4 ms·
Think about how many webmaster and business owners' egos are stroked by all the traffic they are getting, when in actuality they are often just serving thousand
by drewnick 2mo ago
Think about how many webmaster and business owners' egos are stroked by all the traffic they are getting, when in actuality they are often just serving thousands of bots.
- andai 2mo agoI was insulted recently reading about the apparently thousands of hits per second the rest of you guys are getting. Even the bots are shunning me!
- 0xdeadbeefbabe 2mo agoI don't even have a domain name and I'm getting lots of hits.
- xplt 2mo agoOld and busted: serverless New hotness: DNS-less
- 0xdeadbeefbabe 2mo agoYeah it's even superior to smol web in some circles. It's not that much longer than a phone number.
- inigyou 2mo agoAh yes my phone number is 2602 1337 ABCD CAFE 3542 77FF FE12 3456 See? It's quite short.
- voidUpdate 2mo agoSome people still use ipv4
- jasonjayr 2mo agoI recently brought up a website on a never-before-seen .com domain. Within about 10 mins of bringing it up with a SSL certificate, Anthropic came knocking on the door requesting the front page. (Almost certainty due to them watching the Public Certificate Transparency logs)
- andai 2mo agoHow do you know who's visiting? Reverse IP lookups? Or do they announce it in the headers?
- jasonjayr 2mo agoI saw it via the User-agent header + confirmed via IP ownership lookup.
- dawnerd 2mo agoHad a bit setup a new Wordpress install before I could lock it down. I was very confused why a brand new install didn’t give me the setup page before seeing in the logs someone had automated it. Pure evil to be scraping new renewals and dns changes to look for this kinda stuff. For the record I thought I had this site behind basic auth.
- 01284a7e 2mo ago"Public Certificate Transparency logs"... The scam of "everyone should have SSL" right here, ladies and gentlemen.
- hamdingers 2mo agoGet a letsencrypt cert, I always get a massive wave of vulnerability probers after renewing.
- esseph 2mo agoBecause your certificate shows up in the global chain, which triggers all kinds of automated things including bots
- mmh0000 2mo agoIt's all TLS certs, because they show up in the Transparency Log[1] You can watch a live stream of it here: https://bencevans.io/security/certificate-stream https://bencevans.io/security/certificate-stream [1] https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency
- doubled112 2mo agoI use subdomains and a wildcard cert to partly obfuscate this.
- RulerOf 2mo agoI do the same, but I switched from cert-per-subdomain a couple of years ago. They're either using Passive DNS logs or a historical dataset.
- unethical_ban 2mo agoWhen I stood up some sites last year, I used codenames for the subdomains thinking I was obfuscating a little. I didn't know about the transparency logs until months later.
- martyvis 2mo agoTIL about Certificate Transparency (they didn't teach that in security school)
- bigbuppo 2mo ago
- whstl 2mo agoCould be because of number of pages you have. At work we have several million public content pages, so a few badly behaving bots can already do a lot of damage. For my personal website it’s 10x more bots but I barely notice because it’s a few pages.
- econ 2mo agoHumans never visit but I have some websites with ancient cms's. When I got bored playing with them I download the html, change the extensions to php and replace the site with a static copy. People then tirelessly try to hack it since they have laundry lists of known vulnerabilities. (Now that I think about it I regret not making the admin area public for added nostalgia.)
- ehnto 2mo agoNot that I follow my own advice, but a popped server can still be a liability for you. If you don't need it online I would take it down. Don't want to suddenly realise you've been an email spam node for several months.
- b112 2mo agoRe-read the post. He converted the sites to static html.
- unclebucknasty 2mo agoTo GP's point, any connected server can become a liability, even if it is intended to just host static HTML (or for some other purpose).
- fragmede 2mo agoI'm serving static sites via Cloudflare pages. Pretty sure that's gonna be actually static.
- unclebucknasty 2mo agoYou're running Cloudflare Pages on a home server?
- ehnto 2mo agoIt's fine, I am just being a nit, but static doesn't mean zero code. There is still a server and program turning a web request into a response. But in your case it's not your problem, it's cloudflare's. I only mentioned it in the assumption they had a VM or shared hosting, in which case it's worth thinking about.
- thenthenthen 2mo agoI never had this issue really… until two years ago, new website new host… boom, hugged to death by thousands of bots per second. This is on an alicloud vps.
- inigyou 2mo agoyeah someone told me he had a single static HTML homepage and used up his entire 10TB/month traffic limit from bots hitting it.
- ryukoposting 2mo agoI always had a decent bit of background noise, I think hosting on AWS comes with that. But after someone linked to me on hackaday the bot traffic went through the roof. One link to you from a noteworthy website, and all bets are off forever.
- outofpaper 2mo agoMaybe you just have fail2ban properly set up.
- lelanthran 2mo ago> I was insulted recently reading about the apparently thousands of hits per second the rest of you guys are getting. Even the bots are shunning me! You're running the wrong stack - I, myself, find that simply having a static file website is enough to cut down on the traffic. You need to run something other than static file serving to get bot attention.
- jareklupinski 2mo agoimagine having a KPI tied to cash bonuses based on that...
- zbentley 2mo ago2004 was a weird time.
- an0malous 2mo agoIs that basically the delta between Cloudflare’s Pages analytics and Google Analytics? CF says I get thousands of visits a day and GA says it’s like 3-4 users.
- gavinhking 2mo agoBasically, unless CF is counting static asset network requests etc. For what it's worth, GA also miscategorizes some bots as humans as well.
- Jskewel 2mo agoCloudflare analytics is great, but you need to filter by edge status code 200 to see the actual real traffic that was allowed through their firewall.
- ehnto 2mo agoYou pretty quickly learn to qualify incoming traffic since it directly impacts how you track conversions. But definitely to begin with, you see thousands of "people" view a page and no one bites, it can be disheartening until you realise it was mostly bots. I have basically 180d entirely on view metrics, they are more or less noise to a small business owner. Did someone buy or not, that's all you actually need to care about. Even big retail stores are pushing back on crap like KEPLAR/foot traffic tracking, since it doesn't actually change what you do, or impact sales. Measure sales, measure customer delight, make those the targets.
- chrsstrm 2mo agoWhat are you talking about? Are you saying 80% of my loyal visitors aren’t from Singapore? /s
- michaelbuckbee 2mo agoSince most analytics is done with JS (Google Analytics, etc.) very little of this shows up in site visit stats.