Popular Posts

Popular Content

Powered by Blogger.

Search This Blog

Follow on Google+

Recent Posts

About us

TLDR: I help with a gaming community-related site that is being targetted by a script kiddie, they are registering hundreds of thousands of accounts on our forums to 'protest' a cheating (aimbot) ban. They then post large ASCII art spam, giant shock images (the first one started after we blocked new accounts from posting [img]), the usual.

Currently we use a simple question/answer addon at registration time - it works against all untargeted bots and is just a little "what is 4 plus six" or "what is the abbreviation for this website" type of question. It's worked fine for years and we don't really get general untargeted spam.

I am somewhat ethically disinclined to use reCAPTCHA, and there are some older members that can't reasonably solve hcaptcha easily. Same for using heavy fingerprinting or other privacy invading methods. It's also donation-run, so enterprise services that would block something like this (such as Distil) are both out of budget and out of ethics.

Is there a way I can possibly solve this? Negotiation is not really an option on the table, the last time one of the other volunteers responded at all we got a ~150Gbps volumetric attack.

I've tried some basic things, like requiring cookie and JS support via middleware; they moved from a Java HTTP-library script to some kind of Selenium equivalent afterward. They also use a massive amount of proxies, largely compromised machines being sold for abuse.


Comments URL: https://news.ycombinator.com/item?id=24334657

Points: 53

# Comments: 44



from Hacker News: Front Page https://ift.tt/2EVqAs4
Continue Reading

Vice President Mike Pence was put on standby to temporarily assume the powers of the presidency during President Donald Trump's unannounced visit to Walter Reed hospital in November 2019, according to a copy of New York Times reporter Michael Schmidt's forthcoming book obtained by CNN.


from CNN.com - RSS Channel https://ift.tt/2QIvbAA
Continue Reading

President Donald Trump argued in a federal appellate court filing Monday that a district court had wrongly sided with Manhattan District Attorney Cy Vance's office in a lawsuit over a subpoena to Trump's longtime accounting firm for his financial records, saying the lower court's assessment was "not the kind of process the Supreme Court envisioned when it remanded this case."


from CNN.com - RSS Channel https://ift.tt/31Li888
Continue Reading