5 ms·
My tiny side project gets a lot of bot traffic. And just yesterday, I had a large spike from TOR including the IP range 185.220.101.0/24. I was also considering
by uallo 5y ago
My tiny side project gets a lot of bot traffic. And just yesterday, I had a large spike from TOR including the IP range 185.220.101.0/24. I was also considering blocking these IP addresses. As the project relies on third-party APIs which are rate-limited, the bots may cause larger loading times for real users.
I'd assume that Stack Exchange might also get lots of bot traffic from TOR.
- GentooInstaller 5y agoIt was never "TOR", it's; Tor: https://matt.traudt.xyz/posts/2021-02-22-tor-spelling https://matt.traudt.xyz/posts/2021-02-22-tor-spelling. The DNS checking service is rate limited and adds latency, but there is a bulk exit list available here; https://check.torproject.org/torbulkexitlist https://check.torproject.org/torbulkexitlist (please don't use 3rd party blocklists, as those often contain middles and guards, even though traffic cannot leave those kind of relays). But, before you block Tor, please consider that doing so will most likely block a number of legitimate users who you haven't noticed before - just to stop one jerk. Instead, you could restrict access to certain parts of your site for Tor visitors for example. Bot traffic from Tor is usually of the easily detectable variety (as the attacker didn't have enough skill to build/acquire a botnet and get "clean" IP's),
- bartvk 5y agoThank you for correcting the spelling.
- yanmaani 5y agoA middle-ground might be just putting some kind of CAPTCHA or similar on them, if they're causing actual trouble.
- wanderer_ 5y agoOr a regular old rate limiter - who's loading a new page more often than a couple of seconds anyway?
- goodpoint 5y agoIt's spelled Tor!