4 ms·
Including all IPs I blocked today, they're spread between 5 different ASNs. I may resort to blocking them eventually, but for now - individually blocking the IP
by santah 6y ago
Including all IPs I blocked today, they're spread between 5 different ASNs. I may resort to blocking them eventually, but for now - individually blocking the IPs (even in the thousands as it is) - seems to be working well enough.
As for user agent - they're using a very common, real browser user agent that's impossible to distinct from legit users.
- Gys 6y agoDo you have many users in Russia? You could block the whole country ;-) Russia has no GDPR or something. So you could put (special key in) a cookie? They probably do not process it so subsequent requests without a cookie are to be discarded?
- lewiscollard 6y ago> Russia has no GDPR or something. So you could put (special key in) a cookie? It is entirely permissible under the GDPR to use cookies for security purposes.
- eythian 6y agoIf you can look closer at the HTTP requests, it may still be distinct. For example, the header order may not match any legitimate browser, or some other header doesn't make sense in the context of that UA.