Bot check on connect

Discussion of all aspects of the website, wiki, and forums, including assistance requests and new ideas for them.

Moderator: Forum Moderators

Post Reply
JMichael
Posts: 49
Joined: February 19th, 2013, 4:25 am

Bot check on connect

Post by JMichael »

When I came to the site today I got an infuriating "Hold on a minute while I check to make sure you're not a Bot".

I don't see Cloudflare mentioned in the URL. (Cloudflare is where I usually encounter the "Please wait while we check the security of your connection", which I consider equally idiotic, and cause for me to find another web site to visit.)

Is this a new addition to the forum web site? Is it a choice of you web host?
User avatar
Pentarctagon
Project Manager
Posts: 5730
Joined: March 22nd, 2009, 10:50 pm
Location: Earth (occasionally)

Re: Bot check on connect

Post by Pentarctagon »

We've been getting effectively DDoSed recently by what look like AI scraper bots, so we're trying the Anubis software to mitigate it.
99 little bugs in the code, 99 little bugs
take one down, patch it around
-2,147,483,648 little bugs in the code
User avatar
Spannerbag
Posts: 759
Joined: December 18th, 2016, 6:14 pm
Location: Yes

Re: Bot check on connect

Post by Spannerbag »

Pentarctagon wrote: May 18th, 2025, 7:47 pm We've been getting effectively DDoSed recently by what look like AI scraper bots, so we're trying the Anubis software to mitigate it.
Ah, that explains recent forum server slowness!
Sorry to hear that, FWIW I had an anxious few minutes when I was bot tested, found wanting and banned:
You have been banned from this board until May 26th, 2025, 7:36 am.

Please contact the Board Administrator for more information.

Reason given for ban: IP address used for spamming

A ban has been issued on your IP address.
So I rebooted, obtained a different dynamic public IP and everything worked fine. :)
Trouble is, the bots might do the same...

However prior to rebooting I did try to email the web address for Board Administrator (forums@wesnoth.org) and this was bounced twice, both times message was:
Address not found
Your message wasn't delivered to forums@wesnoth.org because the address couldn't be found or is unable to receive email.

The response from the remote server was:
550 Unroutable address
Only emailed using the old (banned) public ip address.
If I'm banned again, is there any information from me that would help?

Good luck with Anubis.

Cheers,
-- Spannerbag
SP Campaigns: After EI (v1.14) Leafsea Burning (v1.18, v1.16)
I suspect the universe is simpler than we think and stranger than we can know.
Also, I fear that beyond a certain point more intelligence does not necessarily benefit a species...
User avatar
Ravana
Forum Moderator
Posts: 3313
Joined: January 29th, 2012, 12:49 am
Location: Estonia
Contact:

Re: Bot check on connect

Post by Ravana »

I accidentally banned anubis, not the spammer. So everyone was banned.
gnombat
Posts: 892
Joined: June 10th, 2010, 8:49 pm

Re: Bot check on connect

Post by gnombat »

Note that forums.wesnoth.org, units.wesnoth.org, addons.wesnoth.org, and wiki.wesnoth.org all load resources (.css files, .js files, etc.) from www.wesnoth.org.

It seems that if you visit one of those subdomains without first visiting www.wesnoth.org, you end up with a semi-broken page because it fails to load resources from www.wesnoth.org (presumably because you are missing some required Anubis cookie for www.wesnoth.org).
User avatar
loonycyborg
Windows Packager
Posts: 299
Joined: April 1st, 2008, 4:45 pm
Location: Russia/Moscow

Re: Bot check on connect

Post by loonycyborg »

Is it possible to make them load resources from matching domains?
"meh." - zookeeper
gnombat
Posts: 892
Joined: June 10th, 2010, 8:49 pm

Re: Bot check on connect

Post by gnombat »

loonycyborg wrote: May 19th, 2025, 10:43 pm Is it possible to make them load resources from matching domains?
That's one way to fix the issue.

Alternatively, you could serve resources from a subdomain like files.wesnoth.org which is (I think?) not protected by Anubis. (Of course, if files.wesnoth.org is not protected by Anubis then it is theoretically vulnerable to getting DDoS'ed, but if it is just serving a few static files that seems unlikely.)
User avatar
loonycyborg
Windows Packager
Posts: 299
Joined: April 1st, 2008, 4:45 pm
Location: Russia/Moscow

Re: Bot check on connect

Post by loonycyborg »

I made an exception in anubis bot policy to allow without challenge all paths with /wesmere/.*
"meh." - zookeeper
User avatar
Saizo-Luz
Posts: 83
Joined: June 14th, 2024, 12:50 pm
Location: High Heavens

Re: Bot check on connect

Post by Saizo-Luz »

The site has been very slow since then... :(
Post Reply