AI / IT experts in Tokyo : https://ayo.tokyo/
- 3 Posts
- 6 Comments
AYO_Official@lemmy.mlOPto
Self Hosted - Self-hosting your services.@lemmy.ml•Forgejo Scraping Protection: Nginx and Anubis
1·15 days agoIsn’t the use of different random IP per request by bots a stronger arguments in favor of the default Anubis behavior? This would mean a lot of POW to be done by the bots.
The deep link accesses is worrying indeed and Anubis is not a silver bullet.
I also agree with the use of a known abusive IP database.
AYO_Official@lemmy.mlOPto
Self Hosted - Self-hosting your services.@lemmy.ml•Forgejo Scraping Protection: Nginx and Anubis
1·17 days agoThanks for the sources, reading them make me realize : MAYBE I have been protected so far because my website is built using InfernoJS and I didn’t realize Forgejo doesn’t requires Javascript.
So the spams are more likely to appear from the “low-effort” bots that don’t run a Javascript engine. The problem is that the website has only 5 static pages (the JS framework allows better server efficiency and language/theme switch) so spam were never an issue (you can get the whole websites in 10 requests).
I am thinking about adding a fail2ban rule on the 503 answers triggered by nginx rate limit. This should but this would once again only protected against low-effort bot that don’t calculate the rate limit.
Experience will tell how good of a protection this is.
Let me add that the website is still not using Anubis, this is only for the public forgejo instance. Also any published software is mirrored on codeberg. I think visitors of the self-host git repository is very niche and specialized, for any one but me looking at this forgejo instance should be more of looking my work or backup of the published work than anything, so very niche.
PS : loving the runtimewire article concluding “instead of repeatedly charging the humans trying to read the page” when they have this

AYO_Official@lemmy.mlOPto
Self Hosted - Self-hosting your services.@lemmy.ml•Forgejo Scraping Protection: Nginx and Anubis
3·18 days agoThe principle is pretty simple : use a little bit of compute. If you’re a bot and want to visit many sites the cost will add up, if you are a human going to a website the 1 second cost for the initial page is not a big deal.
Also notice the difference with the extremely annoying cloudflare checkbox asking if you are a human that became ubiquitous lately. I’d rather wait a second.
AYO_Official@lemmy.mlOPto
Open Source@lemmy.ml•Forgejo Scraping Protection: Nginx and Anubis
3·19 days agoActually same, this blog is also a nice way for me to document how my server was setup.
I am quiet distro hopping because of ARM based distribution never really working nicely (GPU acceleration, old hardware not being updated). I need to remember what is what and why as my main job is not really taking care of servers but coding.
AYO_Official@lemmy.mlOPto
Open Source@lemmy.ml•Forgejo Scraping Protection: Nginx and Anubis
4·19 days agoFixed, thanks. Sadly url is *** forever.
This seems to be exactly the content of the post: rate limit + Anubis.
The main point is more about “How to setup Anubis” rather than “Should we use Anubis” as I documented how I did my setup so I will not forget and at the same time sharing the resource. I am also using fail2ban but I didn’t feel a post about how to set ip up would be as useful as documentation and guides seems already there.