How to Block Some of the Bots
51 points - today at 6:32 PM
SourceComments
CqtGLRGcukpy today at 8:28 PM
If you are unable to read this, there is an archived copy at https://archive.ph/d3236
fxtentacle today at 7:04 PM
I like the idea of adding a fake cpanel subdomain for 169.254.169.254 so that script kiddies will start port-scanning their own hosting provider, which will likely get them flagged/banned.
binaryturtle today at 6:51 PM
410 and a "Sec-Fetch-Mode:" string in the response body. I guess it thinks I'm a bot? Thanks!
Nothing to read, nothing to see, I move along. (Yikes, the modern web sucks!)
genodethrowaway today at 8:37 PM
and all valid traffic too, judging by these HN comments (and my own attempts to connect).
fatty_patty89 today at 8:50 PM
what's up with those response headers?
"adult" ...
"ai" ...
response length 68
RobotToaster today at 8:22 PM
Blocks firefox's built in VPN.
FabCH today at 8:39 PM
The post content is great. I personally hate the way Cloudfare has been the „default answer“ for the bot problem because Cloudfare has become the most successful MITM attack in history. We need content like this to keep the internet alive.
The added explanations by the author in this comment thread are hilarious. You sir are a good writer.
iririririr today at 7:25 PM
most (all?) of those will 100% block valid traffic too
ajsnigrutin today at 7:44 PM
There's a special place in hell for people who block curl and wget, especially on sites with downloadable files (eg source code tgz's, media, etc.), basically anything i might need to wget on a server.
Capricorn2481 today at 7:53 PM
Am I the only one that exclusively gets attacks with spoofed user agents and rotating TLS signatures? I feel like every post I see about not needing a CDN has tips that could be overcome in under an hour of scripting.
gorkemyildirim today at 8:46 PM
[dead]
receptopalak today at 8:15 PM
[flagged]