I hadn't looked at it this morning yet, but just now did and yes, the load average is down to 3-7. I checked the files and it looks like Charles (or a support admin) modified the .htaccess file to block the entire /24 subnet of the offending IP address and that seems to have done the trick. Other files/scripts may have been changed as well, but that's the most obvious one to me and I haven't spoken to Charles about it yet. I can still see tons of "GET" requests in the log files from the offending IP address, but it looks like they're being ignored/blocked/denied so the load it would normally generate isn't happening. I'd still like to deny requests from that IP/range to begin with, but I'll be content to see them symptoms go away even if the disease is still there. Let's hope things stay this way and thanks for pointing out that it's working better now to remind me to have a look.
|