←back to thread

253 points akyuu | 1 comments | | HN request time: 0s | source
Show context
firefoxd ◴[] No.45946355[source]
I have been using zipbombs and they were effective to some extent. Then I had the smart idea to write about it on HN [0]. The result was a flood of new types of bots that overwhelmed my $6 server. For ~100k daily request, it wasn't sustainable to serve 1 to 10MB payloads.

I've updated my heuristic to only serve the worst offenders, and created honeypots to collect ips and repond with 403s. After a few months, and some other spam tricks I'll keep to myself this time, my traffic is back to something reasonable again.

[0]: https://news.ycombinator.com/item?id=43826798

replies(1): >>45946751 #
1. tetris11 ◴[] No.45946751[source]
There's likely a large market for this kind of thing. Maybe time to spin out a side business and deploy your heuristics to struggling IPs.

Though I have to admit I dont know who your target audience would be. Self-hosting orgs don't tend to be flush with cash