u0445 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 UA \u043f\u043e PTR \u043c\u044b \u0437\u0430\u043d\u043e\u0441\u0438\u043c \u0432 \u0447\u0435\u0440\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a \u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c.<br \/>  ** \u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u043f\u043e\u0432\u0442\u043e\u0440\u044f\u0435\u043c\u043e\u0441\u0442\u044c \u0440\u0435\u0444\u0435\u0440\u0435\u0440\u043e\u0432 \u0432 access-\u043b\u043e\u0433\u0435 \u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u0441 \u0440\u0435\u0444\u0435\u0440\u0435\u0440\u043e\u043c, \u043f\u0440\u0435\u0432\u044b\u0441\u0438\u0432\u0448\u0438\u043c \u0437\u0430\u0434\u0430\u043d\u043d\u043e\u0435 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e \u0432\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0439<br \/>  ** \u041e\u0441\u0442\u0430\u043b\u044c\u043d\u044b\u0445 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u043a\u0430\u043f\u0447\u0435\u0439 \u0438 \u0440\u0430\u0437\u0440\u0435\u0448\u0430\u0435\u043c \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u0443\u0441\u043f\u0435\u0445\u0430.<\/p>\n<p>  \u041f\u0435\u0440\u0432\u044b\u0435 \u0442\u0440\u0438 \u043f\u0443\u043d\u043a\u0442\u0430 \u044d\u0442\u043e \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u043d\u044b\u0435 \u0440\u0435\u0448\u0435\u043d\u0438\u044f, \u043f\u043e\u044d\u0442\u043e\u043c\u0443 \u043f\u043e\u0434\u0440\u043e\u0431\u043d\u0435\u0435 \u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043b\u044e\u0441\u044c \u043d\u0430 \u043d\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0435 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u043f\u043e PTR, \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0438 nginx c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c \u043a\u043e\u043d\u0441\u0442\u0440\u0443\u043a\u0446\u0438\u0438 try_files \/nonexist $map_var \u0438 \u0441\u043b\u043e\u0436\u043d\u044b\u0445 map.<\/p>\n<h5>\u041c\u044b \u0440\u0435\u0430\u043b\u0438\u0437\u043e\u0432\u0430\u043b\u0438 \u0441\u043a\u0440\u0438\u043f\u0442 \u0434\u043b\u044f \u0430\u0441\u0438\u043d\u0445\u0440\u043e\u043d\u043d\u043e\u0439 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u0441 UA \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u0438\u043a\u043e\u0432 \u043d\u0430 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0435 PTR-\u0437\u0430\u043f\u0438\u0441\u0438 \u043d\u0430\u0441\u0442\u043e\u044f\u0449\u0438\u043c PTR-\u0437\u0430\u043f\u0438\u0441\u044f\u043c \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u0438\u043a\u043e\u0432.<\/h5>\n<p>  \u041e\u043d \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u043f\u043e cron \u0440\u0430\u0437 \u0432 \u043c\u0438\u043d\u0443\u0442\u0443. \u041f\u043e \u0443\u043d\u0438\u043a\u0430\u043b\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u043c\u0443 \u0441\u043f\u0438\u0441\u043a\u0443 IP \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u0441 UA \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u0438\u043a\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0443 PTR \u0438 \u0441\u0432\u0435\u0440\u044f\u0435\u0442 \u0434\u043e\u043c\u0435\u043d\u043d\u043e\u0435 \u0438\u043c\u044f \u0432\u0442\u043e\u0440\u043e\u0433\u043e \u0443\u0440\u043e\u0432\u043d\u044f. \u0415\u0441\u043b\u0438 \u0434\u043e\u043c\u0435\u043d \u0441\u043e\u0432\u043f\u0430\u0434\u0430\u0435\u0442, \u0442\u043e \u0434\u043e\u0431\u0430\u0432\u043b\u044f\u0435\u0442 IP \u0432 \u0431\u0435\u043b\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a, \u0438\u043d\u0430\u0447\u0435 \u0432 \u0447\u0435\u0440\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a. \u041f\u0440\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0435 \u0441\u043f\u0438\u0441\u043a\u0430, \u0441\u043a\u0440\u0438\u043f\u0442 \u043d\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u0442 PTR \u0443\u0436\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d\u043d\u044b\u0445 \u0440\u0430\u043d\u0435\u0435 IP \u0434\u043b\u044f \u0443\u0441\u043a\u043e\u0440\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0446\u0435\u0441\u0441\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438. \u042d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u0440\u043e\u0445\u043e\u0434\u0438\u0442\u044c \u043f\u043e \u0441\u043f\u0438\u0441\u043a\u0443 IP \u0438\u0437 access-\u043b\u043e\u0433\u0430 \u0435\u0436\u0435\u043c\u0438\u043d\u0443\u0442\u043d\u043e \u0434\u0430\u0436\u0435 \u043f\u0440\u0438 \u0432\u044b\u0441\u043e\u043a\u043e\u0439 \u0441\u043a\u043e\u0440\u043e\u0441\u0442\u0438 \u043d\u0430\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f access-\u043b\u043e\u0433\u0430. \u0417\u0430\u043f\u0438\u0441\u0438 \u0432 \u0447\u0435\u0440\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043e\u043a \u0437\u0430\u043d\u043e\u0441\u044f\u0442\u0441\u044f \u0441 \u0443\u043a\u0430\u0437\u0430\u043d\u0438\u0435\u043c \u0444\u0438\u043a\u0441\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u0440\u0435\u043c\u0435\u043d\u0438 \u0443\u0434\u0430\u043b\u0435\u043d\u0438\u044f \u0438\u0437 \u0441\u043f\u0438\u0441\u043a\u0430 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0434\u043b\u044f \u0438\u0441\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043f\u043e\u0441\u0442\u043e\u044f\u043d\u043d\u043e\u0439 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u043e\u0431\u0449\u0438\u0445 IP \u0432 \u0431\u043e\u043b\u044c\u0448\u0438\u0445 NAT \u0441\u0435\u0442\u044f\u0445.<\/p>\n<p>  \u0422\u0430\u043a\u0438\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c \u043c\u044b \u0444\u043e\u0440\u043c\u0438\u0440\u0443\u0435\u043c \u0438 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u0438\u0432\u0430\u0435\u043c \u0444\u0430\u0439\u043b\u044b ptr_blacklist.map \u0438 ptr_whitelist.map \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u043d\u043a\u043b\u0443\u0434\u044f\u0442\u0441\u044f \u0432 \u043a\u043e\u043d\u0444\u0438\u0433 nginx.<\/p>\n<p>  \u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0435\u0436\u0435\u043c\u0438\u043d\u0443\u0442\u043d\u043e.  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041b\u0438\u0441\u0442\u0438\u043d\u0433 \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u044f UA \u0438 PTR:<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">#!\/bin\/bash  # \u0411\u0430\u0437\u043e\u0432\u044b\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0441\u043a\u0440\u0438\u043f\u0442\u0430, \u043e\u0431\u044b\u0447\u043d\u043e \u0432\u044b\u043d\u043e\u0441\u044f\u0442\u0441\u044f \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 \u0444\u0430\u0439\u043b, # \u0447\u0442\u043e\u0431\u044b \u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u043f\u043e\u0434\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c \u043f\u043e\u0434 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442, \u043d\u0435 \u043c\u0435\u043d\u044f\u044f \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043a\u0440\u0438\u043f\u0442. # Export inc file for nginx EXPORT_MAP=true  # Domain list DOMAIN_LIST=&quot;domain&quot;  # Block time (in minutes) BLOCK_TIME=1440  # White list IP IP_WHITELIST=&quot;&quot;  # White list PTR BOTS=&quot;google|yandex|bing|Bing|msn&quot;  # false - not block IP if there is a PTR record BLOCK_WITH_PTR=true  UNBLOCK_ENABLE=true LOGFILE=\/var\/log\/ua-table.log LOGFILE2=\/var\/log\/ua-table-history.log LOCK=\/tmp\/ua_check.lock  D=$DOMAIN_LIST  # \u0421\u043a\u0440\u0438\u043f\u0442 \u0444\u043e\u0440\u043c\u0438\u0440\u0443\u0435\u0442 ptr_blacklist \u0438 ptr_whitelist \u0438 \u0442\u043e\u043b\u044c\u043a\u043e \u043f\u043e\u0442\u043e\u043c \u043a\u043e\u043f\u0438\u0440\u0443\u0435\u0442 \u0438\u0445 \u0432 map-\u0444\u0430\u0439\u043b\u044b # \u0434\u043b\u044f \u043c\u0438\u043d\u0438\u043c\u0438\u0437\u0430\u0446\u0438\u0438 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0438 \u0440\u0430\u0431\u043e\u0447\u0438\u0445 \u0444\u0430\u0439\u043b\u043e\u0432 BL_FILE=\/etc\/nginx\/vhosts.d\/ptr_blacklist WL_FILE=\/etc\/nginx\/vhosts.d\/ptr_whitelist BL_FILE_MAP=$BL_FILE.map WL_FILE_MAP=$WL_FILE.map  TMP_LOG=\/tmp\/$D-acc-temp.log TMP_LOG1=\/tmp\/$D-acc-temp1.log NGINX_LOG=\/srv\/www\/$D\/shared\/log\/$D-acc.log  [ ! -f \/usr\/bin\/host ] && echo &quot;\/usr\/bin\/host not found. Please yum install bind-utils&quot; && exit [ -z &quot;$DOMAIN_LIST&quot; ] && echo &quot;DOMAIN_LIST is empty&quot; [ ! -f $LOGFILE ] && touch $LOGFILE [ ! -f $LOGFILE2 ] && touch $LOGFILE2  debug=&quot;0&quot;  function e {     echo -e $(\/bin\/date &quot;+%F %T&quot;) $1 }  # \u041f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u043d\u0435 \u0437\u0430\u043f\u0443\u0449\u0435\u043d \u043b\u0438 \u0441\u043a\u0440\u0438\u043f\u0442, \u044d\u0442\u043e \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043d\u0435 \u0434\u0443\u0431\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0437\u0430\u0442\u044f\u043d\u0443\u0432\u0448\u0438\u0435\u0441\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 [ -f $LOCK ] && e &quot;Script $0 is already runing&quot; && exit \/bin\/touch $LOCK  DT=`\/bin\/date &quot;+%F %T&quot;`  if [ ! -f $NGINX_LOG ];then     echo &quot;Log ($NGINX_LOG) not found.&quot;     \/bin\/rm -rf $LOCK     exit fi  # \u041e\u0441\u043d\u043e\u0432\u043d\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u0441\u043a\u0440\u0438\u043f\u0442\u0430  # \u0414\u0435\u043b\u0430\u0435\u043c \u0432\u044b\u0431\u043e\u0440\u043a\u0443 \u0438\u0437 acc-\u043b\u043e\u0433\u0430, \u0440\u0435\u0433\u0438\u0441\u0442\u0440 \u0432\u0430\u0436\u0435\u043d, \u0442\u0430\u043a \u043c\u044b \u043d\u0435 \u0446\u0435\u043f\u043b\u044f\u0435\u043c \u0437\u0430\u043f\u0438\u0441\u0438 \u0441 \u0432\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u0435\u043c \u0432 referer \/bin\/egrep &quot;Yandex|Google|bingbot|Bing&quot; $NGINX_LOG | \/usr\/bin\/awk '{print $1}' | \/bin\/sort -n | \/usr\/bin\/uniq &gt; $TMP_LOG   if [ &quot;$EXPORT_MAP&quot; == &quot;true&quot; ]; then     [ ! -f $BL_FILE_MAP ] && \/bin\/touch $BL_FILE_MAP     [ ! -f $WL_FILE_MAP ] && \/bin\/touch $WL_FILE_MAP     [ ! -f $BL_FILE ] && \/bin\/touch $BL_FILE || \/bin\/cp -f $BL_FILE $BL_FILE.bak     [ ! -f $WL_FILE ] && \/bin\/touch $WL_FILE || \/bin\/cp -f $WL_FILE $WL_FILE.bak fi  # \u0420\u0430\u0437\u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c \u0430\u0434\u0440\u0435\u0441\u0430 UNBLOCK=0 while read line do     if [[ &quot;$line&quot; == *=* ]]; then         GET_TIME=`echo $line | \/usr\/bin\/awk -F&quot;=&quot; '{print $2}'`         NOW=`\/bin\/date '+%s'`         #echo $NOW         #echo $GET_TIME         if [ &quot;$NOW&quot; -gt &quot;$GET_TIME&quot; ]; then             IP=`echo $line | awk '{print $3}'`             e &quot;$IP unblocked.&quot; &gt;&gt; $LOGFILE2             \/bin\/sed -i '\/'$IP'\/d' $BL_FILE             \/bin\/sed -i '\/'$IP'\/d' $LOGFILE             UNBLOCK=1         #else             #e &quot;Nothing to unblock&quot; &gt;&gt; $LOGFILE2        fi     fi done &lt; $LOGFILE  # \u0411\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c \u0430\u0434\u0440\u0435\u0441\u0430 while read line do     IP=$line     wl=0     bl=0  # \u0432\u0445\u043e\u0434\u0438\u0442 \u0432 \u0440\u0443\u0447\u043d\u043e\u0439 WL     for I in $IP_WHITELIST     do         if [ &quot;$I&quot; = &quot;$IP&quot; ];then             wl=1         fi     done  # \u0440\u0430\u043d\u0435\u0435 \u0443\u0436\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d \u0438 \u0432\u043d\u0435\u0441\u0435\u043d \u0432 WL     for I in $(\/usr\/bin\/awk '{print $1}' &lt; &quot;$WL_FILE&quot; )     do         if [ &quot;$I&quot; = &quot;$IP&quot; ];then             wl=1         fi     done  # \u0440\u0430\u043d\u0435\u0435 \u0443\u0436\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d \u0438 \u0432\u043d\u0435\u0441\u0435\u043d \u0432 BL     for I in $(\/usr\/bin\/awk '{print $1}' &lt; &quot;$BL_FILE&quot; )     do         if [ &quot;$I&quot; = &quot;$IP&quot; ];then             bl=1         fi     done  # \u0415\u0441\u043b\u0438 IP \u0435\u0441\u0442\u044c \u0432 \u0441\u043f\u0438\u0441\u043a\u0430\u0445, \u0437\u043d\u0430\u0447\u0438\u0442 \u0440\u0430\u043d\u0435\u0435 \u0443\u0436\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u0435\u043d, \u043d\u0435 \u043f\u0440\u043e\u0432\u0435\u0440\u044f\u0435\u043c \u0435\u0433\u043e PTR     if [ &quot;$wl&quot; = &quot;1&quot; -o &quot;$bl&quot; = &quot;1&quot; ]; then        [ &quot;$debug&quot; -gt &quot;1&quot; ] && e &quot;$IP in white or black list&quot; &gt;&gt; $LOGFILE2     else         PTR=&quot;&quot;         SRCHBOT=&quot;&quot;         FINDPTR=&quot;`\/usr\/bin\/host $IP | \/bin\/grep -v 'not found' | \/bin\/grep -v 'no PTR record' | \/usr\/bin\/head -1 | \/usr\/bin\/awk '{ print $5 }' | \/bin\/sed 's\/\\.$\/\/'`&quot;         if [ -z &quot;$FINDPTR&quot; ];then             PTR=&quot; (PTR record not found)&quot;         else             PTR=&quot; ($FINDPTR)&quot;         fi         SRCHBOT=`\/usr\/bin\/host $IP | \/usr\/bin\/awk '{ print $5 }' | \/usr\/bin\/rev | \/usr\/bin\/cut -d . -f 2-3 | \/usr\/bin\/rev | \/bin\/egrep &quot;$BOTS&quot;`         [ -n &quot;$SRCHBOT&quot; ] && BOT=&quot;YES&quot; || BOT=&quot;NO&quot;         [ -z &quot;$BLOCK_WITH_PTR&quot; ] && BLOCK_WITH_PTR=true         if [ &quot;$EXPORT_MAP&quot; == &quot;true&quot; ]; then             if [ &quot;$BOT&quot; == &quot;NO&quot; ]; then                 e &quot;$IP blocked $BLOCK_TIME minutes. ($D) Unblock = `\/bin\/date --date=&quot;$BLOCK_TIME minute&quot; +%s`&quot; &gt;&gt; $LOGFILE                 e &quot;$IP$PTR blocked $BLOCK_TIME minutes. ($D)&quot; &gt;&gt; $LOGFILE2                 echo &quot;$IP 0;&quot; &gt;&gt; $BL_FILE             else                 echo &quot;$IP 1;&quot; &gt;&gt; $WL_FILE             fi         fi     fi done &lt; $TMP_LOG  # \u0447\u0430\u0441\u0442\u044c \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0438 \u043f\u043e\u0434\u043c\u0435\u043d\u044b map-\u0444\u0430\u0439\u043b\u043e\u0432 if [ &quot;$EXPORT_MAP&quot; == &quot;true&quot; ]; then      \/bin\/sort -u -o $BL_FILE $BL_FILE &gt; \/dev\/null 2&gt;&1     \/bin\/sort -u -o $WL_FILE $WL_FILE &gt; \/dev\/null 2&gt;&1          MAP_CHANGED=0     if ! diff $BL_FILE $BL_FILE.bak &gt; \/dev\/null 2&gt;&1; then         \/bin\/cp -f $BL_FILE_MAP $BL_FILE_MAP.bak &gt; \/dev\/null 2&gt;&1         \/bin\/cp -f $BL_FILE $BL_FILE_MAP &gt; \/dev\/null 2&gt;&1         MAP_CHANGED=1     fi     if ! diff $WL_FILE $WL_FILE.bak &gt; \/dev\/null 2&gt;&1; then         \/bin\/cp -f $WL_FILE_MAP $WL_FILE_MAP.bak &gt; \/dev\/null 2&gt;&1         \/bin\/cp -f $WL_FILE $WL_FILE_MAP &gt; \/dev\/null 2&gt;&1         MAP_CHANGED=1     fi     if [ &quot;$MAP_CHANGED&quot; -eq &quot;1&quot; -o &quot;$UNBLOCK&quot; -eq &quot;1&quot; ]; then \tRELOAD=`\/usr\/sbin\/nginx -t 2&gt;&1 | \/bin\/grep ok` \tif [ -n &quot;$RELOAD&quot; ];then    \t    \/sbin\/service nginx reload             e &quot;nginx is reloaded&quot; &gt;&gt; $LOGFILE2 \telse     \t    ERROR_RELOAD=`\/sbin\/service nginx configtest 2&gt;&1` \t    \/bin\/cp -f $BL_FILE_MAP.bak $BL_FILE_MAP &gt; \/dev\/null 2&gt;&1 \t    \/bin\/cp -f $WL_FILE_MAP.bak $WL_FILE_MAP &gt; \/dev\/null 2&gt;&1             e &quot;nginx error config test failed&quot; &gt;&gt; $LOGFILE2 \tfi      fi fi \/bin\/rm -rf $LOCK <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>  <\/p>\n<h5>\u0421\u043a\u0440\u0438\u043f\u0442 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0447\u0430\u0441\u0442\u043e\u0442\u044b \u0440\u0435\u0444\u0435\u0440\u0435\u0440\u043e\u0432 \u0438 \u0444\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0444\u0430\u0439\u043b\u0430 referer-block.conf \u0432\u0438\u0434\u0430:<\/h5>\n<p>  <\/p>\n<pre><code class=\"bash\">~domain.ru 0; ~\u2026 1; ~\u2026 1; <\/code><\/pre>\n<p>  \u0417\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u0442\u0441\u044f \u0435\u0436\u0435\u043c\u0438\u043d\u0443\u0442\u043d\u043e.  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041b\u0438\u0441\u0442\u0438\u043d\u0433 \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0447\u0430\u0441\u0442\u043e\u0442\u044b \u0440\u0435\u0444\u0435\u0440\u0435\u0440\u043e\u0432:<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">#!\/bin\/bash # referer_protect v.1.0.6  # \u0411\u0430\u0437\u043e\u0432\u044b\u0435 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0438 \u0441\u043a\u0440\u0438\u043f\u0442\u0430, \u043e\u0431\u044b\u0447\u043d\u043e \u0432\u044b\u043d\u043e\u0441\u044f\u0442\u0441\u044f \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 \u0444\u0430\u0439\u043b, # \u0447\u0442\u043e\u0431\u044b \u0438\u0445 \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u043f\u043e\u0434\u0441\u0442\u0440\u0430\u0438\u0432\u0430\u0442\u044c \u043f\u043e\u0434 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u0435\u043a\u0442, \u043d\u0435 \u043c\u0435\u043d\u044f\u044f \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u043a\u0440\u0438\u043f\u0442. RECORDS=500 DOMAIN_LIST=domain LA=15 # if Load Average &gt; $LA = Referer is block BLOCK_TIME=360 #in minutes #REF_WHITELIST=&quot;&quot; BLOCK_ENABLE=true # true\/false - enable\/disable add firewall rule. email=&quot;mail@mail.ru&quot; LOGFILE=\/var\/log\/referer-table.log LOGFILE2=\/var\/log\/referer-table-history.log LOCK=\/tmp\/referer.lock MSG_ALERT=\/tmp\/msg-alert.tmp debug=&quot;0&quot;  LA_CURRENT=&quot;`cat \/proc\/loadavg | awk '{ print $1}' | awk 'BEGIN { FS=&quot;.&quot;; }{ print $1}'`&quot; DT=`date &quot;+%F %T&quot;`  [ ! -f $LOGFILE ] && touch $LOGFILE [ -f &quot;$MSG_ALERT&quot; ] && rm -f $MSG_ALERT  function e {     echo -e $(date &quot;+%F %T&quot;) $1 }  function msg {     echo &quot;Referer:$REFERER. Domain:$D&quot; &gt;&gt; $MSG_ALERT }  function send_mail {     if [ &quot;$BLOCK_ENABLE&quot; = &quot;true&quot; -a &quot;$LA_CURRENT&quot; -gt &quot;$LA&quot; ];then \tcat $MSG_ALERT | mailx -s &quot;Referers report. Warning&quot; $email     elif [ &quot;$BLOCK_ENABLE&quot; = &quot;true&quot; -a &quot;$LA_CURRENT&quot; -le &quot;$LA&quot; ];then \tcat $MSG_ALERT | mailx -s &quot;Referers report. Notice &quot; $email     else \tcat $MSG_ALERT | mailx -s &quot;Referers report. Notice (Test mode)&quot; $email     fi }  [ -f $LOCK ] && e &quot;Script $0 is already runing&quot; && exit touch $LOCK  NEED_NGINX_RELOAD=0  for D in $DOMAIN_LIST do      TMP_LOG=\/tmp\/ddos-$D-acc-referer.log     TMP_AWK=\/tmp\/tmp_$D-awk.tmp     #NGINX_LOG=\/srv\/www\/$D\/logs\/$D-acc     NGINX_LOG=\/srv\/www\/$D\/shared\/log\/$D-acc.log     REFCONF=\/etc\/nginx\/referer-block-$D.conf      [ ! -s &quot;$REFCONF&quot; ] && echo &quot;~$D 0;&quot; &gt;&gt; $REFCONF      if [ ! -f $NGINX_LOG ];then         echo &quot;Log ($NGINX_LOG) not found.&quot;         \/bin\/rm -rf $LOCK         exit     fi      tail -10000 $NGINX_LOG | awk '($9 == &quot;200&quot;) || ($9 == &quot;404&quot;)' | awk '{print $11}' | sort | uniq -c | sort -n | awk -v x=$RECORDS ' $1 &gt; x {print $2} ' &gt; $TMP_LOG     sed -i &quot;s\/\\&quot;\/\/g&quot; $TMP_LOG # \u0443\u0431\u0438\u0440\u0430\u0435\u043c \u043a\u0430\u0432\u044b\u0447\u043a\u0438     sed -i &quot;\/^-\/d&quot; $TMP_LOG # \u0443\u0431\u0438\u0440\u0430\u0435\u043c referer &quot;-&quot;     sed -i &quot;\/$D\/d&quot; $TMP_LOG # \u0443\u0431\u0438\u0440\u0430\u0435\u043c \u0441\u0432\u043e\u0439 \u0434\u043e\u043c\u0435\u043d     sed -i &quot;\/^localhost\/d&quot; $TMP_LOG # \u0443\u0431\u0438\u0440\u0430\u0435\u043c localhost     awk -F\/ '{print $3}' $TMP_LOG &gt; $TMP_AWK # \u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c \u0442\u043e\u043b\u044c\u043a\u043e \u0434\u043e\u043c\u0435\u043d \u043e\u0442 url     cat $TMP_AWK &gt; $TMP_LOG      # \u0420\u0430\u0437\u0431\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c \u0437\u0430\u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 referer     while read line         do             if [[ &quot;$line&quot; == *=* ]]; then                 GET_TIME=`echo $line | awk -F&quot;=&quot; '{print $2}'`                 NOW=`date +%s`                 #echo $NOW                 #echo $GET_TIME                 if [ &quot;$NOW&quot; -gt &quot;$GET_TIME&quot; ]; then                     REFERER=`echo $line | awk '{print $4}'`                     e &quot;Referer $REFERER unblocked.&quot; &gt;&gt; $LOGFILE2                     \/bin\/sed -i '\/'$REFERER'\/d' $LOGFILE                     \/bin\/sed -i '\/'$REFERER'\/d' $REFCONF \t\t    NEED_NGINX_RELOAD=1                fi             fi         done &lt; $LOGFILE      # \u0411\u043b\u043e\u043a\u0438\u0440\u0443\u0435\u043c referer     while read line     do         REFERER=$line          DOUBLE=`cat $REFCONF | grep &quot;$REFERER&quot;`         if [ -n &quot;$DOUBLE&quot; ]; then             [ &quot;$debug&quot; != &quot;0&quot; ] && e &quot;referer $REFERER exist in DROP rule&quot; \telse \t    if [ &quot;$BLOCK_ENABLE&quot; = &quot;true&quot; -a &quot;$LA_CURRENT&quot; -gt &quot;$LA&quot; ];then \t\techo &quot;~$REFERER 1;&quot; &gt;&gt; $REFCONF \t\te &quot;Referer $REFERER blocked $BLOCK_TIME minutes ($D) Unblock = `date --date=&quot;$BLOCK_TIME minute&quot; +%s`&quot; &gt;&gt; $LOGFILE \t\te &quot;Referer $REFERER blocked $BLOCK_TIME minutes ($D)&quot; &gt;&gt; $LOGFILE2 \t        NEED_NGINX_RELOAD=1 \t\tif [ ! -s &quot;$MSG_ALERT&quot; ];then  \t\t    echo &quot;Status: WARNING&quot; &gt; $MSG_ALERT \t\t    echo &quot;Date: $DT&quot; &gt;&gt; $MSG_ALERT \t\t    echo &quot;Referer: $RECORDS matches from 10000&quot; &gt;&gt; $MSG_ALERT  \t\t    echo &quot;LA: $LA_CURRENT&quot; &gt;&gt; $MSG_ALERT \t\t    echo &quot;Referer(s) is blocked on $BLOCK_TIME minutes:&quot; &gt;&gt; $MSG_ALERT \t\t    echo &quot;&quot; &gt;&gt; $MSG_ALERT \t\tfi \t\tmsg \t    elif [ &quot;$BLOCK_ENABLE&quot; = &quot;true&quot; -a &quot;$LA_CURRENT&quot; -le &quot;$LA&quot; ];then     \t\tTESTDOUBLE=`cat $LOGFILE | grep &quot;$REFERER&quot;` \t        if [ -z &quot;$TESTDOUBLE&quot; ]; then \t\t    e &quot;Referer $REFERER TEST blocked $BLOCK_TIME minutes ($D) Unblock = `date --date=&quot;$BLOCK_TIME minute&quot; +%s`&quot; &gt;&gt; $LOGFILE \t\t    e &quot;TEST. Referer $REFERER TEST blocked $BLOCK_TIME minutes ($D)&quot; &gt;&gt; $LOGFILE2 \t\t    if [ ! -s &quot;$MSG_ALERT&quot; ];then  \t\t\techo &quot;Status: Notice&quot; &gt; $MSG_ALERT \t\t\techo &quot;Date: $DT&quot; &gt;&gt; $MSG_ALERT \t\t\techo &quot;Referer: $RECORDS matches from 10000&quot; &gt;&gt; $MSG_ALERT  \t\t\techo &quot;LA: $LA_CURRENT&quot; &gt;&gt; $MSG_ALERT \t\t\techo &quot;Referer(s) not blocking:&quot; &gt;&gt; $MSG_ALERT \t\t\techo &quot;&quot; &gt;&gt; $MSG_ALERT \t\t    fi \t\t    msg \t\tfi \t    else     \t\tTESTDOUBLE=`cat $LOGFILE | grep &quot;$REFERER&quot;` \t        if [ -z &quot;$TESTDOUBLE&quot; ]; then \t\t    e &quot;Referer $REFERER TEST blocked $BLOCK_TIME minutes ($D) Unblock = `date --date=&quot;$BLOCK_TIME minute&quot; +%s`&quot; &gt;&gt; $LOGFILE \t\t    e &quot;TEST. Referer $REFERER TEST blocked $BLOCK_TIME minutes ($D)&quot; &gt;&gt; $LOGFILE2 \t\t    if [ ! -s &quot;$MSG_ALERT&quot; ];then  \t\t\techo &quot;Date: $DT&quot; &gt; $MSG_ALERT \t\t\techo &quot;Current referer found over $RECORDS matches from 10000 records, but script working is TEST MODE &quot; &gt;&gt; $MSG_ALERT  \t\t\techo &quot;Current LA - $LA_CURRENT&quot; &gt;&gt; $MSG_ALERT \t\t\techo &quot;Referer(s) not blocking:&quot; &gt;&gt; $MSG_ALERT \t\t\techo &quot;&quot; &gt;&gt; $MSG_ALERT \t\t    fi \t\t    msg \t\tfi \t    fi \tfi      done &lt; $TMP_LOG  [ -n &quot;email&quot; -a -s &quot;$MSG_ALERT&quot; ] && send_mail  done  # reload nginx if config change if [ $NEED_NGINX_RELOAD -eq 1 ]; then   \/sbin\/service nginx reload &gt;\/dev\/null 2&gt;\/dev\/null fi  \/bin\/rm -rf $LOCK <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>   <\/p>\n<h5>\u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0444\u0430\u0439\u043b nginx \u043a\u0430\u043a \u0441\u0438\u043c\u043b\u0438\u043d\u043a \u0443\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442 \u043d\u0430 \u043e\u0434\u0438\u043d \u0438\u0437 \u0434\u0432\u0443\u0445 \u0444\u0430\u0439\u043b\u043e\u0432, \u0440\u0430\u0431\u043e\u0442\u0430\u044e\u0449\u0438\u0445 \u0432 \u043e\u0431\u044b\u0447\u043d\u043e\u043c \u0438 high LA \u0440\u0435\u0436\u0438\u043c\u0430\u0445.<\/h5>\n<p>  \u0420\u0435\u0436\u0438\u043c \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0441\u043a\u0440\u0438\u043f\u0442\u043e\u043c, \u0438\u0441\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u044b\u043c \u0435\u0436\u0435\u043c\u0438\u043d\u0443\u0442\u043d\u043e \u0438\u0437 Cron  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u0421\u043a\u0440\u0438\u043f\u0442 \u043f\u0435\u0440\u0435\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u0440\u0435\u0436\u0438\u043c\u043e\u0432:<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">#!\/bin\/bash  ### check LA level MAX_LA=10  processid=`\/sbin\/pidof -x $(basename $0) -o %PPID` if [[ $processid ]];then exit fi  CFG_DDOS='fpm.domain.ru.ddos' CFG_NODDOS='fpm.domain.ru.noddos'   load_average=$(uptime | awk '{print $11}' | cut -d &quot;.&quot; -f 1) echo &quot;$(date '+%Y-%m-%d %H:%M') : LA $load_average&quot;  if [[ $load_average -ge $MAX_LA ]]; then   if [ -f \/tmp\/la_flag ]; then     date '+%s' &gt; \/tmp\/la_flag      exit 1   else #    echo &quot;$(date +%Y-%m-%d-%H-%M)&quot;     date '+%s' &gt; \/tmp\/la_flag      mv \/etc\/nginx\/vhosts.d\/new.domain.ru.conf \/etc\/nginx\/vhosts.d\/new.domain.ru.conf.bak &gt; \/dev\/null 2&gt;&1     ln -s \/etc\/nginx\/vhosts.d\/$CFG_DDOS \/etc\/nginx\/vhosts.d\/new.domain.ru.conf     reload=`\/usr\/sbin\/nginx -t 2&gt;&1 | grep ok`     if [ -n &quot;$reload&quot; ];then       \/sbin\/service nginx reload       rm -f \/etc\/nginx\/vhosts.d\/new.domain.ru.conf.bak &gt; \/dev\/null 2&gt;&1       echo &quot;$(date '+%Y-%m-%d %H:%M') : DDOS config up $reload&quot;       exit 0     else       \/sbin\/service nginx configtest 2&gt;&1       mv \/etc\/nginx\/vhosts.d\/new.domain.ru.conf.bak \/etc\/nginx\/vhosts.d\/new.domain.ru.conf &gt; \/dev\/null 2&gt;&1       echo &quot;nginx error config ddos test failed&quot;       echo &quot;alarm nginx config ddos test failed&quot; | mail -s alarm root\t\t       exit 1     fi   fi else   if [ -f \/tmp\/la_flag ]; then     TIMEA=`cat \/tmp\/la_flag`     TIMEC=`date '+%s'`     TIMED=$(( $TIMEC - $TIMEA ))     if [ $TIMED -gt 600 ]; then       echo &quot;high LA ENDED $(date +%Y-%m-%d-%H-%M)&quot;       rm -f \/tmp\/la_flag &gt; \/dev\/null 2&gt;&1       mv \/etc\/nginx\/vhosts.d\/new.domain.ru.conf \/etc\/nginx\/vhosts.d\/new.domain.ru.conf.bak &gt; \/dev\/null 2&gt;&1       ln -s \/etc\/nginx\/vhosts.d\/$CFG_NODDOS \/etc\/nginx\/vhosts.d\/new.domain.ru.conf       reload=`\/usr\/sbin\/nginx -t 2&gt;&1 | grep ok`       echo &quot;$(date '+%Y-%m-%d %H:%M') : NO DDOS config up $reload&quot;       if [ -n &quot;$reload&quot; ];then          \/sbin\/service nginx reload          rm -f \/etc\/nginx\/vhosts.d\/new.domain.ru.conf.bak &gt; \/dev\/null 2&gt;&1          echo &quot;$(date '+%Y-%m-%d %H:%M') : NO ddos config up&quot; \t exit 0       else         \/sbin\/service nginx configtest 2&gt;&1         mv \/etc\/nginx\/vhosts.d\/new.domain.ru.conf.bak \/etc\/nginx\/vhosts.d\/new.domain.ru.conf &gt; \/dev\/null 2&gt;&1 \techo &quot;nginx error config noddos test failed&quot; \techo &quot;alarm nginx config noddos test failed&quot; | mail -s alarm root         exit 1       fi     else       exit 1     fi   else     exit 1   fi fi  <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>  <\/p>\n<h5> \u0427\u0430\u0441\u0442\u044c \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u0442\u0434\u0435\u043b\u044c\u043d\u044b\u0439 \u0444\u0430\u0439\u043b, \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0430\u0435\u043c\u044b\u0439 \u0432 \u043e\u0441\u043d\u043e\u0432\u043d\u044b\u0445 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u0430\u0445.<\/h5>\n<p>  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u0424\u0430\u0439\u043b \u0441 \u043e\u0431\u0449\u0438\u043c\u0438 \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u0430\u043c\u0438 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u0438 \u0434\u043b\u044f \u043e\u0431\u043e\u0438\u0445 \u0440\u0435\u0436\u0438\u043c\u043e\u0432 vhosts.d\/map.domain.ru.inc:<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">map_hash_bucket_size 128; geoip_country \/usr\/share\/GeoIP\/GeoIP.dat;  limit_req_zone $newlimit_addres1 zone=newone:10m rate=50r\/m;  map $whitelist-$remote_addr:$remote_port $newlimit_addres1 {     ~&quot;^0&quot;                   $binary_remote_addr;     ~&quot;^1-(?&lt;match_rap&gt;.*)&quot;  $match_rap; }  geo $whitelist {    default 0;    91.205.47.150 1;    194.87.91.154 1;    83.69.225.78 1;    77.88.18.82 1;    91.143.46.202 1;    213.180.192.0\/19 1;    87.250.224.0\/19 1;    77.88.0.0\/18 1;    93.158.128.0\/18 1;    95.108.128.0\/17 1;    178.154.128.0\/17 1;    199.36.240.0\/22 1;    84.201.128.0\/18 1;    141.8.128.0\/18 1;    188.134.88.105 1;    89.163.3.25 1;    46.39.246.91 1;    84.21.76.123 1;    136.243.83.53 1;    77.50.238.152 1;    83.167.117.49 1;    109.188.82.40 1;    79.141.227.19 1;    176.192.62.78 1;    86.62.91.133 1;    144.76.88.101 1; }  # \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 \u0440\u0435\u0444\u0435\u0440\u0435\u0440\u043e\u0432 \u0447\u0435\u0440\u0435\u0437 \u0441\u043a\u0440\u0438\u043f\u0442 block_referer.sh map $http_referer $bad_referer {     default      &quot;0&quot;;     include \/etc\/nginx\/referer-block.conf; } map $http_referer:$request_method $bad_post_referer {     default      &quot;0&quot;;     &quot;~*domain.ru.*:POST$&quot; &quot;0&quot;;     &quot;~*:POST$&quot; &quot;1&quot;;     include \/etc\/nginx\/referer-block.conf; }  # \u041d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u043d\u0430\u0431\u043e\u0440 \u0441\u043f\u0438\u0446\u0435\u0444\u0438\u0447\u043d\u044b\u0445 \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043e\u043a \u043f\u0440\u043e\u0435\u043a\u0442\u0430 map $query_string $bad_query { ...     default 0; }  # \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0430 \u043a\u0443\u043a, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0442 \u0432 \u0444\u0430\u0439\u043b\u0435 \/checkcapcha.php map $http_cookie $allowed_cookie {   &quot;~somecookie&quot; 1;   default  0; }  \u041e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u0435 \u043f\u043e GeoIP \u0432 \u0440\u0435\u0436\u0438\u043c\u0435 \u041f\u043e\u0434 \u0430\u0442\u0430\u043a\u043e\u0439 map $geoip_country_code $allowed_country {     RU 1;     default 0; }  # \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u043a\u0430 \u043f\u043e\u0434\u0441\u0435\u0442\u0435\u0439 Amazon include vhosts.d\/deny-amazon.inc;  # \u0420\u0443\u0447\u043d\u044b\u0435 \u0431\u0435\u043b\u044b\u0439 \u0438 \u0447\u0435\u0440\u043d\u044b\u0439 \u0441\u043f\u0438\u0441\u043a\u0438 map $remote_addr $valid_addr {     include vhosts.d\/main_blacklist.map;     include vhosts.d\/main_whitelist.map;     default 2; }  # UA \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439-\u0431\u043e\u0442\u043e\u0432 map $http_user_agent $user_agent_search_bot {     &quot;~Yandex&quot;           &quot;1&quot;;     &quot;~Google&quot;           &quot;1&quot;;     &quot;~*bing&quot;            &quot;1&quot;;     &quot;~*MSNBot&quot;          &quot;1&quot;;     default             &quot;&quot;; }  map $remote_addr $ptr_wl_bl {     include vhosts.d\/ptr_blacklist.map;     include vhosts.d\/ptr_whitelist.map;     default &quot;&quot;; } map &quot;$user_agent_search_bot:$ptr_wl_bl&quot; $searchbot {     &quot;1:1&quot;  &quot;1&quot;;     &quot;1:0&quot;  &quot;0&quot;;     default  &quot;2&quot;; } <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>  <\/p>\n<h5>\u041b\u0438\u0441\u0442\u0438\u043d\u0433\u0438 \u043a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0445 \u0444\u0430\u0439\u043b\u043e\u0432<\/h5>\n<p>  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u043a\u043e\u043d\u0444\u0438\u0433 \u0434\u043b\u044f \u043d\u043e\u0440\u043c\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u0440\u0435\u0436\u0438\u043c\u0430 \u0440\u0430\u0431\u043e\u0442\u044b vhosts.d\/fpm.domain.ru.noddos:<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">include vhosts.d\/map.domain.ru.inc;  map &quot;$searchbot:$valid_addr:$bad_referer:$bad_query&quot; $root_location_p1 {     default   @allow_limit;     &quot;~^1:&quot;    @allow;     &quot;~^2:1&quot;   @allow_limit;      &quot;~^0&quot;      @loc_403;     &quot;~^2:0&quot;    @loc_403;     &quot;2:2:1:0&quot;  @loc_403;     &quot;2:2:1:1&quot;  @loc_403;     &quot;2:2:0:1&quot;  @loc_403; }  map &quot;$searchbot:$valid_addr:$bad_post_referer:$bad_query&quot; $root_only_location_p1 {     default   @allow_limit;     &quot;~^1:&quot;    @allow;     &quot;~^2:1&quot;   @allow_limit;      &quot;~^0&quot;      @loc_403;     &quot;~^2:0&quot;    @loc_403;     &quot;2:2:1:0&quot;  @loc_403;     &quot;2:2:1:1&quot;  @loc_403;     &quot;2:2:0:1&quot;  @loc_403; }  ########################################################  server {      listen 80;     listen 443 ssl;      fastcgi_read_timeout 300s;     fastcgi_send_timeout 300s;     fastcgi_connect_timeout 300s;      server_name domain.ru www.domain.ru m.domain.ru www.m.domain.ru;       ssl_certificate ssl\/www.domain.ru.crt;     ssl_certificate_key ssl\/www.domain.ru.key;     charset UTF-8;      access_log \/srv\/www\/domain\/shared\/log\/domain-acc.log main;     error_log \/srv\/www\/domain\/shared\/log\/domain-err.log;      root   \/srv\/www\/domain\/current\/public\/;      error_page 500 502 \/highla.html;  # \u0412\u044b\u0434\u0430\u0435\u0442\u0441\u044f capcha \u0432 \u0444\u0430\u0440\u043c\u0435 POST \u0441 action=&quot;\/checkcapcha.php&quot;     location = \/highla.html {         charset UTF-8;         root   \/srv\/www\/domain\/current\/public\/;         allow all;     }  # \u0423\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0445\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u043a\u0443\u043a\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u0434\u0440\u0435\u0441\u0430 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u044f.     location = \/checkcapcha.php {         charset UTF-8;         root   \/srv\/www\/domain\/current\/public\/;         include fastcgi_params;         fastcgi_buffers 8 16k;         fastcgi_buffer_size 32k;         fastcgi_index index.php;         fastcgi_param  SCRIPT_FILENAME $realpath_root$fastcgi_script_name;         fastcgi_param  REQUEST_SCHEME     $scheme;         fastcgi_param  HTTPS              $https if_not_empty;         fastcgi_pass 127.0.0.1:9000;         allow all;     }  # \u0418\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u043d\u044b\u0435 location \u0434\u043b\u044f \u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u043e \u043d\u0438\u043c \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u0443\u044e map     location @loc_403 {       access_log \/srv\/www\/domain\/shared\/log\/loc_403-acc main;       return 403;     }      location @allow {         access_log \/srv\/www\/domain\/shared\/log\/allow-acc main;         add_header X-debug-message &quot;Allow&quot;;         try_files $uri \/index.php?$query_string;     }      location @allow_limit {         limit_req zone=newone burst=15;         access_log \/srv\/www\/domain\/shared\/log\/allow-acc main;         add_header X-debug-message &quot;Allow&quot;;         try_files $uri \/index.php?$query_string;     }      location @deny {         access_log \/srv\/www\/domain\/shared\/log\/deny-acc main;         add_header X-debug-message &quot;Deny&quot;;         return 403;     }     location @restrict {         access_log \/srv\/www\/domain\/shared\/log\/resrtict-acc main;         add_header X-debug-message &quot;Restrict&quot;;         return 502;     }      location \/ {         try_files \/fake-nonexistens-location-forr273 $root_location_p1;     }      location = \/ {         try_files \/fake-nonexistens-location-forr273 $root_only_location_p1;     }      location ~* \\.php {        include fastcgi_params;        fastcgi_buffers 8 16k;        fastcgi_buffer_size 32k;        fastcgi_index index.php;        fastcgi_param  SCRIPT_FILENAME $realpath_root$fastcgi_script_name;        fastcgi_param  REQUEST_SCHEME     $scheme;        fastcgi_param  HTTPS              $https if_not_empty;        fastcgi_pass 127.0.0.1:9000;     }      location ~* \\.(jpg|jpeg|gif|png|ico|css|zip|tgz|gz|rar|bz2|doc|xls|exe|pdf|ppt|tar|mid|midi|wav|bmp|rtf|js|swf|flv|avi|djvu|mp3)$ {         root \/srv\/www\/domain\/current\/public; \texpires 7d; \taccess_log off; \tlog_not_found off;     }      location ~ \/\\.git {         deny all;     }      location ~ \/\\.ht {         deny all;     }      location ~ \/\\.svn {         deny all;     }  } <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>  <\/p>\n<div class=\"spoiler\"><b class=\"spoiler_title\">\u041a\u043e\u043d\u0444\u0438\u0433 \u0434\u043b\u044f \u0440\u0435\u0436\u0438\u043c\u0430 high LA vhosts.d\/fpm.domain.ru.ddos:<\/b><\/p>\n<div class=\"spoiler_text\">\n<pre><code class=\"bash\">include vhosts.d\/map.domain.ru.inc;  map &quot;$searchbot:$valid_addr:$bad_referer:$bad_query&quot; $root_location {     default   @main;     &quot;~^1:&quot;    @allow;     &quot;~^2:1&quot;   @allow;      &quot;~^0&quot;      @loc_403;     &quot;~^2:0&quot;    @loc_403;     &quot;2:2:1:0&quot;  @loc_403;     &quot;2:2:1:1&quot;  @loc_403;     &quot;2:2:0:1&quot;  @loc_403; }  map &quot;$searchbot:$valid_addr:$bad_post_referer:$bad_query&quot; $root_only_location {     default   @main;     &quot;~^1:&quot;    @allow;     &quot;~^2:1&quot;   @allow;      &quot;~^0&quot;      @loc_403;     &quot;~^2:0&quot;    @loc_403;     &quot;2:2:1:0&quot;  @loc_403;     &quot;2:2:1:1&quot;  @loc_403;     &quot;2:2:0:1&quot;  @loc_403; }  map &quot;$allowed_country:$allowed_cookie&quot; $main_location {     &quot;1:0&quot;    @allow_limit;     &quot;1:1&quot;    @allow_limit;     &quot;0:1&quot;    @allow_limit;     default  @restrict; }  ########################################################  server {     listen 80;     listen 443 ssl;          fastcgi_read_timeout 300s;     fastcgi_send_timeout 300s;     fastcgi_connect_timeout 300s;      server_name domain.ru www.domain.ru m.domain.ru www.m.domain.ru;      ssl_certificate ssl\/www.domain.ru.crt;     ssl_certificate_key ssl\/www.domain.ru.key;     charset UTF-8;      access_log \/srv\/www\/domain\/shared\/log\/domain-acc.log main;     error_log \/srv\/www\/domain\/shared\/log\/domain-err.log;      root   \/srv\/www\/domain\/current\/public\/;  # \u0412\u044b\u0434\u0430\u0435\u0442\u0441\u044f capcha \u0432 \u0444\u0430\u0440\u043c\u0435 POST \u0441 action=&quot;\/checkcapcha.php&quot;     error_page 500 502 \/highla.html;     location = \/highla.html {         charset UTF-8; \troot   \/srv\/www\/domain\/current\/public\/;         allow all;     }  # \u0423\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0445\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u0430\u044f \u043a\u0443\u043a\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u0434\u0440\u0435\u0441\u0430 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u044f.     location = \/checkcapcha.php {         charset UTF-8;         root   \/srv\/www\/domain\/current\/public\/;         include fastcgi_params;         fastcgi_buffers 8 16k;         fastcgi_buffer_size 32k;         fastcgi_index index.php;         fastcgi_param  SCRIPT_FILENAME $realpath_root$fastcgi_script_name;         fastcgi_param  REQUEST_SCHEME     $scheme;         fastcgi_param  HTTPS              $https if_not_empty;         fastcgi_pass 127.0.0.1:9000;         allow all;     }  # \u0418\u043c\u0435\u043d\u043e\u0432\u0430\u043d\u043d\u044b\u0435 location \u0434\u043b\u044f \u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u043e \u043d\u0438\u043c \u0447\u0435\u0440\u0435\u0437 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u0443\u044e map     location @loc_403 {       access_log \/srv\/www\/domain\/shared\/log\/loc_403-acc main;       return 403;     }          location @allow {         access_log \/srv\/www\/domain\/shared\/log\/allow-acc main;         add_header X-debug-message &quot;Allow&quot;;         try_files $uri \/index.php?$query_string;     }      location @allow_limit {         limit_req zone=newone burst=55;         access_log \/srv\/www\/domain\/shared\/log\/allow-limit-acc main;         add_header X-debug-message &quot;Allow&quot;;         try_files $uri \/index.php?$query_string;     }      location @deny {         access_log \/srv\/www\/domain\/shared\/log\/deny-acc main;         add_header X-debug-message &quot;Deny&quot;;         return 403;     }     location @restrict {         access_log \/srv\/www\/domain\/shared\/log\/resrtict-acc main;         add_header X-debug-message &quot;Restrict&quot;;         return 502;     }      location @main {         add_header X-debug-message &quot;Main&quot;; \ttry_files \/fake-nonexistens-location-forr273 $main_location;     }      location \/ { \ttry_files \/fake-nonexistens-location-forr273 $root_location;     }      location = \/ { \ttry_files \/fake-nonexistens-location-forr273 $root_only_location;     }      location ~* \\.php {        include fastcgi_params;        fastcgi_buffers 8 16k;        fastcgi_buffer_size 32k;        fastcgi_index index.php;        fastcgi_param  SCRIPT_FILENAME $realpath_root$fastcgi_script_name;        fastcgi_param  REQUEST_SCHEME     $scheme;        fastcgi_param  HTTPS              $https if_not_empty;        fastcgi_pass 127.0.0.1:9000;     }      location ~* \\.(jpg|jpeg|gif|png|ico|css|zip|tgz|gz|rar|bz2|doc|xls|exe|pdf|ppt|tar|mid|midi|wav|bmp|rtf|js|swf|flv|avi|djvu|mp3)$ {         root \/srv\/www\/domain\/current\/public;         expires 7d;         access_log off;         log_not_found off;     }      location ~ \/\\.git {         deny all;     }      location ~ \/\\.ht {         deny all;     }      location ~ \/\\.svn {         deny all;     } } <\/code><\/pre>\n<p>  <\/div>\n<\/div>\n<p>  <\/p>\n<h5>\u0418\u0442\u043e\u0433<\/h5>\n<p>  \u042d\u0442\u0438\u043c \u0440\u0435\u0448\u0435\u043d\u0438\u0435\u043c \u043c\u044b \u043f\u043e\u043c\u043e\u0433\u043b\u0438 \u043d\u0430\u0448\u0435\u043c\u0443 \u043a\u043b\u0438\u0435\u043d\u0442\u0443 \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u0439 \u043f\u0440\u043e\u0435\u043a\u0442 \u043e\u0442 \u043f\u0430\u0440\u0430\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u0438 \u043f\u043e\u0432\u044b\u0441\u0438\u0442\u044c \u0441\u0442\u0430\u0431\u0438\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0440\u0430\u0431\u043e\u0442\u044b \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432.<br \/>  \u0410\u0432\u0442\u043e\u0440: \u0432\u0435\u0434\u0443\u0449\u0438\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u043d\u044b\u0439 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440 <a href=\"http:\/\/centos-admin.ru\">\u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438<\/a> \u041c\u0430\u0440\u0430\u0442 \u0420\u0430\u0445\u0438\u043c\u043e\u0432.               <\/p>\n<div class=\"clear\"><\/div>\n<p> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habrahabr.ru\/post\/278553\/\"> https:\/\/habrahabr.ru\/post\/278553\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>       <img decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/post_images\/c55\/a04\/3dd\/c55a043ddd3b007885d70bc836a5729e.jpg\" alt=\"image\"\/><br \/>  \u041a\u043b\u044e\u0447\u0435\u0432\u044b\u0435 \u043c\u043e\u043c\u0435\u043d\u0442\u044b:<br \/>  * \u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u0441\u043a\u0440\u0438\u043f\u0442\u0430 \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 PTR \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439;<br \/>  * \u041a\u043e\u043d\u0444\u0438\u0433\u0443\u0440\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u0435 nginx \u0432 IfIsEvil-style \u0441 \u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u044f\u043c\u0438 map;<br \/>  * \u0418\u043c\u0435\u043d\u0430 location \u0432 \u043f\u0435\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u0445 map;<br \/>  * \u0423\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0432\u0435\u0442\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u0447\u0435\u0440\u0435\u0437 try_files \/nonexist $map_var.<\/p>\n<p>  \u041c\u043d\u043e\u0433\u0438\u0435 \u0432\u044b\u0441\u043e\u043a\u043e\u043d\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u044b\u0435 \u0438 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0435 \u0441\u0430\u0439\u0442\u044b \u0441\u0442\u0440\u0430\u0434\u0430\u044e\u0442 \u043e\u0442 \u0442\u043e\u0433\u043e, \u0447\u0442\u043e \u043a\u0440\u043e\u043c\u0435 \u0436\u0438\u0432\u044b\u0445 \u043f\u043e\u0441\u0435\u0442\u0438\u0442\u0435\u043b\u0435\u0439 \u0438\u0445 \u043f\u043e\u0441\u0435\u0449\u0430\u044e\u0442 \u0440\u0430\u0437\u043d\u043e\u043e\u0431\u0440\u0430\u0437\u043d\u044b\u0435 \u043f\u0430\u0440\u0441\u0435\u0440\u044b, \u0431\u043e\u0442\u044b \u0438 \u043f\u0440\u043e\u0447\u0438\u0435 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0447\u0435\u0441\u043a\u0438\u0435 \u0441\u043a\u0430\u043d\u0435\u0440\u044b, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043d\u0435 \u043d\u0435\u0441\u0443\u0442 \u043d\u0438\u043a\u0430\u043a\u043e\u0433\u043e \u043f\u043e\u043b\u0435\u0437\u043d\u043e\u0433\u043e \u044d\u0444\u0444\u0435\u043a\u0442\u0430, \u0430 \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u043e\u0437\u0434\u0430\u044e\u0442 \u043f\u0430\u0440\u0430\u0437\u0438\u0442\u043d\u044b\u0439 \u0442\u0440\u0430\u0444\u0438\u043a \u0438 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0443 \u043d\u0430, \u0438 \u0431\u0435\u0437 \u0442\u043e\u0433\u043e, \u043d\u0430\u0433\u0440\u0443\u0436\u0435\u043d\u043d\u0443\u044e \u0441\u0438\u0441\u0442\u0435\u043c\u0443. \u0412 \u0434\u0430\u043d\u043d\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435 \u044f \u043d\u0435 \u0438\u043c\u0435\u044e \u0432\u0438\u0434\u0443 \u043f\u043e\u0438\u0441\u043a\u043e\u0432\u044b\u0445 \u0431\u043e\u0442\u043e\u0432, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0445\u043e\u0442\u044c \u0438 \u0437\u0430\u0447\u0430\u0441\u0442\u0443\u044e \u043d\u0430\u0433\u0440\u0443\u0436\u0430\u044e\u0442 \u043f\u0440\u043e\u0435\u043a\u0442 \u043d\u0435 \u043d\u043e\u0440\u043c\u0438\u0440\u043e\u0432\u0430\u043d\u043e, \u043d\u043e \u043f\u0440\u043e\u0441\u0442\u043e \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u044b \u043b\u044e\u0431\u043e\u043c\u0443 \u043f\u0440\u043e\u0435\u043a\u0442\u0443.<br \/>  \u041e\u0434\u0438\u043d \u0438\u0437 \u043d\u0430\u0448\u0438\u0445 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u0432 \u0440\u0435\u0433\u0443\u043b\u044f\u0440\u043d\u043e \u0438\u0441\u043f\u044b\u0442\u044b\u0432\u0430\u043b \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0443 \u043b\u0430\u0432\u0438\u043d\u043e\u043e\u0431\u0440\u0430\u0437\u043d\u043e\u0433\u043e \u0440\u043e\u0441\u0442\u0430 \u043d\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0432 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u043d\u043e\u0435 \u0432\u0440\u0435\u043c\u044f \u0441\u0443\u0442\u043e\u043a. \u041f\u0435\u0440\u0438\u043e\u0434\u0438\u0447\u0435\u0441\u043a\u0438, \u0440\u0430\u0437 \u0432 \u0441\u0443\u0442\u043a\u0438 \u0438 \u0447\u0430\u0449\u0435 \u043f\u0440\u043e\u0438\u0441\u0445\u043e\u0434\u0438\u043b\u0438 \u043d\u0430\u043f\u043b\u044b\u0432\u044b \u043f\u043e\u0441\u0435\u0449\u0435\u043d\u0438\u0439 \u0441\u043e \u0437\u043d\u0430\u0447\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u043c \u0440\u043e\u0441\u0442\u043e\u043c LA \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u0445. \u0411\u044b\u043b\u043e \u043f\u0440\u0438\u043d\u044f\u0442\u043e \u0440\u0435\u0448\u0435\u043d\u0438\u0435 \u043f\u043e\u0441\u0442\u0440\u043e\u0438\u0442\u044c \u0437\u0430\u0449\u0438\u0442\u0443 \u043e\u0442 \u043f\u0430\u0440\u0430\u0437\u0438\u0442\u043d\u043e\u0433\u043e \u0442\u0440\u0430\u0444\u0438\u043a\u0430.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-275479","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/275479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=275479"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/275479\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=275479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=275479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=275479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}