ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Unsolved A Small Orange - bandwidth limit exceded

    IT Discussion
    12
    71
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      That suggests it isn't picking up the JavaScript. It's a bot of some sort.

      1 Reply Last reply Reply Quote 0
      • DanpD
        Danp
        last edited by

        Have you looked into WordFence?

        Mike DavisM 1 Reply Last reply Reply Quote 2
        • NashBrydgesN
          NashBrydges
          last edited by

          If they are bots, Wordfence has an option to automatically block "fake Google crawlers" found under Wordfence -> Firewall -> Rate Limiting. Wordfence is free for many of it's features but also offers some premium features for paid option.

          Something else to watch for is, I noticed that Google crawlers were going ape$hit for a while crawling a couple sites I manage to the tune of hundreds of pages per day. That's since calmed down though. Right around the time I submitted a sitemap to Google Search Console.

          Mike DavisM 1 Reply Last reply Reply Quote 0
          • Mike DavisM
            Mike Davis @Danp
            last edited by

            @Danp said in A Small Orange - bandwidth limit exceded:

            Have you looked into WordFence?

            Thanks for the tip. WordFence was the first thing to let me see what's going on. The live view feature let me see the requests and where they are coming from. Mostly it's IPs from all over the world that are trying to pull up admin and register pages that don't exist.

            I let it run for a few hours and it didn't put a dent in the traffic, so I just tweaked some of the settings so that it will start blocking after 20 failed attempts for different things. We'll see how it looks tomorrow.

            1 Reply Last reply Reply Quote 0
            • Mike DavisM
              Mike Davis @NashBrydges
              last edited by

              @NashBrydges said in A Small Orange - bandwidth limit exceded:

              If they are bots, Wordfence has an option to automatically block "fake Google crawlers" found under Wordfence -> Firewall -> Rate Limiting. Wordfence is free for many of it's features but also offers some premium features for paid option.

              They are bots. When I adjust the filter to "humans" it shows no hits. I turned on the "fake google crawler" rule. We'll see what it looks like tomorrow.

              1 Reply Last reply Reply Quote 0
              • Mike DavisM
                Mike Davis
                last edited by

                After 2 minutes I've had to turn off "Alert when an IP address is blocked".

                1 Reply Last reply Reply Quote 2
                • Mike DavisM
                  Mike Davis
                  last edited by

                  Those changes didn't make a dent in the traffic. I set WordFence to block bots after 1 404 error. We'll see what that does.

                  1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    That's so crazy that you are getting SO much traffic.

                    1 Reply Last reply Reply Quote 0
                    • Mike DavisM
                      Mike Davis
                      last edited by

                      I have to wonder if I should just move to a new host or something. I can't explain why they are pounding on my site so hard.

                      1 Reply Last reply Reply Quote 0
                      • Mike DavisM
                        Mike Davis
                        last edited by

                        What are they trying to do when they call the: http://www.domainname.com/?ctl=register page?

                        1 Reply Last reply Reply Quote 0
                        • Mike DavisM
                          Mike Davis
                          last edited by

                          I think I may have figured it out. The site used to be hosted on an IIS box running .net nuke. .net nuke was vulnerable to users registering themselves and creating a link back to their page. (link juice for SEO optimization) It seems that after I moved the site, they are still trying to hack the registration from when the site was on DNN.

                          I just updated wordFence to block on the url "/?ctl=register" and /*/Default.aspx so now it's blocking most attempts.

                          1 Reply Last reply Reply Quote 3
                          • Mike DavisM
                            Mike Davis
                            last edited by

                            CloudFlare is still seeing the same amount of traffic, but ASmallOrange is seeing way less bandwidth. (It's actually reading 0 for the day.) The WordFence live feed is a constant stream of blocked requests.

                            1 Reply Last reply Reply Quote 2
                            • Mike DavisM
                              Mike Davis @IRJ
                              last edited by

                              @IRJ said in A Small Orange - bandwidth limit exceded:

                              https://wordpress.org/support/topic/how-to-change-the-admin-url-or-wp-admin-to-secure-login/?replies=13

                              There are also plenty of FREE plugins that do this with one click.

                              https://wordpress.org/plugins/rename-wp-login/

                              https://wordpress.org/plugins/protect-wp-admin/

                              Wordfence also lets you do this and restrict IPs to the admin page.

                              I'm trying to make this as the solution to the problem. The other tools weren't telling me what was going on because they were showing me what pages were served, not what pages were asked for an unresolved. WordFence was able to show me that spammers were trying to register through .aspx pages that the old .netNuke site used. By banning those pages, my bandwidth consumption has gone down. I'm curious to see how long they have to get 404s before they will stop making requests.

                              JaredBuschJ 1 Reply Last reply Reply Quote 1
                              • jrcJ
                                jrc
                                last edited by

                                Anyone mention web crawlers on here? Indexing servers (like Google) will hit a website over and over again looking for changes to catalog and add to their index.

                                Try adding a robots.txt to the root (http://www.robotstxt.org/robotstxt.html(

                                Mike DavisM scottalanmillerS 2 Replies Last reply Reply Quote 0
                                • Mike DavisM
                                  Mike Davis @jrc
                                  last edited by

                                  @jrc Don't I want the legit robots to hit my site and see that it's not running .netNuke anymore so the script kiddies will leave the site alone?

                                  jrcJ 1 Reply Last reply Reply Quote 0
                                  • jrcJ
                                    jrc @Mike Davis
                                    last edited by

                                    @Mike-Davis

                                    Do you need it findable on search engines? If the answer is no, then I don't think you need it indexed by the robots out there. Unless they do something else that I am not aware of (very possible).

                                    Just remember that when a robot hits your site, it will generate bandwidth, and if you have a lot of them doing so, then you'd generate a lot of bandwidth. I vaguely recall someone else having an issue that was very similar to yours here, and the solution was denying robots access. No idea where I heard about it, may have been on Security Now, though I really am not sure.

                                    1 Reply Last reply Reply Quote 0
                                    • JaredBuschJ
                                      JaredBusch @Mike Davis
                                      last edited by

                                      @Mike-Davis said in A Small Orange - bandwidth limit exceded:

                                      @IRJ said in A Small Orange - bandwidth limit exceded:

                                      https://wordpress.org/support/topic/how-to-change-the-admin-url-or-wp-admin-to-secure-login/?replies=13

                                      There are also plenty of FREE plugins that do this with one click.

                                      https://wordpress.org/plugins/rename-wp-login/

                                      https://wordpress.org/plugins/protect-wp-admin/

                                      Wordfence also lets you do this and restrict IPs to the admin page.

                                      I'm trying to make this as the solution to the problem. The other tools weren't telling me what was going on because they were showing me what pages were served, not what pages were asked for an unresolved. WordFence was able to show me that spammers were trying to register through .aspx pages that the old .netNuke site used. By banning those pages, my bandwidth consumption has gone down. I'm curious to see how long they have to get 404s before they will stop making requests.

                                      Click the menu button below the post and select mark as answer (not visible in this screenshot asn I did not make this topic).

                                      0_1493776878402_upload-4df2723c-35f2-4592-b304-8f7cb7f15c34

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @jrc
                                        last edited by

                                        @jrc said in A Small Orange - bandwidth limit exceded:

                                        Anyone mention web crawlers on here? Indexing servers (like Google) will hit a website over and over again looking for changes to catalog and add to their index.

                                        Try adding a robots.txt to the root (http://www.robotstxt.org/robotstxt.html(

                                        They should not create traffic anything like that.

                                        1 Reply Last reply Reply Quote 1
                                        • 1
                                        • 2
                                        • 3
                                        • 4
                                        • 2 / 4
                                        • First post
                                          Last post