| ▲ | richwater 4 hours ago | ||||||||||||||||||||||
I would assume the fastest way to actually make this stop would be to setup a bunch of honeypot exploits, trigger their detection and someone will figure out what they did wrong. Other than not, with these huge companies you have 0 recourse. | |||||||||||||||||||||||
| ▲ | robotmay 4 hours ago | parent | next [-] | ||||||||||||||||||||||
I did something like this a few weeks ago on my photography site: https://robertmay.photography/journal/meta-has-tried-to-scra... Meta not only hasn't noticed, but is currently sending about 11 requests per second to my site. I've also seemingly trapped one of those TV proxy scraper nets as I'm getting absolutely hammered by requests from all over the place now. I get maybe 10 legit visitors per day, and I'm currently blocking 406,787 IPs from things that have fallen into my honeypot. I've tweaked my site to return empty status responses a configurable amount of time but the traffic has been so intense that Traefik is now struggling, so I'm going to have to figure out something else. I was returning over-capacity errors and I think that was a mistake, I've swapped to 400 range status codes now. I don't want to use Cloudflare so I'm not sure what to do after this. The people at these companies are either incompetent or malicious. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | slau 4 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
I actually think this is brilliant. Let the scanner IP get access to the most unpatched Wordpress, maybe even generate some garbage ERP numbers. Once the asset scanner detects the vulns, everyone will kick into high gear to patch this. | |||||||||||||||||||||||
| ▲ | numpad0 2 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
I wonder if source IP can be ping triangulated, then total ping count displayed as "Tesla MAU: +/-x% today", "Suspected ownership changes this month: xxx cars" by apparent home location changes, then residential and Tesla-unrelated locations excluded server side, and plotted on the map, then finally the whole system exposed to the public Internet and shared to SpaceX fans. "Hey Texas Model S #345 just left KXYZ, moving at >100mph towards the pad. Everyone get cameras out!" It'll be gone by lunchtime that day. | |||||||||||||||||||||||
| ▲ | robinpie 4 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
(OOP here). I wonder if switching my replies from 299 to 200 OK would be enough for some of them. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | Joel_Mckay 4 hours ago | parent | prev [-] | ||||||||||||||||||||||
Often, the folks you want to ban are not the hosts running the scans. One's best bet is to play possum, and use your clients last login IPs falling in your service area geo-IP ranges for a firewall white-list. Then redirect the other traffic for a black hole route. If the nuisance hosts assume they have driven the host offline, they will eventually give up and move on. =3 | |||||||||||||||||||||||