4 ms·
Unacceptable, sorry this is happening. Do you know about fail2ban? You can have it automatically filter IPs that violate certain rules. One rule could be match
by awsanswers 2y ago
Unacceptable, sorry this is happening. Do you know about fail2ban? You can have it automatically filter IPs that violate certain rules. One rule could be matching on the bot trying certain URLs. You might be able to get some kind of honeypot going with that idea. Good luck
- thayne 2y agoThey said that it is coming from different ip addresses every time, so fail2ban wouldn't help.
- keisborg 2y agoMonitor access logs for links that only crawlers can find. Edit: oh, I got your point now.
- jsheard 2y agoAmazon does publish every IP address range used by AWS, so there is the nuclear option of blocking them all pre-emptively. https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-rang...
- xena 2y agoI'd do that, but my DNS is via route 53. Blocking AWS would block my ability to manage DNS automatically as well as certificate issuance via DNS-01.
- unsnap_biceps 2y agoIf you only block new inbound requests, it shouldn't impact your route 53 or DNS-01 usage.
- actuallyalys 2y agoThey list a service for each address, so maybe you could block all the non-Route 53 IP addresses. Although that assumes they aren’t using the Route 53 IPs or unlisted IPs for scraping (the page warns it’s not a comprehensive list). Regardless, it sucks that you have to deal with this. The fact that you’re a customer makes it all the more absurd.
- SteveNuts 2y agoIt’ll most likely eventually help, as long as they don’t have an infinite address pool. Do these bots use some client software (browser plugin, desktop app) that’s consuming unsuspecting users bandwidth for distributed crawling?