Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. How to proctect instances from Bot, Crawlers, Requests, & Co?

How to proctect instances from Bot, Crawlers, Requests, & Co?

Scheduled Pinned Locked Moved Discuss
17 Posts 6 Posters 89 Views 6 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • timconsidineT timconsidine

    Interesting questions. I shall be watching hing for answers - wished I had them.

    P Offline
    P Offline
    p44
    translator
    wrote last edited by p44
    #3

    @timconsidine Great, I’m glad that I’m not alone. I also saw your posts in this discussion related to specific problem of DDOS attacks.

    I started to approach to this problem examining how VPS resources are “wasted” on daily bases when migrated from bare metal to VPS... In some peaks, I had a connection timeout on incoming 25 port, and then slowly I saw what was going on... most of accesses on that time they weren’t “human”...

    1 Reply Last reply
    1
    • fbartelsF Offline
      fbartelsF Offline
      fbartels
      App Dev
      wrote last edited by
      #4

      If the bots are compliant to it https://en.wikipedia.org/wiki/Robots.txt would be the tool you are looking for. This file can already be managed through the Cloudron UI.

      When it comes to preventing bad actors then https://docs.crowdsec.net/ could be worthwhile to look into.

      P 1 Reply Last reply
      2
      • fbartelsF fbartels

        If the bots are compliant to it https://en.wikipedia.org/wiki/Robots.txt would be the tool you are looking for. This file can already be managed through the Cloudron UI.

        When it comes to preventing bad actors then https://docs.crowdsec.net/ could be worthwhile to look into.

        P Offline
        P Offline
        p44
        translator
        wrote last edited by
        #5

        @fbartels Yes, Robots.txt, .htaccess, all good... but it could be great to manage rules in a central (and simple) way, special on Cloudron instances with multiple apps installed.

        It seems to be little bit complicated for my skills. I had a look on this post.

        Are you using Crowdsec?

        1 Reply Last reply
        0
        • jdaviescoatesJ Offline
          jdaviescoatesJ Offline
          jdaviescoates
          wrote last edited by
          #6

          I always install Wordfence on all my WordPress sites. Blocks most stuff.

          I use Cloudron with Gandi & Hetzner

          1 Reply Last reply
          3
          • J Offline
            J Offline
            joseph
            Staff
            wrote last edited by
            #7

            Is there a service out there that provides AI block lists? crowdsec only has a platinum list at 3500/month ?

            1 Reply Last reply
            1
            • P Offline
              P Offline
              p44
              translator
              wrote last edited by
              #8

              @jdaviescoates @joseph Thanks, I wouldn't want to rely on outside services.

              jdaviescoatesJ 1 Reply Last reply
              1
              • P p44

                @jdaviescoates @joseph Thanks, I wouldn't want to rely on outside services.

                jdaviescoatesJ Offline
                jdaviescoatesJ Offline
                jdaviescoates
                wrote last edited by
                #9

                @p44 TBH wrt WordPress i'd expect Wordfence would likely do a much better job that you'd ever be able to do manually. They have very long blocklists and know about many more bad IPs than you do. I just use the free version.

                I use Cloudron with Gandi & Hetzner

                1 Reply Last reply
                2
                • P Offline
                  P Offline
                  p44
                  translator
                  wrote last edited by
                  #10

                  @jdaviescoates Thanks, it seems that they don’t block AI bots...

                  1 Reply Last reply
                  2
                  • robiR Offline
                    robiR Offline
                    robi
                    wrote last edited by
                    #11

                    Can you extract the blocklists from Wordfence to have it populate the Cloudron deny list?

                    Conscious tech

                    1 Reply Last reply
                    2
                    • P Offline
                      P Offline
                      p44
                      translator
                      wrote last edited by
                      #12

                      @robi Thanks for advice.

                      I don’t know where and if Wordfence has a public list, but I think that blocklists has a lot of data that can be huge to handle from CPU.

                      robiR jdaviescoatesJ 2 Replies Last reply
                      0
                      • P p44

                        @robi Thanks for advice.

                        I don’t know where and if Wordfence has a public list, but I think that blocklists has a lot of data that can be huge to handle from CPU.

                        robiR Offline
                        robiR Offline
                        robi
                        wrote last edited by
                        #13

                        @p44 those are solved problems with lookup tables.

                        Conscious tech

                        P 1 Reply Last reply
                        1
                        • P p44

                          @robi Thanks for advice.

                          I don’t know where and if Wordfence has a public list, but I think that blocklists has a lot of data that can be huge to handle from CPU.

                          jdaviescoatesJ Offline
                          jdaviescoatesJ Offline
                          jdaviescoates
                          wrote last edited by
                          #14

                          @p44 I think Wordfence adds stuff to .htaccess

                          I use Cloudron with Gandi & Hetzner

                          1 Reply Last reply
                          0
                          • robiR robi

                            @p44 those are solved problems with lookup tables.

                            P Offline
                            P Offline
                            p44
                            translator
                            wrote last edited by p44
                            #15

                            @robi Thanks a lot.

                            I found and applied specific rules in Wordpress .htaccess:

                            • 8G Firewall
                            • Ultimate Block List to Stop AI Bots

                            I think is a good start.

                            Both filters it seems working fine. Of course, it would better to manage and deploy centrally.

                            Thanks again for your advices Robi.

                            robiR 1 Reply Last reply
                            2
                            • P p44

                              @robi Thanks a lot.

                              I found and applied specific rules in Wordpress .htaccess:

                              • 8G Firewall
                              • Ultimate Block List to Stop AI Bots

                              I think is a good start.

                              Both filters it seems working fine. Of course, it would better to manage and deploy centrally.

                              Thanks again for your advices Robi.

                              robiR Offline
                              robiR Offline
                              robi
                              wrote last edited by
                              #16

                              @p44 You are very welcome.

                              Now making a tool to parse those IPs for the Cloudron block list is something an eager LLM agent could do.

                              Conscious tech

                              P 1 Reply Last reply
                              1
                              • robiR robi

                                @p44 You are very welcome.

                                Now making a tool to parse those IPs for the Cloudron block list is something an eager LLM agent could do.

                                P Offline
                                P Offline
                                p44
                                translator
                                wrote last edited by p44
                                #17

                                @robi Amazing!!!

                                Something like a “bridge” that every day take from the source and update Cloudron block list...

                                1 Reply Last reply
                                0

                                Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                                Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                                With your input, this post could be even better 💗

                                Register Login
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Don't have an account? Register

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • Bookmarks
                                • Search