Site hit by attack / ddos

My site was hit by an attack / ddos on the 2nd/3rd January - it is on the hobby tier and has been paused by Vercel. Even if I upgraded to Pro the edge requests / traffic that the attack used would exceed the Pro limits. What can I do in this situation please?

I have now added a firewall rule to challenge traffic coming from the region these requests are being made (pdx1). However my site is still paused and unsure how to proceed to get my site back online.

Hi @rd13, welcome to the Vercel Community!

Thanks for sharing this here. I’m happy to see that the issue got resolved automatically.

See you around in the community. :wave:

@anshumanb

This attack is continuing - I have a firewall rule in place blocking by user agent:

Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6778.139 Mobile Safari/537.36 (compatible; GoogleOther)

It looks as though the IP address range is actually googlebot?

Are you familiar with these IP address ranges? They seem to be targeting random and non-existent paths.

I am trying to deploy a fix to 404 some of these paths it is trying to crawl however deployment is blocked on my account. Can you fix this please?

Hi @rd13, sorry that you’re facing this issue.

Have you tried activating the Attack Challenge Mode?

As the next step, you can also try blocking these IP addresses and see if it stops the attack.