3 ms·
Are the IPs from the same ARN block? Cloudflare should show you that in the Firewall events page. If they're using IPs from a single VPN/Server company then you
by aclelland 6y ago
Are the IPs from the same ARN block? Cloudflare should show you that in the Firewall events page. If they're using IPs from a single VPN/Server company then you might be able to just block the ASN.
You might also be able to find common user agent headers through the CF firewall page and block them based on their UA. That'd not work if their scraper tool was randomizing the UA string but quite a few of them don't
- santah 6y agoIncluding all IPs I blocked today, they're spread between 5 different ASNs. I may resort to blocking them eventually, but for now - individually blocking the IPs (even in the thousands as it is) - seems to be working well enough. As for user agent - they're using a very common, real browser user agent that's impossible to distinct from legit users.
- Gys 6y agoDo you have many users in Russia? You could block the whole country ;-) Russia has no GDPR or something. So you could put (special key in) a cookie? They probably do not process it so subsequent requests without a cookie are to be discarded?
- lewiscollard 6y ago> Russia has no GDPR or something. So you could put (special key in) a cookie? It is entirely permissible under the GDPR to use cookies for security purposes.
- eythian 6y agoIf you can look closer at the HTTP requests, it may still be distinct. For example, the header order may not match any legitimate browser, or some other header doesn't make sense in the context of that UA.