Answer the question
In order to leave comments, you need to log in
How to protect your site from bots and hacks?
Hello. Help with a task.
There is a site where users can post ads for the sale of their goods.
We want to make it possible for them to publish without registration and authorization .
How to protect the site from spam and all kinds of attacks? Let's say we use recaptcha and track a large number of requests per minute. If a user makes more than 100 posts per minute, we block it. Is this enough or am I missing something? Thanks for the detailed answer.
Answer the question
In order to leave comments, you need to log in
1. You can do it: captcha + local ID=login+pass+random+timestamp with storage in datastorage (it can be created at any time even without user participation).
But moments arise: the phone is without confirmation => the phone will be indicated by someone else just so that someone is constantly spammed with calls => the site will be closed quickly due to complaints.
2. About the rest, in terms of security, this is setting up firewall rules and web server rules.
Without registration, this is shit and not a client. Sorry for the vocabulary. The woodpecker is not a client at all. Spamer is also not a client. And in the end you will weed out 80%
We want to make it possible for them to publish without registration and authorization.
If a user makes more than 100 posts per minute, we block it. Is this enough or am I missing something?
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question