Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. WordPress (Managed)
  3. Blackhole for Bad Bots - proposing this as a default install

Blackhole for Bad Bots - proposing this as a default install

Scheduled Pinned Locked Moved WordPress (Managed)
19 Posts 5 Posters 2.3k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcusquinnM Offline
      marcusquinnM Offline
      marcusquinn
      wrote on last edited by
      #1
      • https://wordpress.org/plugins/blackhole-bad-bots/

      We find this very effective as a lightweight general protection compared to the heavier do-it-all alternatives.

      We do use the Pro version but I feel the free version would be good enough for most to save from instances becoming probed & spammed.

      Suggestion applies to Managed and Development versions.

      Web Design https://www.evergreen.je
      Development https://brandlight.org
      Life https://marcusquinn.com

      robiR 1 Reply Last reply
      2
      • marcusquinnM marcusquinn
        • https://wordpress.org/plugins/blackhole-bad-bots/

        We find this very effective as a lightweight general protection compared to the heavier do-it-all alternatives.

        We do use the Pro version but I feel the free version would be good enough for most to save from instances becoming probed & spammed.

        Suggestion applies to Managed and Development versions.

        robiR Offline
        robiR Offline
        robi
        wrote on last edited by
        #2

        @marcusquinn have not come across this one before, but I was expecting it to be a bit more than just block.

        It would be nice if it added a toggle for sending the bad bots into a tarpit which slows them way down with plenty of timeouts, slow responses and wastes their time and resources with endless crawl loops, etc... really black hole them.

        Conscious tech

        marcusquinnM 1 Reply Last reply
        0
        • robiR robi

          @marcusquinn have not come across this one before, but I was expecting it to be a bit more than just block.

          It would be nice if it added a toggle for sending the bad bots into a tarpit which slows them way down with plenty of timeouts, slow responses and wastes their time and resources with endless crawl loops, etc... really black hole them.

          marcusquinnM Offline
          marcusquinnM Offline
          marcusquinn
          wrote on last edited by
          #3

          @robi Brownhole for Bad Bots 😂

          Web Design https://www.evergreen.je
          Development https://brandlight.org
          Life https://marcusquinn.com

          1 Reply Last reply
          1
          • d19dotcaD Offline
            d19dotcaD Offline
            d19dotca
            wrote on last edited by
            #4

            Interesting plugin, hadn't seen that before. Looks promising and seems logical too in it's approach.

            @marcusquinn - In your experience using this plugin, has this been seen to reduce spam in forms by any chance? That's a problem I've been having lately on a few sites, not a big deal as I don't get too much but maybe a few a week use a form on a website that's just spam. Even using Google reCAPTCHA and honeypot form fields won't do the trick for some reason. When I checked Google reCAPTCHA it saw those as basically perfectly valid, so if I were to up the score limit it may start to have false positives which I don't want to risk for some of my clients.

            --
            Dustin Dauncey
            www.d19.ca

            robiR marcusquinnM jdaviescoatesJ 3 Replies Last reply
            0
            • d19dotcaD d19dotca

              Interesting plugin, hadn't seen that before. Looks promising and seems logical too in it's approach.

              @marcusquinn - In your experience using this plugin, has this been seen to reduce spam in forms by any chance? That's a problem I've been having lately on a few sites, not a big deal as I don't get too much but maybe a few a week use a form on a website that's just spam. Even using Google reCAPTCHA and honeypot form fields won't do the trick for some reason. When I checked Google reCAPTCHA it saw those as basically perfectly valid, so if I were to up the score limit it may start to have false positives which I don't want to risk for some of my clients.

              robiR Offline
              robiR Offline
              robi
              wrote on last edited by
              #5

              @d19dotca see if the source IPs have any correlation, ASN, network or country. Then use the blocking feature in Cloudron.

              Conscious tech

              d19dotcaD 1 Reply Last reply
              0
              • robiR robi

                @d19dotca see if the source IPs have any correlation, ASN, network or country. Then use the blocking feature in Cloudron.

                d19dotcaD Offline
                d19dotcaD Offline
                d19dotca
                wrote on last edited by
                #6

                @robi I was thinking about that, but the problem is a couple of my client websites are access from various countries around the world, so I can't really blanket block a country by CIDR rules or something, I'd be worried at that point of blocking people that shouldn't be blocked to visiting my client's website. He's a highly respected ENT surgeon so he has "fellows" and people join him for training for a year from all over the globe. It's crazy where everyone comes from to train with him, haha. Really cool to see, but makes it hard for me to block countries that we'd normally not care about for other sites for example. lol.

                --
                Dustin Dauncey
                www.d19.ca

                robiR 1 Reply Last reply
                0
                • d19dotcaD d19dotca

                  @robi I was thinking about that, but the problem is a couple of my client websites are access from various countries around the world, so I can't really blanket block a country by CIDR rules or something, I'd be worried at that point of blocking people that shouldn't be blocked to visiting my client's website. He's a highly respected ENT surgeon so he has "fellows" and people join him for training for a year from all over the globe. It's crazy where everyone comes from to train with him, haha. Really cool to see, but makes it hard for me to block countries that we'd normally not care about for other sites for example. lol.

                  robiR Offline
                  robiR Offline
                  robi
                  wrote on last edited by
                  #7

                  @d19dotca I hear you.. tough but still worth doing the correlation for other insights.

                  The other thing you can look into is post comment/form filtering. Perhaps add your own question to solve that is accepted either way, but later helps tell you if you're dealing with a bot or human.

                  From there there may be a few other things to try 😉

                  Conscious tech

                  d19dotcaD 1 Reply Last reply
                  0
                  • robiR robi

                    @d19dotca I hear you.. tough but still worth doing the correlation for other insights.

                    The other thing you can look into is post comment/form filtering. Perhaps add your own question to solve that is accepted either way, but later helps tell you if you're dealing with a bot or human.

                    From there there may be a few other things to try 😉

                    d19dotcaD Offline
                    d19dotcaD Offline
                    d19dotca
                    wrote on last edited by
                    #8

                    @robi Actually you lead me onto a great idea. I went and did some RBL checks on those IP addresses I see sending the forms, and sure enough most of the recent ones are in the Spamhaus XBL list. Now to see if I can somehow get that data into Cloudron as a large listing or something, may be a huge help in reducing spam / bots to the websites.

                    --
                    Dustin Dauncey
                    www.d19.ca

                    jimcavoliJ robiR 2 Replies Last reply
                    2
                    • d19dotcaD d19dotca

                      @robi Actually you lead me onto a great idea. I went and did some RBL checks on those IP addresses I see sending the forms, and sure enough most of the recent ones are in the Spamhaus XBL list. Now to see if I can somehow get that data into Cloudron as a large listing or something, may be a huge help in reducing spam / bots to the websites.

                      jimcavoliJ Offline
                      jimcavoliJ Offline
                      jimcavoli
                      App Dev
                      wrote on last edited by
                      #9

                      @d19dotca Now that's a good thought!

                      1 Reply Last reply
                      1
                      • d19dotcaD d19dotca

                        Interesting plugin, hadn't seen that before. Looks promising and seems logical too in it's approach.

                        @marcusquinn - In your experience using this plugin, has this been seen to reduce spam in forms by any chance? That's a problem I've been having lately on a few sites, not a big deal as I don't get too much but maybe a few a week use a form on a website that's just spam. Even using Google reCAPTCHA and honeypot form fields won't do the trick for some reason. When I checked Google reCAPTCHA it saw those as basically perfectly valid, so if I were to up the score limit it may start to have false positives which I don't want to risk for some of my clients.

                        marcusquinnM Offline
                        marcusquinnM Offline
                        marcusquinn
                        wrote on last edited by
                        #10

                        @d19dotca not had any spam issues TBH, so I think so. Like I say, we have the pro version but not harm in trying the free.

                        Web Design https://www.evergreen.je
                        Development https://brandlight.org
                        Life https://marcusquinn.com

                        1 Reply Last reply
                        0
                        • d19dotcaD d19dotca

                          @robi Actually you lead me onto a great idea. I went and did some RBL checks on those IP addresses I see sending the forms, and sure enough most of the recent ones are in the Spamhaus XBL list. Now to see if I can somehow get that data into Cloudron as a large listing or something, may be a huge help in reducing spam / bots to the websites.

                          robiR Offline
                          robiR Offline
                          robi
                          wrote on last edited by
                          #11

                          @d19dotca
                          Nice work, that's a great start - existing known spammers.

                          Now they just need to be in the right format list.

                          It would help to make a new thread with your findings and share the list.

                          Conscious tech

                          1 Reply Last reply
                          2
                          • d19dotcaD d19dotca

                            Interesting plugin, hadn't seen that before. Looks promising and seems logical too in it's approach.

                            @marcusquinn - In your experience using this plugin, has this been seen to reduce spam in forms by any chance? That's a problem I've been having lately on a few sites, not a big deal as I don't get too much but maybe a few a week use a form on a website that's just spam. Even using Google reCAPTCHA and honeypot form fields won't do the trick for some reason. When I checked Google reCAPTCHA it saw those as basically perfectly valid, so if I were to up the score limit it may start to have false positives which I don't want to risk for some of my clients.

                            jdaviescoatesJ Online
                            jdaviescoatesJ Online
                            jdaviescoates
                            wrote on last edited by
                            #12

                            @d19dotca I always install Wordfence which I really like. You could also try https://wordpress.org/plugins/goodbye-captcha/

                            The idea of bringing in spam IP lists sounds like a good plan too.

                            I use Cloudron with Gandi & Hetzner

                            robiR 1 Reply Last reply
                            2
                            • jdaviescoatesJ jdaviescoates

                              @d19dotca I always install Wordfence which I really like. You could also try https://wordpress.org/plugins/goodbye-captcha/

                              The idea of bringing in spam IP lists sounds like a good plan too.

                              robiR Offline
                              robiR Offline
                              robi
                              wrote on last edited by
                              #13

                              @jdaviescoates Looking at WP Bruiser I can't tell what it does.. there's a lot of marketing around it but it also seems like a lot of cloak and dagger.

                              It would be nice to know how it works.

                              Conscious tech

                              marcusquinnM jdaviescoatesJ 2 Replies Last reply
                              0
                              • robiR robi

                                @jdaviescoates Looking at WP Bruiser I can't tell what it does.. there's a lot of marketing around it but it also seems like a lot of cloak and dagger.

                                It would be nice to know how it works.

                                marcusquinnM Offline
                                marcusquinnM Offline
                                marcusquinn
                                wrote on last edited by
                                #14

                                @robi We use WP Bruiser with a bunch of add-on licences, generally we check everything for performance and code quality before committing to a choice, so it was a while back now but I don't recall any issues since.

                                Web Design https://www.evergreen.je
                                Development https://brandlight.org
                                Life https://marcusquinn.com

                                robiR 1 Reply Last reply
                                0
                                • marcusquinnM marcusquinn

                                  @robi We use WP Bruiser with a bunch of add-on licences, generally we check everything for performance and code quality before committing to a choice, so it was a while back now but I don't recall any issues since.

                                  robiR Offline
                                  robiR Offline
                                  robi
                                  wrote on last edited by
                                  #15

                                  @marcusquinn that's nice. do you know what it does to stop bots?

                                  Conscious tech

                                  marcusquinnM 1 Reply Last reply
                                  0
                                  • robiR robi

                                    @marcusquinn that's nice. do you know what it does to stop bots?

                                    marcusquinnM Offline
                                    marcusquinnM Offline
                                    marcusquinn
                                    wrote on last edited by
                                    #16

                                    @robi I know we don't have a bot problem 🙂

                                    Quick look at the reports on one website would suggest so:

                                    20014755-6e1f-470c-a921-e0744f0999de-image.png

                                    Web Design https://www.evergreen.je
                                    Development https://brandlight.org
                                    Life https://marcusquinn.com

                                    robiR 1 Reply Last reply
                                    0
                                    • marcusquinnM marcusquinn

                                      @robi I know we don't have a bot problem 🙂

                                      Quick look at the reports on one website would suggest so:

                                      20014755-6e1f-470c-a921-e0744f0999de-image.png

                                      robiR Offline
                                      robiR Offline
                                      robi
                                      wrote on last edited by
                                      #17

                                      @marcusquinn it's ok to say you don't know how it works too 😆

                                      Conscious tech

                                      marcusquinnM 1 Reply Last reply
                                      0
                                      • robiR robi

                                        @marcusquinn it's ok to say you don't know how it works too 😆

                                        marcusquinnM Offline
                                        marcusquinnM Offline
                                        marcusquinn
                                        wrote on last edited by
                                        #18

                                        @robi I truly don't care how it works. I care about how things work that no-one else has solved 🙂

                                        Web Design https://www.evergreen.je
                                        Development https://brandlight.org
                                        Life https://marcusquinn.com

                                        1 Reply Last reply
                                        0
                                        • robiR robi

                                          @jdaviescoates Looking at WP Bruiser I can't tell what it does.. there's a lot of marketing around it but it also seems like a lot of cloak and dagger.

                                          It would be nice to know how it works.

                                          jdaviescoatesJ Online
                                          jdaviescoatesJ Online
                                          jdaviescoates
                                          wrote on last edited by
                                          #19

                                          @robi I've no idea how it works either!

                                          I use Cloudron with Gandi & Hetzner

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                            • Login

                                            • Don't have an account? Register

                                            • Login or register to search.
                                            • First post
                                              Last post
                                            0
                                            • Categories
                                            • Recent
                                            • Tags
                                            • Popular
                                            • Bookmarks
                                            • Search