Can Anubis and Iocane be linked?
from Maroon@lemmy.world to selfhosted@lemmy.world on 31 Mar 17:18
https://lemmy.world/post/44994665
from Maroon@lemmy.world to selfhosted@lemmy.world on 31 Mar 17:18
https://lemmy.world/post/44994665
This may sound like a weird thing to do, but I realised that many crawlers and bots are somehow still able to get past my Anubis. I presume they have gotten smarter and are capable of using JavaScript.
To counter this, I want to link my Anubis to an Iocane setup such that:
Internet > nginx reverse proxy > Anubis > Iocane > my site/app
My hope is that two different filtering mechanisms (one of which will actively poison and waste the bot’s resourced) will protect my system better.
I thought I’d ask before actually trying out something like this.
threaded - newest
Context:
en.wikipedia.org/wiki/Anubis_(software)
lib.rs/crates/iocaine
Iocaine expects you know how to detect it the bots, if they can get past anubis do you have another detection process?
Have you tried fucking with the status codes?
There is a great defcon talk about that:
Slides
Video on Youtube
So you could e.g. return a 401 and still show the page. Most automated systems will probably ignore the response of an ‘unauthorized’ message.