The site has been running slowly due to this:
site:/var/disco# iptables -L | grep yandex | wc -l
333
site:/var/disco#
I just took decisive action by blocking Yandex networks in iptables
using a /16
CIDR range.
Sample Reference:
REJECT all -- 95-108-213-139.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-137.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-135.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-132.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-131.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-129.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-128.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-126.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-125.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-124.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-122.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-121.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-118.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-116.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-110.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-109.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-106.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-105.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 95-108-213-102.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 87-250-224-96.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 87-250-224-95.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 87-250-224-91.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 87-250-224-88.spider.yandex.com anywhere reject-with icmp-port-unreachable
REJECT all -- 87-250-224-86.spider.yandex.com anywhere reject-with icmp-port-unreachable
Go away Yandex!