this post was submitted on 30 Mar 2026
78 points (92.4% liked)
Technology
83295 readers
4508 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
No wonder why some sites started to lag so hard in recent months.
Yeah my favorite electronics hobby supplies website has started to take 2-10 seconds to load. Still great service and the best selection of modules in my region though. They should really throw Anubis in front of it.
Besides Anubis, is there any other tool that might work here?
I know about fail2ban and rate limiting configurations on Nginx level etc. But I mean, yes we have Anubis.. But aside of Anubis??
CrowdSec could probably catch a moderate amount of them, but that is really geared towards bad actors and malicious probing bots.
Fial2ban also wouldn't work at all here since they aren't trying brute force attacks, they are just using high bandwidth stealing as much public data from everything possible.
I think cloudflare is also making an alternative (or has already), but it is a tough problem.
Thanks! I use OPNsense, I do already have set several block lists actually like FireHOL 1,2,3 and 4.
I found the community plugin called
os-crowdsec. I will try it set it up: https://docs.crowdsec.net/docs/next/getting_started/install_crowdsec_opnsense/I want to avoid Cloudflare :).. And yes I know fail2ban will not catch these kind of AI bots or DDos attacks. Even if its a brute force attack, most bad actors are using a botnet with 100.000's of unique IPs.. Fail2ban would be no help either in that case.
EDIT: I also found another block list: https://threathive.net/. Which updates every 15 min. This one is great I think as well. So the list would be: https://threathive.net/hiveblocklist.txt