[CentOS-mirror] Abusive repodata downloads

Tue Apr 2 10:35:53 UTC 2024
Carsten Otto <otto at informatik.rwth-aachen.de>

Hi,

I'm one of the admins of ftp.halifax.rwth-aachen.de, which offers fedora
and fedora-epel among other distributions and projects. I've recently
noticed that many Fedora users (including EPEL, CentOS, and BlackArch)
frequently re-download "repodata" files that haven't been updated since
the previous request.

As some of those files are rather large ("filelists") and others are hit
extremely often, I added fail2ban rules to deny users access to our
service for some time.

Please adjust your software so that file mirrors like ours are not
(ab)used like this. Files that haven't been changed usually shouldn't be
downloaded.

Thanks
Carsten
-- 
Dr. Carsten Otto
http://verify.rwth-aachen.de/otto/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
URL: <http://lists.centos.org/pipermail/centos-mirror/attachments/20240402/90bc0811/attachment.sig>