Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

In specifications, Murphy's Law supersedes Ohm's.


tech / sci.electronics.design / Chinese downloads overloading my website

SubjectAuthor
* Chinese downloads overloading my websitelegg
+- Re: Chinese downloads overloading my websiteJohn R Walliker
+- Re: Chinese downloads overloading my websiteDon Y
+* Re: Chinese downloads overloading my websitelegg
|`* Re: Chinese downloads overloading my websiteJan Panteltje
| `* Re: Chinese downloads overloading my websitelegg
|  +* Re: Chinese downloads overloading my websiteJan Panteltje
|  |+* Re: Chinese downloads overloading my websiteLiz Tuddenham
|  ||`- Re: Chinese downloads overloading my websiteJeff Liebermann
|  |`* Re: Chinese downloads overloading my websitelegg
|  | +- Re: Chinese downloads overloading my websiteDon Y
|  | `* Re: Chinese downloads overloading my websiteJan Panteltje
|  |  +* Re: Chinese downloads overloading my websitejim whitby
|  |  |+- Re: Chinese downloads overloading my websiteDon Y
|  |  |`* Re: Chinese downloads overloading my websiteJan Panteltje
|  |  | `* Re: Chinese downloads overloading my websitelegg
|  |  |  `* Re: Chinese downloads overloading my websiteDon Y
|  |  |   `* Re: Chinese downloads overloading my websitelegg
|  |  |    +- Re: Chinese downloads overloading my websiteDon Y
|  |  |    `* Re: Chinese downloads overloading my websiteMartin Brown
|  |  |     `* Re: Chinese downloads overloading my websitelegg
|  |  |      `- Re: Chinese downloads overloading my websitePeter
|  |  `* Re: Chinese downloads overloading my websitelegg
|  |   `* Re: Chinese downloads overloading my websiteDon Y
|  |    `* Re: Chinese downloads overloading my websitelegg
|  |     `* Re: Chinese downloads overloading my websiteDon Y
|  |      `* Re: Chinese downloads overloading my websitePeter
|  |       `* Re: Chinese downloads overloading my websiteDon Y
|  |        +* Re: Chinese downloads overloading my websiteLiz Tuddenham
|  |        |+- Re: Chinese downloads overloading my websiteDon Y
|  |        |+* Re: Chinese downloads overloading my websitePeter
|  |        ||`* Re: Chinese downloads overloading my websiteLiz Tuddenham
|  |        || `- Re: Chinese downloads overloading my websitePeter
|  |        |`* Re: Chinese downloads overloading my websiteDon Y
|  |        | `* Re: Chinese downloads overloading my websiteLiz Tuddenham
|  |        |  +- Re: Chinese downloads overloading my websiteDon Y
|  |        |  `- Re: Chinese downloads overloading my websiteCarlos E.R.
|  |        `* Re: Chinese downloads overloading my websitePeter
|  |         +* Re: Chinese downloads overloading my websiteCarlos E.R.
|  |         |+* Re: Chinese downloads overloading my websiteDon Y
|  |         ||`* Re: Chinese downloads overloading my websitePeter
|  |         || `* Re: Chinese downloads overloading my websiteDon Y
|  |         ||  `* Re: Chinese downloads overloading my websitePeter
|  |         ||   `- Re: Chinese downloads overloading my websiteDon Y
|  |         |`* Re: Chinese downloads overloading my websitePeter
|  |         | +- Re: Chinese downloads overloading my websiteDon Y
|  |         | `* Re: Chinese downloads overloading my websiteCarlos E.R.
|  |         |  `- Re: Chinese downloads overloading my websiteDon Y
|  |         `- Re: Chinese downloads overloading my websiteDon Y
|  `- Re: Chinese downloads overloading my websiteJasen Betts
+* Re: Chinese downloads overloading my websiteMartin Brown
|`- Re: Chinese downloads overloading my websitelegg
`* Re: Chinese downloads overloading my websitelegg
 `* Re: Chinese downloads overloading my websitePeter
  `* Re: Chinese downloads overloading my websitelegg
   `* Re: Chinese downloads overloading my websitebitrex
    `* Re: Chinese downloads overloading my websiteDon Y
     `* Re: Chinese downloads overloading my websitebitrex
      `- Re: Chinese downloads overloading my websiteDon Y

Pages:123
Chinese downloads overloading my website

<7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135499&group=sci.electronics.design#135499

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Chinese downloads overloading my website
Date: Thu, 07 Mar 2024 12:49:30 -0500
Organization: A noiseless patient Spider
Lines: 18
Message-ID: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="73afa39374c22dae8b80bbe9174505c6";
logging-data="1246006"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+d3y8achwmkSL3rfgVjR1J"
Cancel-Lock: sha1:mBnL3RyuE8uIL+v9w/6LgT1xKO4=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Thu, 7 Mar 2024 17:49 UTC

Got a note from an ISP today indicating that my website
was suspended due to data transfer over-use for the month. (>50G)
It's only the 7th day of the month and this hadn't been a
problem in the 6 years they'd hosted the service.

Turns out that three chinese sources had downloaded the same
set of files, each 262 times. That would do it.

So, anyone else looking to update bipolar semiconductor,
packaging or spice parameter spreadsheets; look at K.A.Pullen's
'Conductance Design Curve Manual' or any of the other bits
stored at ve3ute.ca are out of luck, for the rest of the month .

Seems strange that the same three addresses downloaded the
same files, the same number of times. Is this a denial of
service attack?

RL

Re: Chinese downloads overloading my website

<usd4ta$13c4i$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135505&group=sci.electronics.design#135505

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: jrwalliker@gmail.com (John R Walliker)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Thu, 7 Mar 2024 19:35:46 +0000
Organization: A noiseless patient Spider
Lines: 27
Message-ID: <usd4ta$13c4i$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Thu, 7 Mar 2024 19:35:06 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="0bcb8fc9ba436a959544490a3193dcaa";
logging-data="1159314"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18digppA+koop8NxeXuxcWZpoVVD/pEWI0="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:9hbmWHI4au06psJrhH3pKiaZSzU=
Content-Language: en-GB
In-Reply-To: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
 by: John R Walliker - Thu, 7 Mar 2024 19:35 UTC

On 07/03/2024 17:49, legg wrote:
> Got a note from an ISP today indicating that my website
> was suspended due to data transfer over-use for the month. (>50G)
> It's only the 7th day of the month and this hadn't been a
> problem in the 6 years they'd hosted the service.
>
> Turns out that three chinese sources had downloaded the same
> set of files, each 262 times. That would do it.
>
> So, anyone else looking to update bipolar semiconductor,
> packaging or spice parameter spreadsheets; look at K.A.Pullen's
> 'Conductance Design Curve Manual' or any of the other bits
> stored at ve3ute.ca are out of luck, for the rest of the month .
>
> Seems strange that the same three addresses downloaded the
> same files, the same number of times. Is this a denial of
> service attack?
>
> RL

I have seen DNS servers in China poisoned in such a way that lookups
of sites that are deemed to be inappropriate are responded to with the
address of some random but genuine site. This happened to a company in
the UK and resulted in a huge amount of traffic.
Why such a DNS poisoning would lead to lots of downloads is less obvious.
John

Re: Chinese downloads overloading my website

<usd57n$17ag2$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135506&group=sci.electronics.design#135506

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: blockedofcourse@foo.invalid (Don Y)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Thu, 7 Mar 2024 12:40:32 -0700
Organization: A noiseless patient Spider
Lines: 32
Message-ID: <usd57n$17ag2$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Thu, 7 Mar 2024 19:40:40 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="413e233e00eb8789d7cf8b4b19b5637a";
logging-data="1288706"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19C2vCB1YuLYL5E0bNbRWoW"
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.2.2
Cancel-Lock: sha1:aYX/Wo2xNEx6DBYFcit57zXA6Kw=
Content-Language: en-US
In-Reply-To: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
 by: Don Y - Thu, 7 Mar 2024 19:40 UTC

On 3/7/2024 10:49 AM, legg wrote:
> Got a note from an ISP today indicating that my website
> was suspended due to data transfer over-use for the month. (>50G)
> It's only the 7th day of the month and this hadn't been a
> problem in the 6 years they'd hosted the service.
>
> Turns out that three chinese sources had downloaded the same
> set of files, each 262 times. That would do it.
>
> So, anyone else looking to update bipolar semiconductor,
> packaging or spice parameter spreadsheets; look at K.A.Pullen's
> 'Conductance Design Curve Manual' or any of the other bits
> stored at ve3ute.ca are out of luck, for the rest of the month .
>
> Seems strange that the same three addresses downloaded the
> same files, the same number of times. Is this a denial of
> service attack?

Of sorts.

You might look at the *times* to see if it looks "mechanical"
or "human initiated".

You could change your "service" to one that delivers *requested*
content; email driven so you can insert your own metering function
in that loop. Or, a combination of the two -- hide the content
and return a one-time, unique, time-limited URL as the result of
an *approved* email request...

[Or, you can *hide* your site and only make it available by
invitation]

Re: Chinese downloads overloading my website

<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135516&group=sci.electronics.design#135516

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Thu, 07 Mar 2024 17:12:27 -0500
Organization: A noiseless patient Spider
Lines: 14
Message-ID: <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="73afa39374c22dae8b80bbe9174505c6";
logging-data="1351722"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/26SudMxJAwnbRR3DNvsTp"
Cancel-Lock: sha1:t2itE1aUbrc0t2rPOn/4xFEUDjk=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Thu, 7 Mar 2024 22:12 UTC

A quick response from the ISP says they're blocking
the three hosts and 'monitoring the situatio'.

All the downloading was occuring between certain
hours of the day in sequence - first one host
between 11 and 12pm. one days rest, then the
second host at the same timeon the third day,
then the third host on the fourth day.

Same files 262 times each, 17Gb each.

Not normal web activity, as I know it.

RL

Re: Chinese downloads overloading my website

<usec35$130bu$1@solani.org>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135525&group=sci.electronics.design#135525

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!reader5.news.weretis.net!news.solani.org!.POSTED!not-for-mail
From: alien@comet.invalid (Jan Panteltje)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Fri, 08 Mar 2024 06:43:49 GMT
Message-ID: <usec35$130bu$1@solani.org>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; ISO-8859-15
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 8 Mar 2024 06:43:49 -0000 (UTC)
Injection-Info: solani.org;
logging-data="1147262"; mail-complaints-to="abuse@news.solani.org"
User-Agent: NewsFleX-1.5.7.5 (Linux-5.15.32-v7l+)
Cancel-Lock: sha1:ByMp00C2FXbrL5WywCEORdlzxbE=
X-User-ID: eJwFwYEBwDAEBMCVCI+ME/T3H6F3sNCY9EA4CNaKP+SI4aC6fFNYkfrw7Yl7McYWWVFyrCYk0TMN863DHzpaFTU=
X-Newsreader-location: NewsFleX-1.5.7.5 (c) 'LIGHTSPEED' off line news reader for the Linux platform
NewsFleX homepage: http://www.panteltje.nl/panteltje/newsflex/ and ftp download ftp://sunsite.unc.edu/pub/linux/system/news/readers/
 by: Jan Panteltje - Fri, 8 Mar 2024 06:43 UTC

On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
<legg@nospam.magma.ca> wrote in <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:

>A quick response from the ISP says they're blocking
>the three hosts and 'monitoring the situatio'.
>
>All the downloading was occuring between certain
>hours of the day in sequence - first one host
>between 11 and 12pm. one days rest, then the
>second host at the same timeon the third day,
>then the third host on the fourth day.
>
>Same files 262 times each, 17Gb each.
>
>Not normal web activity, as I know it.
>
>RL

Many sites have a 'I m not a bot' sort of thing you have to go through to get access.

Re: Chinese downloads overloading my website

<uses31$1lgmu$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135542&group=sci.electronics.design#135542

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: '''newspam'''@nonad.co.uk (Martin Brown)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Fri, 8 Mar 2024 11:16:46 +0000
Organization: A noiseless patient Spider
Lines: 38
Message-ID: <uses31$1lgmu$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 8 Mar 2024 11:16:49 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="06dc33d9712cecf3b7fb9cfeb18e1cac";
logging-data="1753822"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/JT+lly2xhqyzXstML1WsLW1hjzWSJFcoig8j24JCHCQ=="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:GMQM34rSaXCvld3I2EyP4IcJJgg=
In-Reply-To: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
Content-Language: en-GB
 by: Martin Brown - Fri, 8 Mar 2024 11:16 UTC

On 07/03/2024 17:49, legg wrote:
> Got a note from an ISP today indicating that my website
> was suspended due to data transfer over-use for the month. (>50G)
> It's only the 7th day of the month and this hadn't been a
> problem in the 6 years they'd hosted the service.
>
> Turns out that three chinese sources had downloaded the same
> set of files, each 262 times. That would do it.

Much as I *hate* Captcha this is the sort of DOS attack that it helps to
prevent. The other option is to add a script to tarpit or block
completely second or third requests for the same large files coming from
the same IP address occurring within the hour.

> So, anyone else looking to update bipolar semiconductor,
> packaging or spice parameter spreadsheets; look at K.A.Pullen's
> 'Conductance Design Curve Manual' or any of the other bits
> stored at ve3ute.ca are out of luck, for the rest of the month .
>
> Seems strange that the same three addresses downloaded the
> same files, the same number of times. Is this a denial of
> service attack?

Quite likely. Your ISP should be able to help you with this if they are
any good. Most have at least some defences against ridiculous numbers of
downloads or other traffic coming from the same bad actor source.

Provided that you don't have too many customers in mainland china
blacklist the main zones of their IP address range:

https://lite.ip2location.com/china-ip-address-ranges?lang=en_US

One rogue hammering your site is just run of the mill bad luck but three
of them doing it in quick succession looks very suspicious to me.

--
Martin Brown

Re: Chinese downloads overloading my website

<ethmuihnmn74laqg6pl3lfk95h97h7vvlo@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135561&group=sci.electronics.design#135561

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Fri, 08 Mar 2024 12:17:32 -0500
Organization: A noiseless patient Spider
Lines: 43
Message-ID: <ethmuihnmn74laqg6pl3lfk95h97h7vvlo@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <uses31$1lgmu$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="6ba6617a928ac72d4755a4ded000bf3e";
logging-data="1922823"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX187sccQCA5z/xoUZaKZ6MaN"
Cancel-Lock: sha1:uulyaOPOa3ZPQpZYG+HfBUYreWc=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Fri, 8 Mar 2024 17:17 UTC

On Fri, 8 Mar 2024 11:16:46 +0000, Martin Brown
<'''newspam'''@nonad.co.uk> wrote:

>On 07/03/2024 17:49, legg wrote:
>> Got a note from an ISP today indicating that my website
>> was suspended due to data transfer over-use for the month. (>50G)
>> It's only the 7th day of the month and this hadn't been a
>> problem in the 6 years they'd hosted the service.
>>
>> Turns out that three chinese sources had downloaded the same
>> set of files, each 262 times. That would do it.
>
>Much as I *hate* Captcha this is the sort of DOS attack that it helps to
>prevent. The other option is to add a script to tarpit or block
>completely second or third requests for the same large files coming from
>the same IP address occurring within the hour.
>
>> So, anyone else looking to update bipolar semiconductor,
>> packaging or spice parameter spreadsheets; look at K.A.Pullen's
>> 'Conductance Design Curve Manual' or any of the other bits
>> stored at ve3ute.ca are out of luck, for the rest of the month .
>>
>> Seems strange that the same three addresses downloaded the
>> same files, the same number of times. Is this a denial of
>> service attack?
>
>Quite likely. Your ISP should be able to help you with this if they are
>any good. Most have at least some defences against ridiculous numbers of
>downloads or other traffic coming from the same bad actor source.
>
>Provided that you don't have too many customers in mainland china
>blacklist the main zones of their IP address range:
>
>https://lite.ip2location.com/china-ip-address-ranges?lang=en_US
>
>One rogue hammering your site is just run of the mill bad luck but three
>of them doing it in quick succession looks very suspicious to me.

Beijin, Harbin and roaming.

Yeah. You gotta ask yourself; what's the friggin' point?

RL

Re: Chinese downloads overloading my website

<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135608&group=sci.electronics.design#135608

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Sat, 09 Mar 2024 20:59:19 -0500
Organization: A noiseless patient Spider
Lines: 54
Message-ID: <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="6b3a8df777a17fe1b6174ba9839775e0";
logging-data="2765503"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19brDJmzKMIZBpCtqYDtcM5"
Cancel-Lock: sha1:ViVOTblBZfGYrZlCkl1JcpCFylo=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Sun, 10 Mar 2024 01:59 UTC

On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
wrote:

>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
><legg@nospam.magma.ca> wrote in <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
>
>>A quick response from the ISP says they're blocking
>>the three hosts and 'monitoring the situatio'.
>>
>>All the downloading was occuring between certain
>>hours of the day in sequence - first one host
>>between 11 and 12pm. one days rest, then the
>>second host at the same timeon the third day,
>>then the third host on the fourth day.
>>
>>Same files 262 times each, 17Gb each.
>>
>>Not normal web activity, as I know it.
>>
>>RL
>
>Many sites have a 'I m not a bot' sort of thing you have to go through to get access.

Any idea what's involved - preferably anything that doesn't
owe to Google?

ISP bumped up limit for this month as courtesy, after blocking the
first three hosts, but a fourth host just gobbled that up.

3rd March
1.82.160.27
Chinanet Shaanxi, China telecom #56 Gaoxin St Beijing 100032

5th March
183.197.52.166
China Mobile Communications

6th March
42.184.167.97
Chinanet Heilongjiang, Heilongjiang Telecom,#178 Zhongshan Rd Haerbin
150040

8th March
106.46.35.206
Chinanet Henan, Henan Telecom

I'd like to limit traffic data volume by any host to <500M,
or <50M in 24hrs. It's all ftp.

Have access to Pldesk, but am unfamiliar with capabilities
and clued out how to do much of anything save file transfer.

RL

Re: Chinese downloads overloading my website

<usjiog$15kaq$1@solani.org>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135612&group=sci.electronics.design#135612

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!reader5.news.weretis.net!news.solani.org!.POSTED!not-for-mail
From: alien@comet.invalid (Jan Panteltje)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Sun, 10 Mar 2024 06:08:15 GMT
Message-ID: <usjiog$15kaq$1@solani.org>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; ISO-8859-15
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 10 Mar 2024 06:08:16 -0000 (UTC)
Injection-Info: solani.org;
logging-data="1233242"; mail-complaints-to="abuse@news.solani.org"
User-Agent: NewsFleX-1.5.7.5 (Linux-5.15.32-v7l+)
Cancel-Lock: sha1:G9/CiEtpUvRJl6F4LmbrixsrPGk=
X-User-ID: eJwNyscBwDAIBLCVIBQf42DK/iPEesvE2euom6utLVuCQNl6cXqCV+WzmlKZfReXwQ37iJHdoVs0oRUuidd+SbkVmA==
X-Newsreader-location: NewsFleX-1.5.7.5 (c) 'LIGHTSPEED' off line news reader for the Linux platform
NewsFleX homepage: http://www.panteltje.nl/panteltje/newsflex/ and ftp download ftp://sunsite.unc.edu/pub/linux/system/news/readers/
 by: Jan Panteltje - Sun, 10 Mar 2024 06:08 UTC

On a sunny day (Sat, 09 Mar 2024 20:59:19 -0500) it happened legg
<legg@nospam.magma.ca> wrote in <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>:

>On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
>wrote:
>
>>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
>><legg@nospam.magma.ca> wrote in <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
>>
>>>A quick response from the ISP says they're blocking
>>>the three hosts and 'monitoring the situatio'.
>>>
>>>All the downloading was occuring between certain
>>>hours of the day in sequence - first one host
>>>between 11 and 12pm. one days rest, then the
>>>second host at the same timeon the third day,
>>>then the third host on the fourth day.
>>>
>>>Same files 262 times each, 17Gb each.
>>>
>>>Not normal web activity, as I know it.
>>>
>>>RL
>>
>>Many sites have a 'I m not a bot' sort of thing you have to go through to get access.
>
>
>Any idea what's involved - preferably anything that doesn't
>owe to Google?
>...
>I'd like to limit traffic data volume by any host to <500M,
>or <50M in 24hrs. It's all ftp.

I no longer run an ftp server (for many years now),
the old one here needed a password.
Some parts of my website used to be password protected.
When I ask google for "how to add a captcha to your website"
I see many solutions, for example this:
https://www.oodlestechnologies.com/blogs/create-a-captcha-validation-in-html-and-javascript/

Maybe some html guru here nows?

Re: Chinese downloads overloading my website

<1qq74yl.1uw3jajjjmt2eN%liz@poppyrecords.invalid.invalid>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135615&group=sci.electronics.design#135615

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!paganini.bofh.team!2.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: liz@poppyrecords.invalid.invalid (Liz Tuddenham)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Sun, 10 Mar 2024 09:28:12 +0000
Organization: Poppy Records
Lines: 75
Message-ID: <1qq74yl.1uw3jajjjmt2eN%liz@poppyrecords.invalid.invalid>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
X-Trace: individual.net x2w0UBQ0uwzyNmnptQt0lQz2bH6yIg6UALoD+ZmUaTDGKqy5ZS
X-Orig-Path: liz
Cancel-Lock: sha1:N4yHM8WEBKCu6kY7LPet4UqEg08= sha256:eOmFiSnAHY6YnCW5mgTyV3IyPTq3H4rNRmieY3gJT3s=
User-Agent: MacSOUP/2.4.6
 by: Liz Tuddenham - Sun, 10 Mar 2024 09:28 UTC

Jan Panteltje <alien@comet.invalid> wrote:

> On a sunny day (Sat, 09 Mar 2024 20:59:19 -0500) it happened legg
> <legg@nospam.magma.ca> wrote in <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>:
>
> >On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
> >wrote:
> >
> >>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
> >><legg@nospam.magma.ca> wrote in
> >><6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
> >>
> >>>A quick response from the ISP says they're blocking
> >>>the three hosts and 'monitoring the situatio'.
> >>>
> >>>All the downloading was occuring between certain
> >>>hours of the day in sequence - first one host
> >>>between 11 and 12pm. one days rest, then the
> >>>second host at the same timeon the third day,
> >>>then the third host on the fourth day.
> >>>
> >>>Same files 262 times each, 17Gb each.
> >>>
> >>>Not normal web activity, as I know it.
> >>>
> >>>RL
> >>
> >>Many sites have a 'I m not a bot' sort of thing you have to go through
> >to get access.
> >
> >
> >Any idea what's involved - preferably anything that doesn't
> >owe to Google?
> >...
> >I'd like to limit traffic data volume by any host to <500M,
> >or <50M in 24hrs. It's all ftp.
>
> I no longer run an ftp server (for many years now),
> the old one here needed a password.
> Some parts of my website used to be password protected.
> When I ask google for "how to add a captcha to your website"
> I see many solutions, for example this:
>
> https://www.oodlestechnologies.com/blogs/create-a-captcha-validation-in-ht
> ml-and-javascript/
>
> Maybe some html guru here nows?

If you can password-protect the pages, why not do that but include the
password in the text so that any human can see it and copy it? i.e.

~~~~~~~~
To prove you are human you must type in the password, the password is
ABC
Password: ___

~~~~~~~~

I don't think there is an easy way of writing anything automatic in the
HTML Body text but you might be able to add a script to the Head that
checks the IP address and blocks the ones you don't want.

If you can write PHP, you could easily write your own version of Captcha
or write a script that limits the number of repeat visits from the same
IP address in a given time. Mixing PHP into HTML pages is easy but you
have to change the file extension of each page from .htm to .php

Servers generally have facilities for PHP already built-in and the W3
Schools tutorials can get you started.

--
~ Liz Tuddenham ~
(Remove the ".invalid"s and add ".co.uk" to reply)
www.poppyrecords.co.uk

Re: Chinese downloads overloading my website

<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135627&group=sci.electronics.design#135627

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Sun, 10 Mar 2024 13:47:48 -0400
Organization: A noiseless patient Spider
Lines: 77
Message-ID: <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="6b3a8df777a17fe1b6174ba9839775e0";
logging-data="3250460"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19ne2qnvsqYeOrS0gLHFH73"
Cancel-Lock: sha1:hVQEJifbEM4EL4Lbfaou0aI9x/c=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Sun, 10 Mar 2024 17:47 UTC

On Sun, 10 Mar 2024 06:08:15 GMT, Jan Panteltje <alien@comet.invalid>
wrote:

>On a sunny day (Sat, 09 Mar 2024 20:59:19 -0500) it happened legg
><legg@nospam.magma.ca> wrote in <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>:
>
>>On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
>>wrote:
>>
>>>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
>>><legg@nospam.magma.ca> wrote in <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
>>>
>>>>A quick response from the ISP says they're blocking
>>>>the three hosts and 'monitoring the situatio'.
>>>>
>>>>All the downloading was occuring between certain
>>>>hours of the day in sequence - first one host
>>>>between 11 and 12pm. one days rest, then the
>>>>second host at the same timeon the third day,
>>>>then the third host on the fourth day.
>>>>
>>>>Same files 262 times each, 17Gb each.
>>>>
>>>>Not normal web activity, as I know it.
>>>>
>>>>RL
>>>
>>>Many sites have a 'I m not a bot' sort of thing you have to go through to get access.
>>
>>
>>Any idea what's involved - preferably anything that doesn't
>>owe to Google?
>>...
>>I'd like to limit traffic data volume by any host to <500M,
>>or <50M in 24hrs. It's all ftp.
>
>I no longer run an ftp server (for many years now),
>the old one here needed a password.
>Some parts of my website used to be password protected.
>When I ask google for "how to add a captcha to your website"
>I see many solutions, for example this:
> https://www.oodlestechnologies.com/blogs/create-a-captcha-validation-in-html-and-javascript/
>
>Maybe some html guru here nows?

That looks like it's good for accessing an html page.
So far the chinese are accessing the top level index, where
files are offered for download at a click.

Ideally, if they can't access the top level, a direct address
access to the files might be prevented?

The website's down after a fifth excursion pushed volumes above
85g on a 70G temporary extension. What's the bet it was 17G
accumulated in 262 'visits'.

Can't ID that final hosts IP address while I'm locked out.

Luckily (~) for users, you can still access most of the usefull
files, updated in January 2024, through the Wayback Machine.

https://web.archive.org/web/20240000000000*/http://www.ve3ute.ca/

Probably the best place for it, in some people's opinion, anyways.

YOU can make stuff available to others, in the future, by 'suggesting'
relevent site addresses to the Internet Archive, if they're not
already being covered.

Once a 'captcha' or other security device is added, you can kiss
Wayback updates goodbye, as most bots will get the message.
I don't mind bots - thay can do good work.

Pity you can't just put stuff up in the public domain without
this kind of bullshit.

RL

Re: Chinese downloads overloading my website

<9t1suip96trhffebg6ikvig9ksd2anpodg@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135629&group=sci.electronics.design#135629

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: jeffl@cruzio.com (Jeff Liebermann)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Sun, 10 Mar 2024 12:29:43 -0700
Lines: 28
Message-ID: <9t1suip96trhffebg6ikvig9ksd2anpodg@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org> <1qq74yl.1uw3jajjjmt2eN%liz@poppyrecords.invalid.invalid>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
X-Trace: individual.net XEffrOr1NQMVVgJvTkvd8wvHjxD/iZm7PUDrkqMohXXdH8hjm0
Cancel-Lock: sha1:MmHD1jT9Rzp1gF9xnnWFHhs+6qw= sha256:07DC7eEdKhSsMRsb0sxxNYKE0W6mzKWN6pVRTy2a8S8=
User-Agent: ForteAgent/8.00.32.1272
 by: Jeff Liebermann - Sun, 10 Mar 2024 19:29 UTC

On Sun, 10 Mar 2024 09:28:12 +0000, liz@poppyrecords.invalid.invalid
(Liz Tuddenham) wrote:

>If you can password-protect the pages, why not do that but include the
>password in the text so that any human can see it and copy it? i.e.
>
>~~~~~~~~
>To prove you are human you must type in the password, the password is
>ABC
>Password: ___
>
>~~~~~~~~

That doesn't work if humans are doing the work in human Captcha
solving services:

"I Was a Human CAPTCHA Solver"
<https://www.f5.com/labs/articles/cisotociso/i-was-a-human-captcha-solver>

More of the same:
<https://www.google.com/search?q=captcha+solving+services>

--
Jeff Liebermann jeffl@cruzio.com
PO Box 272 http://www.LearnByDestroying.com
Ben Lomond CA 95005-0272
Skype: JeffLiebermann AE6KS 831-336-2558

Re: Chinese downloads overloading my website

<usl6bn$35gfh$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135631&group=sci.electronics.design#135631

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: blockedofcourse@foo.invalid (Don Y)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Sun, 10 Mar 2024 13:48:54 -0700
Organization: A noiseless patient Spider
Lines: 68
Message-ID: <usl6bn$35gfh$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Sun, 10 Mar 2024 20:48:55 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="7291c033c852c6280a1642118965cfc1";
logging-data="3326449"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18F3b9rjJuaOJoI8iaFC9Qr"
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.2.2
Cancel-Lock: sha1:/5aK1s1Gatp6nQjvPQdzaH1mDQ0=
In-Reply-To: <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>
Content-Language: en-US
 by: Don Y - Sun, 10 Mar 2024 20:48 UTC

On 3/10/2024 10:47 AM, legg wrote:
> So far the chinese are accessing the top level index, where
> files are offered for download at a click.
>
> Ideally, if they can't access the top level, a direct address
> access to the files might be prevented?

Many file sharing services deliberately do NOT offer access
to a "folder index" for similar reasons. This allows the
owner of the file(s) to publish specific links to individual files
while keeping the folder, itself, hidden.

This is done by creating unique URLs for each file.
I.e., instead of ..../foldername/filename you publish
..../foldername/pseudorandomappearingstring/filename
where "foldername" is some bogus sequence of characters
and pseudorandomappearingstring varies from file to file!

> The website's down after a fifth excursion pushed volumes above
> 85g on a 70G temporary extension. What's the bet it was 17G
> accumulated in 262 'visits'.
>
> Can't ID that final hosts IP address while I'm locked out.
>
> Luckily (~) for users, you can still access most of the usefull
> files, updated in January 2024, through the Wayback Machine.
>
> https://web.archive.org/web/20240000000000*/http://www.ve3ute.ca/
>
> Probably the best place for it, in some people's opinion, anyways.

There's no guarantee that the *files* will be accessible via those
links. I have often gone looking for something that has disappeared
from its original home and able to find the *pages* that reference
them but not the actual *payloads*. (this happened as recently as
yesterday)

Pages take up far less space than payloads, typically, so it is
understandable that they would capture the page but not the
files referenced from it.

> YOU can make stuff available to others, in the future, by 'suggesting'
> relevent site addresses to the Internet Archive, if they're not
> already being covered.
>
> Once a 'captcha' or other security device is added, you can kiss
> Wayback updates goodbye, as most bots will get the message.
> I don't mind bots - thay can do good work.
>
> Pity you can't just put stuff up in the public domain without
> this kind of bullshit.

Making it accessible to *all* means you have to expect *all* to
access it. Hard to blame your ISP for wanting to put a limit on the
traffic to the site (my AUP forbids me from operating a public
server so I have to use more clandestine means of "publishing")

If demand is low enough (you can determine that by looking at past
"legitimate" traffic), you can insert yourself in the process by
requesting a form completion: "These are the things that I have
available. Type the name of the item into the box provided"

This eliminates LINKS on the page and requires someone who can
read the text to identify the item(s) of interest. This allows
you to intervene even if the "user" is not a 'bot but a poorly
paid urchin trying to harvest content.

Re: Chinese downloads overloading my website

<usm4jk$102tm$1@gonzo.revmaps.no-ip.org>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135644&group=sci.electronics.design#135644

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx15.iad.POSTED!not-for-mail
From: usenet@revmaps.no-ip.org (Jasen Betts)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Organization: JJ's own news server
Message-ID: <usm4jk$102tm$1@gonzo.revmaps.no-ip.org>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 11 Mar 2024 05:25:08 -0000 (UTC)
Injection-Info: gonzo.revmaps.no-ip.org; posting-host="localhost:127.0.0.1";
logging-data="1051574"; mail-complaints-to="usenet@gonzo.revmaps.no-ip.org"
User-Agent: slrn/1.0.3 (Linux)
X-Face: ?)Aw4rXwN5u0~$nqKj`xPz>xHCwgi^q+^?Ri*+R(&uv2=E1Q0Zk(>h!~o2ID@6{uf8s;a
+M[5[U[QT7xFN%^gR"=tuJw%TXXR'Fp~W;(T"1(739R%m0Yyyv*gkGoPA.$b,D.w:z+<'"=-lVT?6
{T?=R^:W5g|E2#EhjKCa+nt":4b}dU7GYB*HBxn&Td$@f%.kl^:7X8rQWd[NTc"P"u6nkisze/Q;8
"9Z{peQF,w)7UjV$c|RO/mQW/NMgWfr5*$-Z%u46"/00mx-,\R'fLPe.)^
Lines: 44
X-Complaints-To: https://www.astraweb.com/aup
NNTP-Posting-Date: Mon, 11 Mar 2024 05:30:35 UTC
Date: Mon, 11 Mar 2024 05:25:08 -0000 (UTC)
X-Received-Bytes: 2767
 by: Jasen Betts - Mon, 11 Mar 2024 05:25 UTC

On 2024-03-10, legg <legg@nospam.magma.ca> wrote:
> On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
> wrote:
>
>>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
>><legg@nospam.magma.ca> wrote in <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
>>
>>>A quick response from the ISP says they're blocking
>>>the three hosts and 'monitoring the situatio'.
>>>
>>>All the downloading was occuring between certain
>>>hours of the day in sequence - first one host
>>>between 11 and 12pm. one days rest, then the
>>>second host at the same timeon the third day,
>>>then the third host on the fourth day.
>>>
>>>Same files 262 times each, 17Gb each.
>>>
>>>Not normal web activity, as I know it.
>>>
>>>RL
>>
>>Many sites have a 'I m not a bot' sort of thing you have to go through to get access.
>
>
> Any idea what's involved - preferably anything that doesn't
> owe to Google?

> I'd like to limit traffic data volume by any host to <500M,
> or <50M in 24hrs. It's all ftp.

FTP makes it harder, you'll prably need to process the FTP logs and
put in a firewall rule once an ip address has exceeded their quota.
it may be possible to configure fail2ban to do this or you might have
to write your own script.

> Have access to Pldesk, but am unfamiliar with capabilities
> and clued out how to do much of anything save file transfer.

You'll probably need a root shell to do this setup.

--
Jasen.
🇺🇦 Слава Україні

Re: Chinese downloads overloading my website

<usm6v6$17e2c$1@solani.org>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135646&group=sci.electronics.design#135646

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!reader5.news.weretis.net!news.solani.org!.POSTED!not-for-mail
From: alien@comet.invalid (Jan Panteltje)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 06:05:26 GMT
Message-ID: <usm6v6$17e2c$1@solani.org>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org> <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; ISO-8859-15
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 11 Mar 2024 06:05:26 -0000 (UTC)
Injection-Info: solani.org;
logging-data="1292364"; mail-complaints-to="abuse@news.solani.org"
User-Agent: NewsFleX-1.5.7.5 (Linux-5.15.32-v7l+)
Cancel-Lock: sha1:ocKnGwXqqG+wd0ufONwZFa8XwP4=
X-Newsreader-location: NewsFleX-1.5.7.5 (c) 'LIGHTSPEED' off line news reader for the Linux platform
NewsFleX homepage: http://www.panteltje.nl/panteltje/newsflex/ and ftp download ftp://sunsite.unc.edu/pub/linux/system/news/readers/
X-User-ID: eJwVxskBACEIA8CW4pEI5YBi/yW4O6/hUNNeU9Tk5VXZ2pEnLORpONjTiOphHeZEAIw/XkrVyMHbmyH9fFkPUcsVBQ==
 by: Jan Panteltje - Mon, 11 Mar 2024 06:05 UTC

On a sunny day (Sun, 10 Mar 2024 13:47:48 -0400) it happened legg
<legg@nospam.magma.ca> wrote in <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>:

>On Sun, 10 Mar 2024 06:08:15 GMT, Jan Panteltje <alien@comet.invalid>
>wrote:
>
>>On a sunny day (Sat, 09 Mar 2024 20:59:19 -0500) it happened legg
>><legg@nospam.magma.ca> wrote in <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>:
>>
>>>On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
>>>wrote:
>>>
>>>>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
>>>><legg@nospam.magma.ca> wrote in <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
>>>>
>>>>>A quick response from the ISP says they're blocking
>>>>>the three hosts and 'monitoring the situatio'.
>>>>>
>>>>>All the downloading was occuring between certain
>>>>>hours of the day in sequence - first one host
>>>>>between 11 and 12pm. one days rest, then the
>>>>>second host at the same timeon the third day,
>>>>>then the third host on the fourth day.
>>>>>
>>>>>Same files 262 times each, 17Gb each.
>>>>>
>>>>>Not normal web activity, as I know it.
>>>>>
>>>>>RL
>>>>
>>>>Many sites have a 'I m not a bot' sort of thing you have to go through to get access.
>>>
>>>
>>>Any idea what's involved - preferably anything that doesn't
>>>owe to Google?
>>>...
>>>I'd like to limit traffic data volume by any host to <500M,
>>>or <50M in 24hrs. It's all ftp.
>>
>>I no longer run an ftp server (for many years now),
>>the old one here needed a password.
>>Some parts of my website used to be password protected.
>>When I ask google for "how to add a captcha to your website"
>>I see many solutions, for example this:
>> https://www.oodlestechnologies.com/blogs/create-a-captcha-validation-in-html-and-javascript/
>>
>>Maybe some html guru here nows?
>
>That looks like it's good for accessing an html page.
>So far the chinese are accessing the top level index, where
>files are offered for download at a click.
>
>Ideally, if they can't access the top level, a direct address
>access to the files might be prevented?

What I am doing now is using a html://mywebsite/pub/ directory
with lots of files in it that I want to publish in for example this newsgroup,
I then just post a direct link to that file.
So it has no index file and no links to it from the main site.
It has many sub directories too.
https://panteltje.nl/pub/GPS_to_USB_module_component_site_IXIMG_1360.JPG
https://panteltje.nl/pub/pwfax-0.1/README

So you need the exact link to access anything
fine for publishing here...
Maybe Usenet conversations are saved somewhere ? google still holds the archive?
I have most postings saved here on the Raspberry Pi4 8GB I am using for web browsing and Usenet
for what I found interesting back to 2006, older to back 1998 maybe on the old PC upstairs

raspberrypi: ~/.NewsFleX # l
total 692
-rw-r--r-- 1 root root 21971 Jan 9 2006 NewsFleX.xpm
-rw-r--r-- 1 root root 2576 Jul 30 2006 newsservers.dat.bak
drwxr-xr-x 5 root root 4096 Apr 1 2008 news.isu.edu.tw/
drwxr-xr-x 5 root root 4096 Apr 1 2008 textnews.news.cambrium.nl/
-rw-r--r-- 1 root root 1 Mar 5 2009 global_custom_head
drwx------ 4 root root 4096 Dec 6 2009 http/
-rw-r--r-- 1 root root 99 Apr 4 2010 signature.org
-rw-r--r-- 1 root root 8531 Apr 4 2010 signature~
-rw-r--r-- 1 root root 8531 Apr 4 2010 signature
-rw-r--r-- 1 root root 816 Nov 9 2011 filters.dat.OK
drwxr-xr-x 3 root root 4096 Jul 5 2012 nntp.ioe.org/
drwxr-xr-x 2 root root 4096 Mar 30 2015 news.altopia.com/
drwxr-xr-x 25 root root 4096 Mar 1 2020 news2.datemas.de/
drwxr-xr-x 109 root root 4096 Jun 1 2020 news.albasani.net/
drwxr-xr-x 2 root root 4096 Nov 28 2020 setup/
drwxr-xr-x 10 root root 4096 Mar 1 2021 news.ziggo.nl/
drwxr-xr-x 6 root root 4096 Jun 1 2021 news.chello.nl/
drwxr-xr-x 2 root root 4096 Aug 19 2021 news.neodome.net/
drwxr-xr-x 6 root root 4096 Sep 1 2022 news.tornevall.net/
drwxr-xr-x 156 root root 4096 Nov 1 2022 news.datemas.de/
drwxr-xr-x 23 root root 4096 Jan 1 2023 news.aioe.cjb.net/
drwxr-xr-x 4 root root 4096 Jan 1 2023 news.cambrium.nl/
drwxr-xr-x 52 root root 4096 Jan 1 2023 news.netfront.net/
drwxr-xr-x 60 root root 4096 Feb 1 2023 freenews.netfront.net/
-rw-r--r-- 1 root root 1651 Feb 1 2023 urls.dat~
drwxr-xr-x 49 root root 4096 Apr 2 2023 freetext.usenetserver.com/
-rw-r--r-- 1 root root 1698 Apr 18 2023 urls.dat
drwxr-xr-x 15 root root 4096 Aug 2 2023 localhost/
drwxr-xr-x 11 root root 4096 Dec 15 06:57 194.177.96.78/
drwxr-xr-x 190 root root 4096 Dec 15 06:58 nntp.aioe.org/
-rw-r--r-- 1 root root 1106 Feb 23 06:43 error_log.txt
-rw-r--r-- 1 root root 966 Feb 23 13:33 filters.dat~
-rw-r--r-- 1 root root 973 Mar 2 06:28 filters.dat
drwxr-xr-x 57 root root 4096 Mar 3 11:42 news.eternal-september.org/
drwxr-xr-x 14 root root 4096 Mar 3 11:42 news.solani.org/
drwxr-xr-x 197 root root 4096 Mar 3 11:42 postings/
-rw-r--r-- 1 root root 184263 Mar 6 04:45 newsservers.dat~
-rw-r--r-- 1 root root 2407 Mar 6 04:45 posting_periods.dat~
-rw-r--r-- 1 root root 0 Mar 6 06:27 lockfile
-rw-r--r-- 1 root root 87 Mar 6 06:27 kernel_version
-rw-r--r-- 1 root root 107930 Mar 6 06:27 fontlist.txt
-rw-r--r-- 1 root root 184263 Mar 6 06:27 newsservers.dat
-rw-r--r-- 1 root root 2407 Mar 6 06:27 posting_periods.dat
.....
lots of newsservers came and went over time...

I have backups of my website on harddisk, optical and of course my hosting provider.

Re: Chinese downloads overloading my website

<usm96m$3fkqg$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135647&group=sci.electronics.design#135647

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: mr.spock@spockmall.net (jim whitby)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 06:43:34 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 147
Message-ID: <usm96m$3fkqg$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 11 Mar 2024 06:43:34 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="8cc9e89bc304c99fd083ac0a74b65300";
logging-data="3658576"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1882zs6AHvewTaKf0081pJPIyeZrTnyEO4="
User-Agent: Pan/0.149 (Bellevue; 4c157ba git@gitlab.gnome.org:GNOME/pan.git)
Cancel-Lock: sha1:ao4Ojzex0BOwDq62PDk3oqyaruA=
X-Face: 'd|=lF%bYC^5t0@gyc[dBY6e`*9=7%4L:`xOBZam#J*j/9GZh=l&xcbJyuGun(*s
\4oF-ng
Sylo&)70,bE_K]WwpPH'v/&uI6xq.c'l(DORW{gm,W:@N!?uVwKI?"'yY|>Jxa
2q(7fNM8Kd|2+2zF
m&GrR,3#7rFZ3,VhH{,=E`8N*t|raH,8{"h+g#hDE,>@PWE}xa4Mz
HEv&eOT#B]f,#\()-=w(x@xl@
s%wWrtkCSH]c&ev:?m-7)(g|s#\+#h
 by: jim whitby - Mon, 11 Mar 2024 06:43 UTC

> On a sunny day (Sun, 10 Mar 2024 13:47:48 -0400) it happened legg
> <legg@nospam.magma.ca> wrote in
> <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>:
>
>>On Sun, 10 Mar 2024 06:08:15 GMT, Jan Panteltje <alien@comet.invalid>
>>wrote:
>>
>>>On a sunny day (Sat, 09 Mar 2024 20:59:19 -0500) it happened legg
>>><legg@nospam.magma.ca> wrote in
>>><u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>:
>>>
>>>>On Fri, 08 Mar 2024 06:43:49 GMT, Jan Panteltje <alien@comet.invalid>
>>>>wrote:
>>>>
>>>>>On a sunny day (Thu, 07 Mar 2024 17:12:27 -0500) it happened legg
>>>>><legg@nospam.magma.ca> wrote in
>>>>><6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com>:
>>>>>
>>>>>>A quick response from the ISP says they're blocking the three hosts
>>>>>>and 'monitoring the situatio'.
>>>>>>
>>>>>>All the downloading was occuring between certain hours of the day in
>>>>>>sequence - first one host between 11 and 12pm. one days rest, then
>>>>>>the second host at the same timeon the third day,
>>>>>>then the third host on the fourth day.
>>>>>>
>>>>>>Same files 262 times each, 17Gb each.
>>>>>>
>>>>>>Not normal web activity, as I know it.
>>>>>>
>>>>>>RL
>>>>>
>>>>>Many sites have a 'I m not a bot' sort of thing you have to go
>>>>>through to get access.
>>>>
>>>>
>>>>Any idea what's involved - preferably anything that doesn't owe to
>>>>Google?
>>>>...
>>>>I'd like to limit traffic data volume by any host to <500M,
>>>>or <50M in 24hrs. It's all ftp.
>>>
>>>I no longer run an ftp server (for many years now),
>>>the old one here needed a password.
>>>Some parts of my website used to be password protected.
>>>When I ask google for "how to add a captcha to your website"
>>>I see many solutions, for example this:
>>> https://www.oodlestechnologies.com/blogs/create-a-captcha-validation-
in-html-and-javascript/
>>>
>>>Maybe some html guru here nows?
>>
>>That looks like it's good for accessing an html page.
>>So far the chinese are accessing the top level index, where files are
>>offered for download at a click.
>>
>>Ideally, if they can't access the top level, a direct address access to
>>the files might be prevented?
>
> What I am doing now is using a html://mywebsite/pub/ directory with lots
> of files in it that I want to publish in for example this newsgroup,
> I then just post a direct link to that file.
> So it has no index file and no links to it from the main site.
> It has many sub directories too.
> https://panteltje.nl/pub/
GPS_to_USB_module_component_site_IXIMG_1360.JPG
> https://panteltje.nl/pub/pwfax-0.1/README
>
> So you need the exact link to access anything fine for publishing
> here...
> Maybe Usenet conversations are saved somewhere ? google still holds the
> archive?
> I have most postings saved here on the Raspberry Pi4 8GB I am using for
> web browsing and Usenet for what I found interesting back to 2006, older
> to back 1998 maybe on the old PC upstairs
>
> raspberrypi: ~/.NewsFleX # l total 692 -rw-r--r-- 1 root root 21971
> Jan 9 2006 NewsFleX.xpm -rw-r--r-- 1 root root 2576 Jul 30 2006
> newsservers.dat.bak drwxr-xr-x 5 root root 4096 Apr 1 2008
> news.isu.edu.tw/
> drwxr-xr-x 5 root root 4096 Apr 1 2008 textnews.news.cambrium.nl/
> -rw-r--r-- 1 root root 1 Mar 5 2009 global_custom_head
> drwx------ 4 root root 4096 Dec 6 2009 http/
> -rw-r--r-- 1 root root 99 Apr 4 2010 signature.org -rw-r--r--
> 1 root root 8531 Apr 4 2010 signature~
> -rw-r--r-- 1 root root 8531 Apr 4 2010 signature -rw-r--r-- 1
> root root 816 Nov 9 2011 filters.dat.OK drwxr-xr-x 3 root root
> 4096 Jul 5 2012 nntp.ioe.org/
> drwxr-xr-x 2 root root 4096 Mar 30 2015 news.altopia.com/
> drwxr-xr-x 25 root root 4096 Mar 1 2020 news2.datemas.de/
> drwxr-xr-x 109 root root 4096 Jun 1 2020 news.albasani.net/
> drwxr-xr-x 2 root root 4096 Nov 28 2020 setup/
> drwxr-xr-x 10 root root 4096 Mar 1 2021 news.ziggo.nl/
> drwxr-xr-x 6 root root 4096 Jun 1 2021 news.chello.nl/
> drwxr-xr-x 2 root root 4096 Aug 19 2021 news.neodome.net/
> drwxr-xr-x 6 root root 4096 Sep 1 2022 news.tornevall.net/
> drwxr-xr-x 156 root root 4096 Nov 1 2022 news.datemas.de/
> drwxr-xr-x 23 root root 4096 Jan 1 2023 news.aioe.cjb.net/
> drwxr-xr-x 4 root root 4096 Jan 1 2023 news.cambrium.nl/
> drwxr-xr-x 52 root root 4096 Jan 1 2023 news.netfront.net/
> drwxr-xr-x 60 root root 4096 Feb 1 2023 freenews.netfront.net/
> -rw-r--r-- 1 root root 1651 Feb 1 2023 urls.dat~
> drwxr-xr-x 49 root root 4096 Apr 2 2023 freetext.usenetserver.com/
> -rw-r--r-- 1 root root 1698 Apr 18 2023 urls.dat drwxr-xr-x 15
> root root 4096 Aug 2 2023 localhost/
> drwxr-xr-x 11 root root 4096 Dec 15 06:57 194.177.96.78/
> drwxr-xr-x 190 root root 4096 Dec 15 06:58 nntp.aioe.org/
> -rw-r--r-- 1 root root 1106 Feb 23 06:43 error_log.txt -rw-r--r--
> 1 root root 966 Feb 23 13:33 filters.dat~
> -rw-r--r-- 1 root root 973 Mar 2 06:28 filters.dat drwxr-xr-x 57
> root root 4096 Mar 3 11:42 news.eternal-september.org/
> drwxr-xr-x 14 root root 4096 Mar 3 11:42 news.solani.org/
> drwxr-xr-x 197 root root 4096 Mar 3 11:42 postings/
> -rw-r--r-- 1 root root 184263 Mar 6 04:45 newsservers.dat~
> -rw-r--r-- 1 root root 2407 Mar 6 04:45 posting_periods.dat~
> -rw-r--r-- 1 root root 0 Mar 6 06:27 lockfile -rw-r--r-- 1
> root root 87 Mar 6 06:27 kernel_version -rw-r--r-- 1 root root
> 107930 Mar 6 06:27 fontlist.txt -rw-r--r-- 1 root root 184263 Mar 6
> 06:27 newsservers.dat -rw-r--r-- 1 root root 2407 Mar 6 06:27
> posting_periods.dat ....
> lots of newsservers came and went over time...
>
> I have backups of my website on harddisk, optical and of course my
> hosting provider.

You may find the file:

/etc/hosts.deny

useful in this case, you can block by name(s) or ip(s).
Man hosts,deny
for more info

--
Jim Whitby

Famous, adj.:
Conspicuously miserable.
-- Ambrose Bierce, "The Devil's Dictionary"
----------------------
Mageia release 9 (Official) for x86_64
6.6.18-server-1.mga9 unknown
----------------------

Re: Chinese downloads overloading my website

<usmhbp$3hcok$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135648&group=sci.electronics.design#135648

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: blockedofcourse@foo.invalid (Don Y)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 02:02:47 -0700
Organization: A noiseless patient Spider
Lines: 25
Message-ID: <usmhbp$3hcok$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org>
<usm96m$3fkqg$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 11 Mar 2024 09:02:49 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="bfd4745dd589d11941b6ad5b8849d225";
logging-data="3715860"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/p6aKRPp3tk866qmRzu4c9"
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.2.2
Cancel-Lock: sha1:XdRxhGYfJBtxryvz2UiXVOZvvs0=
In-Reply-To: <usm96m$3fkqg$1@dont-email.me>
Content-Language: en-US
 by: Don Y - Mon, 11 Mar 2024 09:02 UTC

On 3/10/2024 11:43 PM, jim whitby wrote:
> You may find the file:
>
> /etc/hosts.deny
>
> useful in this case, you can block by name(s) or ip(s).
> Man hosts,deny
> for more info

My read is not that *he* is having traffic throttled to a
server that *he* operates but, rather, that traffic to
a (virtual) server that his ISP operates on his behalf
is being throttled. I.e., his subscription allows 50GB/month
(and some amount of storage space) and that is being exceeded
by "unfriendly" clients.

As he has no direct control over traffic, he is at the mercy of
unknown (in this case, chinese) users to limit THEIR accesses
to his (virtual) site. I.e., his *provider* needs to restrict
unwanted accesses.

Sort of like complaining to your cellular provider that you are
getting too many text messages from people that you don't want
to hear from and these are eating into your monthly quota...

Re: Chinese downloads overloading my website

<usmkb9$17l2r$1@solani.org>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135650&group=sci.electronics.design#135650

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!reader5.news.weretis.net!news.solani.org!.POSTED!not-for-mail
From: alien@comet.invalid (Jan Panteltje)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 09:53:44 GMT
Message-ID: <usmkb9$17l2r$1@solani.org>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org> <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org> <usm96m$3fkqg$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; ISO-8859-15
Content-Transfer-Encoding: 8bit
Injection-Date: Mon, 11 Mar 2024 09:53:45 -0000 (UTC)
Injection-Info: solani.org;
logging-data="1299547"; mail-complaints-to="abuse@news.solani.org"
User-Agent: NewsFleX-1.5.7.5 (Linux-5.15.32-v7l+)
Cancel-Lock: sha1:USAPJ8s9GNKS8qoBAF46raWJr44=
X-Newsreader-location: NewsFleX-1.5.7.5 (c) 'LIGHTSPEED' off line news reader for the Linux platform
NewsFleX homepage: http://www.panteltje.nl/panteltje/newsflex/ and ftp download ftp://sunsite.unc.edu/pub/linux/system/news/readers/
X-User-ID: eJwFwQcBACAIBMBK8gwhDkP6R/BO2cj6iqmJru5Sgh76RE5fVDWtR7+w4mUpn6MlLw3jfDUaWX4iYjEw9g9xMBXL
 by: Jan Panteltje - Mon, 11 Mar 2024 09:53 UTC

On a sunny day (Mon, 11 Mar 2024 06:43:34 -0000 (UTC)) it happened jim whitby
<mr.spock@spockmall.net> wrote in <usm96m$3fkqg$1@dont-email.me>:

>You may find the file:
>
>/etc/hosts.deny
>
>useful in this case, you can block by name(s) or ip(s).
>Man hosts,deny
>for more info

I wrote a small script years ago using Linux iptables to reject bad IP adresses.

raspberrypi: ~ # cat /usr/local/sbin_pi_95/ireject
# this is called to add a input deny for an IP addres to ipchains,
# and save the configuration.

if [ "$1" = "" ]
then
echo "Usage: reject IP_address"
exit 1
fi

# OLD ipchains
##ipchains -A input -s $1 -l -j REJECT
#ipchains -L
##ipchains-save > /root/firewall
##echo "reject: ipchains configuration written to /root/firewall"

#iptables -A INPUT -s $1 -p all -j REJECT
#iptables -A INPUT -s $1 -p all -j DROP

echo "executing iptables -A INPUT -s $1 -p all -j DROP"
iptables -A INPUT -s $1 -p all -j DROP

echo "executing iptables -A OUTPUT -s $1 -p all -j REJECT"
iptables -A OUTPUT -s $1 -p all -j REJECT

iptables-save > /root/firewall2

exit 0

Therr is an other one 'load_firewall somewhere.
raspberrypi: ~ # cat /usr/local/sbin_pi_95/load-firewall
iptables -F
#/sbin/ipchains-restore < /root/firewall
/sbin/iptables-restore < /root/firewall2

There were many many entries in /root/firewall back then, daily work to keep track of attacks.
Now I am on a dynamic IP address and the website is handled by a company,
saves a lot of time.

Things evolve all the time, iptables sets this Raspberry Pi with 8 GB memory as router too,
runs with a Huawei 4G USB stick with IP 192.168.8.100 for net connection, anywhere in Europe I think,
an other script:

raspberrypi: # cat /usr/local/sbin/start_4g_router
#!/usr//bin/bash

iptables -F

route add -net 192.168.0.0/16 dev eth0

echo 1 >/proc/sys/net/ipv4/ip_forward

iptables -t nat -A POSTROUTING ! -d 192.168.0.0/16 -o eth1 -j SNAT --to-source 192.168.8.100
sleep 1

ifconfig eth0 down
sleep 1

ifconfig eth0 192.168.178.1 up
sleep 1

vnstat -i eth1 -s
sleep 1

# default is set to 192.168.8.1, using 8.8.8.8 and 8.8.4.4 google name server lookup
cp /etc/resolv.conf.GOOGLE /etc/resolv.conf
sleep 1

# reduce swapping
sysctl vm.swappiness=5

echo "ready"

There is more, but then again, things change over time too.

Re: Chinese downloads overloading my website

<du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135652&group=sci.electronics.design#135652

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 10:40:16 -0400
Organization: A noiseless patient Spider
Lines: 103
Message-ID: <du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org> <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org> <usm96m$3fkqg$1@dont-email.me> <usmkb9$17l2r$1@solani.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="4bf5ccac6bd891d8f3c037dd4188dedd";
logging-data="3857246"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX182d/kOvDAZlwelg6p2eDM1"
Cancel-Lock: sha1:1k8yh8FFPeDY6QGon7WM/Sl+Wko=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Mon, 11 Mar 2024 14:40 UTC

On Mon, 11 Mar 2024 09:53:44 GMT, Jan Panteltje <alien@comet.invalid>
wrote:

>On a sunny day (Mon, 11 Mar 2024 06:43:34 -0000 (UTC)) it happened jim whitby
><mr.spock@spockmall.net> wrote in <usm96m$3fkqg$1@dont-email.me>:
>
>>You may find the file:
>>
>>/etc/hosts.deny
>>
>>useful in this case, you can block by name(s) or ip(s).
>>Man hosts,deny
>>for more info
>
>I wrote a small script years ago using Linux iptables to reject bad IP adresses.
>
>raspberrypi: ~ # cat /usr/local/sbin_pi_95/ireject
># this is called to add a input deny for an IP addres to ipchains,
># and save the configuration.
>
>if [ "$1" = "" ]
>then
> echo "Usage: reject IP_address"
> exit 1
>fi
>
># OLD ipchains
>##ipchains -A input -s $1 -l -j REJECT
>#ipchains -L
>##ipchains-save > /root/firewall
>##echo "reject: ipchains configuration written to /root/firewall"
>
>#iptables -A INPUT -s $1 -p all -j REJECT
>#iptables -A INPUT -s $1 -p all -j DROP
>
>echo "executing iptables -A INPUT -s $1 -p all -j DROP"
>iptables -A INPUT -s $1 -p all -j DROP
>
>echo "executing iptables -A OUTPUT -s $1 -p all -j REJECT"
>iptables -A OUTPUT -s $1 -p all -j REJECT
>
>iptables-save > /root/firewall2
>
>exit 0
>
>Therr is an other one 'load_firewall somewhere.
>raspberrypi: ~ # cat /usr/local/sbin_pi_95/load-firewall
>iptables -F
>#/sbin/ipchains-restore < /root/firewall
>/sbin/iptables-restore < /root/firewall2
>
>
>
>There were many many entries in /root/firewall back then, daily work to keep track of attacks.
>Now I am on a dynamic IP address and the website is handled by a company,
>saves a lot of time.
>
>Things evolve all the time, iptables sets this Raspberry Pi with 8 GB memory as router too,
>runs with a Huawei 4G USB stick with IP 192.168.8.100 for net connection, anywhere in Europe I think,
>an other script:
>
>raspberrypi: # cat /usr/local/sbin/start_4g_router
>#!/usr//bin/bash
>
>iptables -F
>
>route add -net 192.168.0.0/16 dev eth0
>
>echo 1 >/proc/sys/net/ipv4/ip_forward
>
>iptables -t nat -A POSTROUTING ! -d 192.168.0.0/16 -o eth1 -j SNAT --to-source 192.168.8.100
>sleep 1
>
>ifconfig eth0 down
>sleep 1
>
>ifconfig eth0 192.168.178.1 up
>sleep 1
>
>vnstat -i eth1 -s
>sleep 1
>
># default is set to 192.168.8.1, using 8.8.8.8 and 8.8.4.4 google name server lookup
>cp /etc/resolv.conf.GOOGLE /etc/resolv.conf
>sleep 1
>
># reduce swapping
>sysctl vm.swappiness=5
>
>echo "ready"
>
>
>There is more, but then again, things change over time too.

Blocking a single IP hasn't worked for my ISP.

Each identical 17G download block (262 visits)was by a new IP
in a completely different location/region.

Beijing, Hearbin, Henan, a mobile and a fifth, so far untraced
due to suspension of my site.

RL

Re: Chinese downloads overloading my website

<d16uuihrafv26mcoujjfir0rf9l8td4njk@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135653&group=sci.electronics.design#135653

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 10:42:18 -0400
Organization: A noiseless patient Spider
Lines: 29
Message-ID: <d16uuihrafv26mcoujjfir0rf9l8td4njk@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="4bf5ccac6bd891d8f3c037dd4188dedd";
logging-data="3857246"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+h+fpYCDGG42YJBVnAFlB2"
Cancel-Lock: sha1:mMCLE8uly4rO7nFW3DPB89GLAnE=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Mon, 11 Mar 2024 14:42 UTC

On Thu, 07 Mar 2024 12:49:30 -0500, legg <legg@nospam.magma.ca> wrote:

>Got a note from an ISP today indicating that my website
>was suspended due to data transfer over-use for the month. (>50G)
>It's only the 7th day of the month and this hadn't been a
>problem in the 6 years they'd hosted the service.
>
>Turns out that three chinese sources had downloaded the same
>set of files, each 262 times. That would do it.
>
>So, anyone else looking to update bipolar semiconductor,
>packaging or spice parameter spreadsheets; look at K.A.Pullen's
>'Conductance Design Curve Manual' or any of the other bits
>stored at ve3ute.ca are out of luck, for the rest of the month .
>
>Seems strange that the same three addresses downloaded the
>same files, the same number of times. Is this a denial of
>service attack?
>
>RL

You can still access most of the usefull files, updated in
January 2024, through the Wayback Machine.

https://web.archive.org/web/20240000000000*/http://www.ve3ute.ca/

Probably the best place for it, in some people's opinion, anyways.

RL

Re: Chinese downloads overloading my website

<usn5j7$3lod7$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135655&group=sci.electronics.design#135655

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: blockedofcourse@foo.invalid (Don Y)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 07:48:04 -0700
Organization: A noiseless patient Spider
Lines: 31
Message-ID: <usn5j7$3lod7$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org>
<usm96m$3fkqg$1@dont-email.me> <usmkb9$17l2r$1@solani.org>
<du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 11 Mar 2024 14:48:08 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="bfd4745dd589d11941b6ad5b8849d225";
logging-data="3858855"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18GcnbuyFdJtIPanSlySHtI"
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.2.2
Cancel-Lock: sha1:AKJOJ7yYhPpsuOnrkpIKBZ/0Rf4=
In-Reply-To: <du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com>
Content-Language: en-US
 by: Don Y - Mon, 11 Mar 2024 14:48 UTC

On 3/11/2024 7:40 AM, legg wrote:
> Blocking a single IP hasn't worked for my ISP.

It won't. Even novice users can move to a different IP using reeadily
available mechanisms.

Whitelisting can work (which is the approach that I use) but
it assumes you know who you *want* to access your site.

(It's a lot harder to guess a permitted IP than it is to avoid
an obviously BLOCKED one!)

> Each identical 17G download block (262 visits)was by a new IP
> in a completely different location/region.
>
> Beijing, Hearbin, Henan, a mobile and a fifth, so far untraced
> due to suspension of my site.

There's a reason things like "captcha" exist.

Note that this still doesn't prevent the *page(s)* from being repeatedly
accessed. But, presumably, their size is considerably smaller than
that of the payloads you want to protect.

OTOH, if someone wants to shut down your account due to an exceeded
quota, they can keep reloading those pages until they've eaten up your
traffic quota. And, "they" can be an automated process!

[Operating a server in stealth mode can avoid this. But, then
you're not "open to the public"! :> ]

Re: Chinese downloads overloading my website

<gabuui56k0fn9iovps09um30lhiqhvc61t@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135658&group=sci.electronics.design#135658

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 12:48:57 -0400
Organization: A noiseless patient Spider
Lines: 75
Message-ID: <gabuui56k0fn9iovps09um30lhiqhvc61t@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org> <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="4bf5ccac6bd891d8f3c037dd4188dedd";
logging-data="3914219"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19krWiQjqnWXY477pAWEbN6"
Cancel-Lock: sha1:qu8/DSNYtTLjSXmMTfZkG0iQ6Z8=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Mon, 11 Mar 2024 16:48 UTC

On Mon, 11 Mar 2024 06:05:26 GMT, Jan Panteltje <alien@comet.invalid>
wrote:

>On a sunny day (Sun, 10 Mar 2024 13:47:48 -0400) it happened legg
><legg@nospam.magma.ca> wrote in <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com>:
>
>>On Sun, 10 Mar 2024 06:08:15 GMT, Jan Panteltje <alien@comet.invalid>
>>wrote:
>>
>>>On a sunny day (Sat, 09 Mar 2024 20:59:19 -0500) it happened legg
>>><legg@nospam.magma.ca> wrote in <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com>:
>>>
<snip>
>>>When I ask google for "how to add a captcha to your website"
>>>I see many solutions, for example this:
>>> https://www.oodlestechnologies.com/blogs/create-a-captcha-validation-in-html-and-javascript/
>>>
>>>Maybe some html guru here nows?
>>
>>That looks like it's good for accessing an html page.
>>So far the chinese are accessing the top level index, where
>>files are offered for download at a click.
>>
>>Ideally, if they can't access the top level, a direct address
>>access to the files might be prevented?

Using barebones (Netscape) Seamonkey Compser, the Oodlestech
script generates a web page with a 4-figure manually-entered
human test.

How do I get a correct response to open the protected web page?

>
>What I am doing now is using a html://mywebsite/pub/ directory
>with lots of files in it that I want to publish in for example this newsgroup,
>I then just post a direct link to that file.
>So it has no index file and no links to it from the main site.
>It has many sub directories too.
> https://panteltje.nl/pub/GPS_to_USB_module_component_site_IXIMG_1360.JPG
> https://panteltje.nl/pub/pwfax-0.1/README
>
>So you need the exact link to access anything
>fine for publishing here...
<snip>

The top (~index) web page of my site has lists of direct links
to subdirectories, for double-click download by user.

It also has limks to other web pages that, in turn, offer links or
downloads to on-site and off-site locations. A great number of
off-site links are invalid, after ~10-20years of neglect. They'll
probably stay that way until something or somebody convinces me
that it's all not just a waste of time.

At present, I only maintain data links or electronic publications
that need it. This may not be neccessary, as the files are generally
small enough for the Wayback machine to have scooped up most of the
databases and spreadsheets. They're also showing up in other places,
with my blessing. Hell - Wayback even has tube curve pages from the
'Conductance Curve Design Manual' - they've got to be buried 4 folders
deep - and each is a hefty image.

Somebody, please tell me the the 'Internet Archive' is NOT owned
by Google?

Some off-site links for large image-bound mfr-logo-ident web pages
(c/o geek@scorpiorising) seem already to have introduced a
captcha-type routine. Wouldn't need many bot hits to bump that
location into a data limit. Those pages take a long time
simply to load.

Anyway - how to get the Oodlestech script to open the appropriate
page, after vetting the user as being human?

RL

Re: Chinese downloads overloading my website

<kmduuilbvdjssqjda1i21d9b08vrk4t86j@4ax.com>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135659&group=sci.electronics.design#135659

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: legg@nospam.magma.ca (legg)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 12:57:20 -0400
Organization: A noiseless patient Spider
Lines: 43
Message-ID: <kmduuilbvdjssqjda1i21d9b08vrk4t86j@4ax.com>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com> <6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org> <u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org> <t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org> <usm96m$3fkqg$1@dont-email.me> <usmkb9$17l2r$1@solani.org> <du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com> <usn5j7$3lod7$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="4bf5ccac6bd891d8f3c037dd4188dedd";
logging-data="3918065"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18YlHNt8TcULWYfdyNyO2r7"
Cancel-Lock: sha1:LmcAfLpMcqvjgkOpp4fvA1+gfTg=
X-Newsreader: Forte Agent 4.2/32.1118
 by: legg - Mon, 11 Mar 2024 16:57 UTC

On Mon, 11 Mar 2024 07:48:04 -0700, Don Y
<blockedofcourse@foo.invalid> wrote:

>On 3/11/2024 7:40 AM, legg wrote:
>> Blocking a single IP hasn't worked for my ISP.
>
>It won't. Even novice users can move to a different IP using reeadily
>available mechanisms.
>
>Whitelisting can work (which is the approach that I use) but
>it assumes you know who you *want* to access your site.
>
>(It's a lot harder to guess a permitted IP than it is to avoid
>an obviously BLOCKED one!)
>
>> Each identical 17G download block (262 visits)was by a new IP
>> in a completely different location/region.
>>
>> Beijing, Hearbin, Henan, a mobile and a fifth, so far untraced
>> due to suspension of my site.
>
>There's a reason things like "captcha" exist.
>
>Note that this still doesn't prevent the *page(s)* from being repeatedly
>accessed. But, presumably, their size is considerably smaller than
>that of the payloads you want to protect.
>
>OTOH, if someone wants to shut down your account due to an exceeded
>quota, they can keep reloading those pages until they've eaten up your
>traffic quota. And, "they" can be an automated process!
>
>[Operating a server in stealth mode can avoid this. But, then
>you're not "open to the public"! :> ]

Doing some simple experiments by temporarily renaming/replacing
some of the larger files being tageted, just to see how the bot
reacts to the new environment. If they find renamed files it
means something. If visits to get the same 17G alter it means
something else.

This all at the expense and patience of my ISP. Thumbs up there.

RL

Re: Chinese downloads overloading my website

<usookd$48ti$2@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135667&group=sci.electronics.design#135667

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: blockedofcourse@foo.invalid (Don Y)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Mon, 11 Mar 2024 22:19:06 -0700
Organization: A noiseless patient Spider
Lines: 27
Message-ID: <usookd$48ti$2@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org>
<usm96m$3fkqg$1@dont-email.me> <usmkb9$17l2r$1@solani.org>
<du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com> <usn5j7$3lod7$1@dont-email.me>
<kmduuilbvdjssqjda1i21d9b08vrk4t86j@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 12 Mar 2024 05:19:10 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="cd61f5e18330181594e65cc325aef3d5";
logging-data="140210"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+gukSaUpjsQxLpZSZWEz+4"
User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.2.2
Cancel-Lock: sha1:KdGvSsjTLQ3SNXUM9ASNGOWmj6I=
Content-Language: en-US
In-Reply-To: <kmduuilbvdjssqjda1i21d9b08vrk4t86j@4ax.com>
 by: Don Y - Tue, 12 Mar 2024 05:19 UTC

On 3/11/2024 9:57 AM, legg wrote:
> Doing some simple experiments by temporarily renaming/replacing
> some of the larger files being tageted, just to see how the bot
> reacts to the new environment. If they find renamed files it
> means something. If visits to get the same 17G alter it means
> something else.

That;s probably a good, inexpensive strategy to see how "active"
your "clients" are. Repeated hits on stale URLs would let you
know they are likely just reprobing from previously stored
results vs. actively *exploring* your site.

[Gotta wonder if they aren't a google/archive wannabe and not
smart enough to just *look* at the site.]

> This all at the expense and patience of my ISP. Thumbs up there.

Be grateful. Many larger corporate providers would just cite
the AUP and your subscription terms and that would be the
end of THAT "discussion".

I run a thin pipe to the house -- my provider would love to
upsell me. But, it's saturated 95% of the time; a fatter
pipe would be idle while I'm away/asleep. As *latency* isn't
an issue, AVERAGE bandwidth remains the same. (as I download
another terabyte of rainbow tables...)

Re: Chinese downloads overloading my website

<usp7vj$7dna$1@dont-email.me>

  copy mid

https://news.novabbs.org/tech/article-flat.php?id=135673&group=sci.electronics.design#135673

  copy link   Newsgroups: sci.electronics.design
Path: i2pn2.org!i2pn.org!eternal-september.org!feeder3.eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: '''newspam'''@nonad.co.uk (Martin Brown)
Newsgroups: sci.electronics.design
Subject: Re: Chinese downloads overloading my website
Date: Tue, 12 Mar 2024 09:41:00 +0000
Organization: A noiseless patient Spider
Lines: 63
Message-ID: <usp7vj$7dna$1@dont-email.me>
References: <7qujui58fjds1isls4ohpcnp5d7dt20ggk@4ax.com>
<6lekuihu1heui4th3ogtnqk9ph8msobmj3@4ax.com> <usec35$130bu$1@solani.org>
<u14quid1e74r81n0ajol0quthaumsd65md@4ax.com> <usjiog$15kaq$1@solani.org>
<t7rrui5ohh07vlvn5vnl277eec6bmvo4p9@4ax.com> <usm6v6$17e2c$1@solani.org>
<usm96m$3fkqg$1@dont-email.me> <usmkb9$17l2r$1@solani.org>
<du5uuih5e5d4ugd7ru8oo0gb6ppenjrtdd@4ax.com> <usn5j7$3lod7$1@dont-email.me>
<kmduuilbvdjssqjda1i21d9b08vrk4t86j@4ax.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 12 Mar 2024 09:41:07 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="addf6acf1814213cb2e2eb642bb3e40c";
logging-data="243434"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19D3JS56r6SCIBf/a0P7yIUgSClSLcO/U6mtLd/jAOZow=="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:A3vKrJK2GN/fMPzDy1JZmL6W+6s=
Content-Language: en-GB
In-Reply-To: <kmduuilbvdjssqjda1i21d9b08vrk4t86j@4ax.com>
 by: Martin Brown - Tue, 12 Mar 2024 09:41 UTC

On 11/03/2024 16:57, legg wrote:
> On Mon, 11 Mar 2024 07:48:04 -0700, Don Y
> <blockedofcourse@foo.invalid> wrote:
>
>> On 3/11/2024 7:40 AM, legg wrote:
>>> Blocking a single IP hasn't worked for my ISP.
>>
>> It won't. Even novice users can move to a different IP using reeadily
>> available mechanisms.
>>
>> Whitelisting can work (which is the approach that I use) but
>> it assumes you know who you *want* to access your site.
>>
>> (It's a lot harder to guess a permitted IP than it is to avoid
>> an obviously BLOCKED one!)
>>
>>> Each identical 17G download block (262 visits)was by a new IP
>>> in a completely different location/region.
>>>
>>> Beijing, Hearbin, Henan, a mobile and a fifth, so far untraced
>>> due to suspension of my site.
>>
>> There's a reason things like "captcha" exist.
>>
>> Note that this still doesn't prevent the *page(s)* from being repeatedly
>> accessed. But, presumably, their size is considerably smaller than
>> that of the payloads you want to protect.
>>
>> OTOH, if someone wants to shut down your account due to an exceeded
>> quota, they can keep reloading those pages until they've eaten up your
>> traffic quota. And, "they" can be an automated process!
>>
>> [Operating a server in stealth mode can avoid this. But, then
>> you're not "open to the public"! :> ]
>
> Doing some simple experiments by temporarily renaming/replacing
> some of the larger files being tageted, just to see how the bot
> reacts to the new environment. If they find renamed files it
> means something. If visits to get the same 17G alter it means
> something else.
>
> This all at the expense and patience of my ISP. Thumbs up there.

Why don't you block entire blocks of Chinese IP addresses that contain
the ones that have attacked you until the problem ceases?
eg. add a few banned IP destinations to your .htaccess file

https://htaccessbook.com/block-ip-address/

1.80.*.* thru 1.95.*.*
101.16.*.* thru 101.16.*.*
101.144.*.* thru 101.159.*.*

If you block just a few big chunks it should make some difference.
You might have to inflict a bit of collateral damage in the 101.* range.

Otherwise you are stuck with adding some Captcha type thing to prevent
malicious bots hammering your site. I'm a bit surprised that your ISP
doesn't offer or have site wide countermeasures for such DOS attacks.

--
Martin Brown

Pages:123
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor