Answer the question
In order to leave comments, you need to log in
How to protect the site from attacking SMS request?
The site can be said "ddosyat". Registration is confirmed by phone number. So. Attackers endlessly request SMS. Our balance on the SMS sending gateways is over. Requests come from different IP, user-agent.
How to protect yourself from such an attack? How are other sites protected?
Answer the question
In order to leave comments, you need to log in
1. After confirming the mail, sending EVERYONE! request to receive SMS through a new captcha task .
2. The interval between the possibility of SMS requests is 5,10,15,30,60 minutes and then blocking the account.
A simple and free replacement for CloudeFlare against most types of attacks: here .
Ask the user to send a message to our virtual number with the code that was displayed on the screen. This is the main way to fight.Struggle against conversion, for which own forces and means are spent. Competitors will say: "THANK YOU SO MUCH!"
I want to open my own DDoS protection serviceTOALL: if anyone is ready to help the author of the question - Welcome!
The easiest thing is to connect CloudFlare and enable aggressive mode.
CF checks if the user is a bot.
There have already been enough options offered, but
as an option , dial the user's phone number (naturally, the pool of numbers should be sufficient),
reset after a few seconds and ask the user to enter the last four digits from the calling number.
Natural captcha and increasing delay between calls
Are the numbers real? When sending SMS, are they checked for existence by your gateway?
Well, as an option, change the strategy from "we will send you an SMS" to "send an SMS to our number", then we will register it.
Or maybe go the other way?
Set up two-factor authentication? And you can opt out of SMS.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question