Chinese downloads overloading my website

Mar 07, 2024 Last reply: 2 years ago 34 Replies

All of this "graphical captcha" stuff is easy to hack if somebody is out to trash *your* site.

For example I run some sites and paid someone 1k or so to develop a graphical captcha. It displayed two numbers as graphic images and you had to enter their product e.g. 12 x 3 = 36.

A friend who is an expert at unix spent just a few mins on a script which used standard unix utilities to do OCR on the page, and you can guess the rest.

Maybe consider hosting the web server yourself, using a virtual machine/Promox as the host and a Cloudflare tunnel for security:

formatting link

You could always have a question which involved correcting the English grammar of a sentence, but that might eliminate far more of your visitors than you intended.

[Said in best posh English accent] Did you meean: "Yes; for instance 95%" ? :-)

What is "stealth mode", what do you do?

I was thinking of using a high port. I do that.

"He helped his Uncle Jack off a horse."

Those things would kill most people for which English is a second language.

Indeed.

Anybody starting a sentence with "indeed" is posh!

The sniffer will find any port # in a few more seconds...

Can you actually do that, with a standard server? Normally every TCP/IP packet is acked. This is deep in the system.

UDP isn't, which is why port knocking works so well.

OK, don't have to self-host. There are possible privacy/security concerns using Cloudflare for private data/WAN applications but for public-facing generally static web pages it seems like a no-brainer, they have pretty generous free plans.

Actually it takes longer than that. So far, no hits; and I would notice when someone tries to login on ssh.

Of course, one can defend the fort from casual attackers, not from determined attackers; those will eventually find a way.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required