4 ms·
I personally have a access_by_lua script that counts accesses per ip and applies a (very generous) rate limit If the limit is reached the user will just be pre
by iMerNibor 11y ago
I personally have a access_by_lua script that counts accesses per ip and applies a (very generous) rate limit
If the limit is reached the user will just be presented with a page explaining you hit a rate limit and a button that runs some javascript to verify you're not a bot which in turn whitelists the user
This strategy has worked really well so far - havent been a target of too bad things yet though.
Its a very good and cheap way to go for smaller sites though
- jsmeaton 11y agoCan a bot dedicated to your site just ping back whatever the javascript would have done anyway to cancel the rate limit?
- iMerNibor 11y agoIt /could/, the next step would be a captcha or something harder for bots to solve - haven't had to go that far yet though. But I usually only have to deal with script kiddies who rent out a botnet, enter a url and click the "attack" button