As an aside, I’ve fought credential stuffers by returning real looking but actually false data, and initiating password resets... start serving different data on each hit, you may need to be annoying enough that they give up.
As an aside, I’ve fought credential stuffers by returning real looking but actually false data, and initiating password resets... start serving different data on each hit, you may need to be annoying enough that they give up.
Problem is - right now I'm over 250 (new) IPs and they keep piling up (their domains now rarely use an IP more than once).
I may have to block entire ranges of IPs or whole ASNs.
Then, setup a script on your laptop or whatever to search this string on their domains every half hour or so.
It even prepares the expression snippet for me to paste directly into a CloudFlare firewall rule.
That's how I got to quickly identify and ban almost 2000 different IPs.
If they continue to expand the IP pool I may need to automate it though.