Honeypot against bad bots

Creating and modifying plugins.
Post Reply
Czorneboh
Regular
Posts: 382
Joined: Tue Apr 08, 2008 7:17 pm
Location: Berlin
Contact:

Honeypot against bad bots

Post by Czorneboh » Thu Jan 08, 2015 1:56 am

Hello everybody!
All of our community my personal wishes for health and good luck in 2015!

I use the 3 recomonded antispam plugins. I do get many bots.

I just found a suggestion to create a honeypot for bad bots here (german):

http://www.seitenreport.de/kb/-/webcraw ... ieren.html

What about the functionality of the current version of spamblock bee according to this suggestion?
What about developing the spamblock bee with that?
Makes it sense? Is it easy?
Or is that something everybody should do for own blog individually?

Czorneboh

User avatar
garvinhicking
Core Developer
Posts: 30020
Joined: Tue Sep 16, 2003 9:45 pm
Location: Cologne, Germany
Contact:

Re: Honeypot against bad bots

Post by garvinhicking » Fri Jan 09, 2015 1:20 pm

That solution is not a very good one:

1.) It blocks based on IP adresses which can change, and which can affect dial up users.

2.) It would require updating the .htaccess dynamically based on the honeypot, which a.) creates all sort of trouble if .htaccess gets too large (the current spamblock plugin tried to do that by deniying IPs and often made more trouble than it was worth) and b.) slows down parsing

3.) someone could block you from accessing a blog if they mailed the honeypot URL to you, you opened it, and then you could never again visit the blog.

Regards,
Garvin
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/

Czorneboh
Regular
Posts: 382
Joined: Tue Apr 08, 2008 7:17 pm
Location: Berlin
Contact:

Re: Honeypot against bad bots

Post by Czorneboh » Fri Jan 09, 2015 6:14 pm

Thank you, Garvin,

I read you.

So at least could I add the list here ...

https://www.ip-bannliste.de/bad-bots.html

... manually into my .htaccess file without the describben negative effects, correct?

(Some of those bots in that linked list I do remember, like httpTrack and Xenu. Perhaps I will exclude those, so far I want to use those by myself. And Yandex.bot to get into Yandex SERPs with my pages.)

User avatar
garvinhicking
Core Developer
Posts: 30020
Joined: Tue Sep 16, 2003 9:45 pm
Location: Cologne, Germany
Contact:

Re: Honeypot against bad bots

Post by garvinhicking » Sat Jan 10, 2015 1:49 pm

Yeah, if you trust that list of IPs to really be bots and not "real" users, you can do that!
# Garvin Hicking (s9y Developer)
# Did I help you? Consider making me happy: http://wishes.garv.in/
# or use my PayPal account "paypal {at} supergarv (dot) de"
# My "other" hobby: http://flickr.garv.in/

Post Reply