Blackhole for Bad Bots - proposing this as a default install
-
We find this very effective as a lightweight general protection compared to the heavier do-it-all alternatives.
We do use the Pro version but I feel the free version would be good enough for most to save from instances becoming probed & spammed.
Suggestion applies to Managed and Development versions.
-
@marcusquinn have not come across this one before, but I was expecting it to be a bit more than just block.
It would be nice if it added a toggle for sending the bad bots into a tarpit which slows them way down with plenty of timeouts, slow responses and wastes their time and resources with endless crawl loops, etc... really black hole them.
-
Interesting plugin, hadn't seen that before. Looks promising and seems logical too in it's approach.
@marcusquinn - In your experience using this plugin, has this been seen to reduce spam in forms by any chance? That's a problem I've been having lately on a few sites, not a big deal as I don't get too much but maybe a few a week use a form on a website that's just spam. Even using Google reCAPTCHA and honeypot form fields won't do the trick for some reason. When I checked Google reCAPTCHA it saw those as basically perfectly valid, so if I were to up the score limit it may start to have false positives which I don't want to risk for some of my clients.
-
@robi I was thinking about that, but the problem is a couple of my client websites are access from various countries around the world, so I can't really blanket block a country by CIDR rules or something, I'd be worried at that point of blocking people that shouldn't be blocked to visiting my client's website. He's a highly respected ENT surgeon so he has "fellows" and people join him for training for a year from all over the globe. It's crazy where everyone comes from to train with him, haha. Really cool to see, but makes it hard for me to block countries that we'd normally not care about for other sites for example. lol.
-
@d19dotca I hear you.. tough but still worth doing the correlation for other insights.
The other thing you can look into is post comment/form filtering. Perhaps add your own question to solve that is accepted either way, but later helps tell you if you're dealing with a bot or human.
From there there may be a few other things to try
-
@robi Actually you lead me onto a great idea. I went and did some RBL checks on those IP addresses I see sending the forms, and sure enough most of the recent ones are in the Spamhaus XBL list. Now to see if I can somehow get that data into Cloudron as a large listing or something, may be a huge help in reducing spam / bots to the websites.
-
@d19dotca I always install Wordfence which I really like. You could also try https://wordpress.org/plugins/goodbye-captcha/
The idea of bringing in spam IP lists sounds like a good plan too.
-
@jdaviescoates Looking at WP Bruiser I can't tell what it does.. there's a lot of marketing around it but it also seems like a lot of cloak and dagger.
It would be nice to know how it works.
-
@marcusquinn that's nice. do you know what it does to stop bots?
-
@marcusquinn it's ok to say you don't know how it works too