|
|
|
|
|
by markhowe
1956 days ago
|
|
Setup a honeypot page to log the ‘users’ IP. Keep hitting it via their domain and you’ll build up a list of IP’s to block? As an aside, I’ve fought credential stuffers by returning real looking but actually false data, and initiating password resets... start serving different data on each hit, you may need to be annoying enough that they give up. |
|
Problem is - right now I'm over 250 (new) IPs and they keep piling up (their domains now rarely use an IP more than once).
I may have to block entire ranges of IPs or whole ASNs.