Top
Best
New

Posted by Bender 4 hours ago

How to Block Some of the Bots(nochan.net)
53 points | 38 commentspage 2
iririririr 3 hours ago|
most (all?) of those will 100% block valid traffic too
Bender 3 hours ago|
I would be interested in some examples of valid traffic that they would block. For the purposes of the document I do not consider anything from a data-center to be valid traffic. People can of course skip any or all steps, experiment with one at a time on a test server as they should.
ferngodfather 2 hours ago|||
> Obvious proxy is obvious.

> if ($http_x_forwarded_for) {....

This may block schools and libraries that use content blockers. Often the internal client is left to make abuse tracking easier (or because the overworked admin didn't know they could turn it off).

Bender 2 hours ago||
This may block schools and libraries

Oh, well that is ok for me I suppose. I add RTA/adult headers that hopefully they also look for and block using parental controls as adult content should not be viewed in a school or library. I could add a note suggesting to skip that step if one wishes schools and libraries that may be using a proxy to view.

ferngodfather 2 hours ago||
That's fair enough.

I think it's a great article to be fair. We need more of this cheap and quick bot blocking. The fact the solution to unwanted traffic is often "use Cloudflare" is _not_ great for the internet, and nobody really actually likes deploying or managing ModSecurity. Its a nice middleground.

ACCount37 2 hours ago|||
VPN exits often "come from datacenters". And there are entire countries where the web can be unusable without.

If you don't have LaLiga in your country, that doesn't mean everyone is so lucky. Blanket IP range bans, in this day and age? Basically a proclamation of incompetence.

ferngodfather 53 minutes ago|||
> Blanket IP range bans, in this day and age? Basically a proclamation of incompetence.

I disagree. If I'm getting problematic traffic from even a few of your IPs and they're in a DC/VPS range, I'm blocking it and moving on with my day.

But I suppose none of my clients services typically ever need to be accessible from such countries anyway.

Bender 2 hours ago|||
Basically a proclamation of incompetence.

I understand your frustration. Normally a blog site would not have any or many of these measures enabled. This is more of a test site to show what could be done on any other type of site. People can pick and choose which methods to use. Some may wish to block VPNs and proxies especially on forums.

I should make an article that shows additional ways to detect VPN's, including residential.

ajsnigrutin 2 hours ago||
There's a special place in hell for people who block curl and wget, especially on sites with downloadable files (eg source code tgz's, media, etc.), basically anything i might need to wget on a server.
BLKNSLVR 41 minutes ago||
There's this weird entitlement people have in which they think that the author of a site is not allowed to choose the method by which they protect their own site because it may be inconvenient to their specific, niche, use case.

Although @Bender's unique answer is better than my obvious observation.

Bender 2 hours ago||
A guy gets sent to hell. The demons guide him into the lobby. Satan jumps out and lets out a big evil roar to no effect. Satan then glances down and sees the spot on the mans finger where there was a ring. "Oh... well you've been through worse. The break room is down the hallway to the left, mail room is upstairs to the right..." Satan just walks away.

Every step is optional of course. There are ways to make curl work on my site but I choose to add friction as some botters abuse libcurl. I doubt anyone else will do what I do. They could spoof the user-agent but most botters seem to not know how to do that despite the myth that they all do.

For what it's worth if I had a site specific to sharing code artifacts or archives I would not block curl and I would also enable native rsyncd.

Capricorn2481 2 hours ago||
Am I the only one that exclusively gets attacks with spoofed user agents and rotating TLS signatures? I feel like every post I see about not needing a CDN has tips that could be overcome in under an hour of scripting.
receptopalak 2 hours ago||
[flagged]
gorkemyildirim 1 hour ago|
[dead]