9 ms·
Same thing happened to me and my service (https://next-episode.net https://next-episode.net) almost 2 years ago. I wrote a HN post about it as well: https://ne
by santah 4y ago
Same thing happened to me and my service (https://next-episode.net https://next-episode.net) almost 2 years ago.
I wrote a HN post about it as well: https://news.ycombinator.com/item?id=26105890 https://news.ycombinator.com/item?id=26105890, but to spare you all the irrelevant details and digging in the comments for updates - here is what worked for me - you can block all their IPs, even though they may have A LOT and can change them on each call:
1) I prepared a fake URL that no legitimate user will ever visit (like website_proxying_mine.com/search?search=proxy_mirroring_hacker_tag)
2) I loaded that URL like 30 thousand times
3) from my logs, I extracted all IPs that searched for "proxy_mirroring_hacker_tag" (which, from memory, was something like 4 or 5k unique IPs)
4) I blocked all of them
After doing the above, the offending domains were showing errors for 2-3 days and then they switched to something else and left me alone.
I still go back and check them every few months or so ...
P.S. My advice is to remove their URL from your post here. This will not help with search engines picking up their domain and ranking it with your content ...
- deleted 4y ago[deleted]
- rexreed 4y agoFor 2) you mean you loaded it from the adversary's proxy site, just to clarify?
- deleted 4y ago[deleted]
- santah 4y agoYes, constructed the honeypot URL using the proxy site and called it (thousands of times) so I can get them to fetch it from my server through their IP so I can log it.
- WirelessGigabit 4y agoThey literally proxy your website? I thought they'd cache it... that makes more sense now in your statement that you hit their website with a specially formatted url. Since they pass that through to you you can filter on that. Also: since you say 4k-5k IPs... any of them from cloud providers? And specific location?
- santah 4y agoNo cloud providers as far as I'm aware. They were all from the same 4-5 ASN networks, all based in Russia.
- justsomehnguy 4y agoResidential proxy botnet.
- tofuahdude 4y agoWhy do they bother doing this domain proxy stuff in the first place?
- justsomehnguy 4y agoHigh quality content with a good standing in Google => unique and quality impressions => more revenue from the ads they insert in the content.
- _siis 4y agoThere is also the potential to use it as a watering hole for more sophisticated or subversive measures where they subtly change what you post to promote something you don't actually promote (so at some point they deviate from pure proxy to mitm).
- adventured 4y agoIf you happen to use Cloudflare.... Cloudflare -> Firewall rules -> Russia JS Challenge (or block)
- everybodyknows 4y agoAlso for (2), any worries that your own providers might imagine you're trying to mount some half-baked DOS campaign?
- santah 4y agoWasn't really worried about that. I didn't do it as a super quick burst, but in a space of multiple hours. First because the proxy servers were super slow and second - I couldn't automate it - their servers had some kind of bot detection which would catch me calling the URLs through script. Instead, I installed a browser extension which would automatically reload a browser tab after specified timeout (I've set it to 10 sec or something) and I opened like 50 tabs of the honeypot URL and left it there to reload for hours ...
- RektBoy 4y agoLook out as this is not optimal. Since they will fingerprint your browser. But it looks like they were people with low IQ, so you were fine.
- blinding-streak 4y agoSide note: great idea for a website. This could be really helpful. You got a new user here.
- mhlakhani 4y agoI have to agree, my SO has been looking for something like this for a long time. Signing up today!
- focusedone 4y agoWow, hadn't seen this before. Awesome site!
- santah 4y agoThanks!
- chris_wot 4y agoMakes me wonder if you could switch serving content based on the URLs. So they redirect back to your website. Or display images marked as copyrighted.
- santah 4y agoI tried but couldn't redirect back to my website as they stripped / rewrote all JS.
- t0suj4 4y agoWould it be possible to hide a hash/encoded URL somewhere in JS and delete the site/redirect if the hash/encoded URL contained something unexpected?
- rot13xor 4y agoYou could have a "stolen content" pure HTML/CSS banner that gets removed by Javascript. Only proxy site visitors will see the banner because the proxy deleted the Javascript.
- dorgo 4y agosome people like me will see the "stolen content" banner on the original website. And attackers can trivially remove it as soon as they get aware of it.
- bvinc 4y agoMight I suggest a spin on this: instead of blocking the IPs, consider serving up different content to those IPs. You could make a page that shames their domain name for stealing content. You could make a redirect page that redirects people to your website. Or you could make a page with absolutely disgusting content. I think it would discourage them from playing the cat and mouse game with you and fixing it by getting new IPs.
- nomel 4y ago> Or you could make a page with absolutely disgusting content. Not if you value the people who might move to the real domain.
- Mikealcl 4y agoYou could do this without effecting normal traffic depending on uniqueness of ip doing the scraping. Love the idea.
- swsieber 4y agoI think you missed the point - if people show up at $PROXY expect nice stuff but see junk, then they won't move over to $REAL and instead blame $REAL. E.g. you'd like some way to redirect people from $PROXY site to $REAL site, and disgusting content on $PROXY won't do that - it'll reflect poorly on $REAL
- nuccy 4y agoInstead of blocking by IP, just check SERVER_NAME/HTTP_SERVER variables in your backend/web server (or even in JavaScript of the page check window.location.hostname) and in case those include anything but original hostname, redirect to the original website (or serve different content with a warning to the visitor). If you have apache2/nginx this can be easily achieved by creating a default virtualhost (which is not your website), and additionally creating explicitly your website virtualhost. Then the default virtualhost can have a proper redirect while serving any other hostname. Those variables are populated by the browser, unless proxying server is rewring them, your web-server will be able to detect imposter and serve him/her with a redirect. If rewrites are indeed in place, then check in the frontend. Blocking by IP is the last option if nothing else works.
- michaelmior 4y agoAs the OP mentioned, JS is stripped and URLs are being written, so I doubt either of those approaches will work.
- nuccy 4y agoMaking js essential is not that hard, right? Just "display: none" on the root element, which is removed by js :) More sophisticated options can been found in other comments.
- nuccy 4y agoThe other kind of problem is if the website is not really proxied but rather dumped, patched and re-served. In such case the only option (if JavaScript frontend redirect doesn't work) is blocking by IP the dumping server. To identify IPs, as pointed in the root comment of this thread, you can create a one-pixel link to a dummy page, which dumping software would visit, but a human wouldn't. So you will see who visited that specific page and block those IPs for good.
- michaelmior 4y agoI would think you'd want to be careful about search engines with that approach. Assuming the OP wants their site indexed, you could end up unintentionally blocking crawlers.
- khiqxj 4y ago8chan like every forum ever has dumb moderators who dont know how to do their job / over extend their hand (and the moderation position of web forums seems to attract people with certain mental disorders that make them seek out perceived microinjustices which the definition thereof changes from day to day) there were a bunch of sites mirroring 8chan to steal content these were useful because they had both a simpler / lighter / better user interface (aside from images being missing), and posts / threads that were deleted would stay on the mirrors. being able to see deleted posts / threads was highly useful as the moderation on such sites tends to be utterly useless and the output of a random number generator. it was hilarious reading "zigforum" instead of "8chan" in all the posts as the mirror replaced certain words to thinly veil their operation. they even had a reply button that didnt seem to work or was just fake. tl;dr the web is broken and only is good when "abused" by proxy/mirrors
- marklit 4y agoAs soon as you have a few of their IPs, look them up on ipinfo.io/1.2.3.4 and you'll find they probably belong to a handful of hosting firms. You can get each firm's entire IP list on that page and add all of those CIDRs to your block list. Saves you needing to make 30K web requests. In most countries in the western world, there are 3-4 major ISPs and this is where 99% of your legit traffic comes from. Regular people don't browse the web proxying via hosting centres as Cloudflare will treat them with suspicion on all the websites they protect.
- reincoder 4y agoThe site seems to be hosted on OVH cloud. OP should report this to them. https://www.ovh.com/abuse/ https://www.ovh.com/abuse/ Found the hosting information from here: https://host.io/us.to https://host.io/us.to
- ElijahLynn 4y agoTHIS ^^
- KomoD 4y agoConsider reaching out to Afraid.org first, https://freedns.afraid.org/contact/ https://freedns.afraid.org/contact/ They are the ones providing the subdomain
- stanislavb 4y agoThanks for the advice. I will give a go to some of these. p.s. I can't remove the URL as the post is not editable anymore. I'm just waking up... in Australia.
- DoreenMichele 4y agoThe mod can though, if you email him at hn@ycombinator.com.
- NullPrefix 4y ago>4) I blocked all of them Don't block them. Show dicks instead
- otikik 4y agoOnce you have their IP addresses you can make them serve anything you want. Set your imagination free. For starters: copyright-infringing material.
- layer8 4y agoUnless you hold the necessary rights to the copyrighted material, that would make you a copyright infringer yourself.
- deleted 4y ago[deleted]