Show HN: “HTTP 419 Never Gonna Give You Up” for bots
bradgessler.com
bradgessler.com
For wp-login bots I serve them a nice chunk of random (generated by a fuzzer) html in the hopes that 1. It wastes abit of their bandwidth/memory and 2. it crashes their parser
In reality I guess bots nowadays are sturdy enough to not get stuck or crash but who knows, feels good to do something :-)
Tarpit instructions https://nyman.re/super-simple-ssh-tarpit/
Wp-login page https://twitter.com/gnyman/status/1181652421841436672?s=20
And I remembered another nice trick which someone else came up with, zip bomb the bots :-)
https://blog.haschek.at/2017/how-to-defend-your-website-with...
It won't work on the more sturdy samples, but maybe try a GZIP bomb on https streams: https://www.infosecmatter.com/metasploit-module-library/?mm=...
If you want to be clear, you can put the gzip bomb behind a link that says "do not click, gzip bomb". The bot won't know the difference.
Now... I'd say "there shouldn't be, it's your server, people can chose to access it or not, but if the right kind of fool comes along, there's no knowing where the stupid ends."
Maybe rename the legit login and put this in its place, but that would cause issues for redirects from the legit login link...
Just curious, is it legal to host a zip bomb on your website? I would think it would be classified under some kind of Cyber crime....
Actually, there was a proposal to remove the 418 code formally, but in the end it was grandfathered in. Unfortunately, unless you have convinced a lot of people to allow 419, it would be not allowed anymore (even in a April Fools' RFC) according to the established protocol of IANA controlling the allocation of error codes, and IANA no longer allow "joke" allocations unless there was an RFC clarifying why that particular code must exists in a non-joking manner (see 451, in homage to Fahrenheit 451 but is the recommended code for a informed block). Even 418 was technically only reserved in such a way that allows it to be overridden in case that a good demonstration that 418 should be the code for that error.
As far as a 419 is concerned, I’d argue that 418 is already suitable anyway as a joke alternative to the more serious 429/503: “wp-admin.php? I’m not WordPress, I’m a teapot!” (Similar style to the joke about one cow warning another about the mad cow disease in the area, and the other responding that it’s not not worried because it’s a helicopter.)
The entire raison d’être of such registries is to include any extensions; if you only cared about the core stuff, you wouldn’t define a registry.
HTTP/1.1 527 Railgun Error
Server: Ballistic Research Laboratory - CHECMATE
Date: Fri Oct 29 02:08:03 2021
Connection: Keep-Alive-overridden
Authorization: Rules-Of-Engagement-090624-2021-10-29
Content-Type: uranium/depleted
Content-Weight: 248kT equivalent[1] gopher.conman.org
---
[1] Shameless plug: http://jaruzel.com/gopher/gopher-client-browser-for-windows
That’s what. Deal with it. Build your enclosed cheburashka internets or whatever. I couldn’t care less about hurting their feelings.
You don't need a standardized error code to signal to a red team, you can say "hi" in a number of different ways, depending on what they're poking at. And if everyone is doing the same thing to script kiddies, well, where's the sport in that?
419 Page Expired (Laravel Framework) Used by the Laravel Framework when a CSRF Token is missing or expired.
"Shut The Fuck Up" in my framework.
https://github.com/laravel/framework/blob/a2c557a1b697c46292...
Side efffects may include:
* Helping bot authors improve their bot so it won't be identified.
* Revealing how good you are at detecting bots.
They look the searches you do at Google and other search engines. The search terms and the results you click on gets sent their way, including metadata from the page.
The content itself is downloaded by their bot (more like a fetcher). That bot has the user agent of a regular browser, so you won't see it.
You also can't specifically block their fetcher. It only adheres to disallow *.