5 ms·
I use 418 as a reply to illegitimate bots. It’s fun and it makes filtering logs easier. Nginx config snippet: # Nothing to hack around here, I’m just a teap
by palsecam 2y ago
I use 418 as a reply to illegitimate bots. It’s fun and it makes filtering logs easier.
Nginx config snippet:
# Nothing to hack around here, I’m just a teapot:
location ~* \.(?:php|aspx?|jsp|dll|sql|bak)$ {
return 418;
}
error_page 418 /418.html;
Example: https://FreeSolitaire.win/wp-login.php https://FreeSolitaire.win/wp-login.php
(NB: /wp-login.php is WordPress login URL, and it’s commonly blindly requested by bots searching for weak WordPress installs.)
- jbombadil 2y agoQuick side-note. Thank you for freesolitaire.win. It's such a beautiful implementation of solitaire. Works so well as a PWA, I can enjoy it even without proper internet connection, it's simple, does the basics, but does it perfectly. There's nothing to add to it, but more importantly... nothing to take out. I wish more software was written like this. I've donated already, but I use it so much I'll donate again.
- palsecam 2y agoWow, thanks jbombadil! That’s so heart-warming to hear <3 I’m speechless. I’m glad you like https://FreeSolitaire.win https://FreeSolitaire.win that much! Thank you again for your kind words (and donation!)
- DaveChurchill 2y agoAlso a +1 for the solitaire! One suggestion: how about an inverted mode where the piles grow up from the bottom? I think it would be much easier to control while playing on phone
- palsecam 2y agoOh that’s an interesting idea! Thanks Dave, had not think about that! Regarding playing on phone: one improvement I have in mind, is to have the stock (aka reserve) and waste piles be on the right side. That would make them easier to reach for right-handed players, I guess. What do you think? (The foundations piles would inversely go to the left. They are rarely manipulated, given that one can double-tap a card to automatically send it to its foundation pile.) Thank you again for the feedback, that’s always very appreciated!
- DaveChurchill 2y agoI think that in such a UI where it's trivial to mirror left and right just give an option and let the user decide their preference
- mixmastamyk 2y ago444 might be quicker, if less fun. https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#return https://nginx.org/en/docs/http/ngx_http_rewrite_module.html#... Wonder how to ban that address permanently just for asking for these urls?
- palsecam 2y ago444 is a (nginx-specific) idea too, indeed. Blocking at the edge (on the CDN) is another, and it would be even quicker ;-) (I use Cloudflare, a Cloudflare worker could be set to answer /wp-login.php or anything, without even reaching my own server.) Wrt. how to ban: an option would be something like fail2ban (https://en.wikipedia.org/wiki/Fail2ban https://en.wikipedia.org/wiki/Fail2ban)
- jmholla 2y ago> Blocking at the edge (on the CDN) is another, and it would be even quicker ;-) (I use Cloudflare, a Cloudflare worker could be set to answer /wp-login.php or anything, without even reaching my own server.) With HTTPS, blocking on the edge requires using a CDN that holds your secret keys. The only way they could block paths is being able to decrypt requests since the path is encrypted. If you trust Cloudflare or someone else to manage your secrets, this will work, but if you are terminating your HTTPS connections, you'll need to handle it with your own infrastructure as people above have.
- sangnoir 2y ago> Wonder how to ban that address permanently just for asking for these urls? fail2ban supports rules based on nginx logs (clients that triggers x 444 responses in y minutes (or y-times) gets banned for n minutes/hours/days)