3 ms·
I wonder if you can have a chain of "invisible" links on your site that a normal person wouldn't see or click. The links can go page A -> page B -> page C, whe
by zdc1 11mo ago
I wonder if you can have a chain of "invisible" links on your site that a normal person wouldn't see or click.
The links can go page A -> page B -> page C, where a request for C = instant IP ban.
- chrisweekly 11mo agoIP addresses from scrapers are innumerable and in constant rotation.
- SkiFire13 11mo agoScrapers nowadays can use residential and mobile IPs, so banning by IP, even if actual malicious requests are coming from them, can also prevent actual unrelated people from accessing your service.
- SoftTalker 11mo agoUnless you're running a very popular service, unlikely that a random residential IP would be both compromised by a malicious VPN and also trying to access your site legitimately.
- arbol 11mo agoLots of people have chrome extensions installed that use their connection like proxy so this is more common than you think
- SoftTalker 11mo agoCan you provide any examples of these extensions? I'm not doubting you, just curious.
- arbol 11mo agoThere's one mentioned here: https://www.bleepingcomputer.com/news/security/data-stealing-chrome-extensions-impersonate-fortinet-youtube-vpns/ https://www.bleepingcomputer.com/news/security/data-stealing... Anyone who owns a chrome extension with 50k+ installs is regularly asked to sell it to people (myself included). The people who buy the extensions try to monetize them any way they can, like proxying traffic for malicious scrapers / attacks.
- snthd 11mo agoBright VPN https://en.wikipedia.org/wiki/Bright_Data https://en.wikipedia.org/wiki/Bright_Data
- esseph 11mo agoBotnets are massive these days. Also a lot of big companies are paying for residential "proxies" to scrape traffic from for AI.
- theoreticalmal 11mo agoHow can a scraper get a mobile IP address?
- arbol 11mo agoJust one of many offering this service https://brightdata.com/proxy-types/mobile-proxies https://brightdata.com/proxy-types/mobile-proxies
- Habgdnv 11mo agoI self host and I have something like this but more obvious: i wrote a web service that talks to my mikrotik via API and add the IP of the requester to the block list with a 30 day timeout (configurable ofc). It hostname is "bot-ban-me.myexamplesite.com" and it is like a normal site in my reverse proxy. So when I request a cert this hostname is in the cert, and in the first few minutes i can catch lots of bad apples. I do not expect anyone to ever type this. I do not mention the address or anything anywhere, so the only way to land there is to watch the CT logs.
- trescenzi 11mo agoThere was an article just yesterday which detailed doing this as not in order to ban but in order to waste time. You can also zip bomb people which is entertaining but probably not super effective. https://herman.bearblog.dev/messing-with-bots/ https://herman.bearblog.dev/messing-with-bots/ https://news.ycombinator.com/item?id=45935729 https://news.ycombinator.com/item?id=45935729
- wibbily 11mo agoI do something like this. Every page gets an invisible link to a honeypot. Click the link, 48hr ban. Honestly I have no idea how well it works, my logs are still full of bots. *Slow* bots, though. As long as they’re not ddosing me I guess it’s fine?
- SoftTalker 11mo agoWe do something similar for ssh. If a remote connection tries to log in as "root" or "admin" or any number of other usernames that indicate a probe for vulnerable configurations, that's an insta-ban for that IP address (banned not only for SSH but for everything).