3 ms·
Yes, that's exactly what they are doing. How can I stop this?
by francescochi 2y ago
Yes, that's exactly what they are doing.
How can I stop this?
- mlhpdx 2y agoPut CORS in place and a strict CSP. Look the Host header in your API backend and block it. It might be forged, but probably not. Identify their host (reverse IP lookup) and block requests from that ASN. If they host in same place as you, complain and get them shut down (or move). The obfuscated JS based domain checking others suggested. None of these is perfect, but they don’t have to be. Just keep adding layers until they go away for good.
- gary_0 2y agoIf your site is only meant for human end users, you can get lists of datacenter IPs and use that to block them (assuming they are running in a datacenter that's on the list). That tends to block all sorts of abuse. If you are worried about blocking legit users with this method, you can show a CAPTCHA instead on every request from a suspect IP. At any rate, get their IP from your logs and run a whois on it to get their ISP and location. You could also try emailing the ISP's abuse contact or filing a DMCA complaint with their hosting provider, although of course that might not work.
- petercooper 2y agoOne naive approach would be to look at what IP address(es) they're using when proxying and blocking them. (Or detecting them in code and redirecting them to your domain, perhaps.)
- roosgit 2y agoI had a similar thing happen to one of my websites. In Varnish I used something like this: if (req.http.host ~ "^(?i)(example.com|www.example.com)") { #redirect to https } else { return(synth(403, "Not allowed.")); } It basically checks if the host is my domain. I don’t know know what the equivalent of `req.http.host` is on the web server you use. This "solution" might run into issues with Google Translate, but I’m not sure.
- pestatije 2y agoblock the ip of that log entry
- solardev 2y agoIn Next.js you can use middleware to sniff the domain and do something (block or redirect to your own): https://nextjs.org/docs/app/building-your-application/routing/middleware https://nextjs.org/docs/app/building-your-application/routin... On the frontend you can also use Javascript to do the same thing and just redirect their traffic to your own (or block them). Make sure to specify canonical tags etc too so Google doesn't think those duped domains are yours. If you have any API routes, make sure you set up CORS and CSPs and such to block requests from unauthorized domains. (Edit: You can probably also just throw Cloudflare in front of the whole setup: https://vercel.com/docs/integrations/external-platforms/cloudflare https://vercel.com/docs/integrations/external-platforms/clou...)
- nicbou 2y agoConfigure which domains your server accepts requests from. Only serve requests coming from the domain that's actually yours.