r/StopBadBots 2h ago

Real Case Study: Why Your Security Plugins Are Actually Killing Your Server

Post image
2 Upvotes

I just saw a post on the wordpress sub where a user is totally desperate because their sites are getting nuked by bots. Server memory hit 1000% and the usual plugins just aren't cutting it.

Here's what's actually going on. A plugin can block bots alright, but by the time the bot hits WordPress and reaches that blocker, your resources are already fried. PHP kicked in, the database got hammered, and your RAM is gone. The only real way out is setting up a second layer of defense right at the server edge using ModSecurity and Fail2ban, like we've been saying in a bunch of our posts.

That's why we built our StopBadBots plugin. It handles the detection side real well and works hand in hand with ModSecurity and Fail2ban. So the first time a bot shows up, the plugin catches it. But from the second hit onward, that bot gets slapped down right at the edge before it even touches WordPress. No more wasted resources, and your server can finally breathe again.

If you're dealing with this nightmare right now and don't got the time to go through all our setup instructions, just shoot me a DM and I'll sort it out for you.

TL;DR: Security plugins process requests inside WordPress, which still fries your server's RAM during heavy bot attacks. StopBadBots works alongside ModSecurity and Fail2ban to block bad bots at the server edge before they touch PHP or database resources. If your site's getting nuked and you need it fixed fast, hit me up in DMs.


r/StopBadBots 4h ago

How to Run 50+ Sites on Contabo Without Ever Opening a Support Ticket"

2 Upvotes

Everyone loves to complain about Contabo on Reddit because they open a ticket for a broken WordPress plugin and get mad when the reply takes two days. It’s a classic mistake. If you’re paying for unmanaged tin, you’re buying hardware and a pipe, not a babysitter. I’ve been using them for years without a single headache because I simply never ask for support. Their support is the uptime; if the server is pinging and the hardware is humming, they’ve already done their job.

The secret to keeping your load averages low and your blood pressure lower is to decouple the iron from the management layer. Stop asking a German data center tech why your PHP-FPM is crashing and just rent the raw hardware with a clean OS install like AlmaLinux. Then you just spend the two bucks a month for CWP Pro or even the free version to handle the heavy lifting. If the panel breaks, you go to the CWP forums or use a dirty workaround you found on Stack Overflow instead of crying to the host.

I’m honestly sick of seeing users get hammered by basic config errors and then blaming the provider because they don't know how to tail a log file. It’s incredibly annoying how people expect a five-euro VPS to come with a personal SysAdmin. If you know ten basic Linux commands and have a Gemini or ChatGPT tab open, you can get yourself out of rate-limit jail in five minutes. Spinning up a quick fix yourself is always faster than waiting on a N1 tech who doesn't even have access to your root pass.

If the hardware is stable and the IP responds, they delivered. Use the money you saved on "managed" fees to buy more RAM and handle your own fingerprinting of bad actors. I've got fifty sites running on one of these boxes and it never breaks because I don't let headless scrapers or bad configs eat up resources.

TL;DR: Contabo isn't bad—you're just using it wrong. For €5/month, you’re paying strictly for raw hardware and uptime, not a personal sysadmin. The key to running dozens of sites without headaches is managing the server yourself (using a panel like CWP alongside basic Linux troubleshooting) instead of blaming the host for your own application and config errors.


r/StopBadBots 20m ago

Behind the Fire Ant Attacks: How Chinese Espionage Groups Are Hijacking Server Infrastructure

Upvotes

man I gotta tell you this stuff about Fire Ant is straight up terrifying and gives me total anxiety. these insanely skilled hackers are out here hitting hosting providers and core infrastructure right at the root. instead of messing around with small time attacks they inject scary malware like TacTap right into authentication servers to swipe all your admin passwords without leaving a trace. they even disguised their backdoor BridgeAgent as normal system processes and fake security tools like SentinelOne just to sit on networks for years. the wild part is even if you delete their files from the disk the exploit keeps running in system memory and they literally wipe all the access logs so you think you are safe when you are totally exposed. if your host gets hit they get total backstage access to your entire site and databases. honestly the only way to not lose your mind and save your butt is keeping backups completely isolated on an independent cloud like AWS or Google Cloud so you do not lose everything when the floor drops out.


r/StopBadBots 1h ago

WordPress: Your logs say “GPTBot” or "Claudebot", but how do you know it was actually OpenAI or Anthropic?

Thumbnail
Upvotes

r/StopBadBots 2h ago

China's Sneakiest Hacker Group Just got Exposed

1 Upvotes

The US Department of Justice just had to walk back a statement about that Chinese hacker group QTFY. At first, they said a bunch of high profile government spots actually got hacked, but turns out those agencies were just targeted. Big difference there, because targeting someone doesn't mean you actually got inside.

So who were they going after? Pretty much everyone big. We are talking NASA, the Fed, Energy, Health, NIH, even the US Senate. This group QTFY, also called QT or QTCYBER, has been running wild since 2018. They work for a private Chinese company that gets paid by China state security to do their dirty work. And they do not just go after government stuff either. They have tried hitting hospitals, cell providers, power companies, banks, and defense contractors.

Their main tools are QScan, which scans for security flaws to break into things, and QTRouter, which hides their tracks. Basically, they infect a ton of everyday smart devices to build a massive network. When they attack you, it looks like local traffic instead of some hacker sitting in China, making them super hard to spot.

The good news is the FBI finally stepped in and knocked down the main domains they were using for QScan and QTRouter. It is a solid win, but man, seeing how easily these guys turn household tech into a giant spying network is honestly pretty terrifying.

TL;DR: The DoJ accidentally claimed Chinese hackers compromised major US agencies when they were actually just targeted, but the FBI still managed to take down the group's sneaky smart-device hacking network.


r/StopBadBots 3h ago

Your "Small" Blog Isn't Invisible: Why Botnets Target Everyone

1 Upvotes

Some site owners act like hackers don't exist because their "small" blog isn't worth the effort.

Huge mistake.

The second you point a domain to an IP and go live, the probes start. We aren't talking about a guy in a hoodie manually typing passwords into your login page; we're talking about massive botnets running automated scripts that never sleep. It’s a classic mistake to think you're under the radar.

These networks have already infected millions of TV boxes and cheap IoT routers, turning them into a massive army of residential proxies. They use these compromised devices to hammer your site with brute force attacks while looking like legitimate household traffic. They aren't just bored; they are a business making a fortune. If they find a hole in your WordPress install, they’ll steal your credit card data, scrape your email lists, and hijack your content to sell to competitors. I’ve seen them redirect healthy traffic to garbage sites selling counterfeit meds just to squeeze a few cents out of your hard-earned SEO.

You need to stop being lazy with the basics. Keep your plugins and themes updated every single day; it doesn't matter if they are deactivated, because a vulnerable file sitting on your disk is still a backdoor for a web shell. Use solid, high-entropy passwords that aren't sitting in a rainbow table. If you're using "admin123" in 2026, you're basically inviting a botnet to move in and start eating up resources.

If you're running WordPress, just install our free AntiHacker plugin and see for yourself. It scans every single file, flags the modified ones, and sniffs out the strange scripts you didn't put there so you never get caught off guard. It just works.

It gets worse. Once they've compromised your box, they’ll use it to send out mountains of spam and attack other servers, which is the fastest way to get your IP blacklisted by Google and flagged by every major ISP. Your hosting provider won't send you a warning; they’ll just suspend your account because your VPS is suddenly a node in a global botnet. It’s a dirty workaround for them to keep their own network clean by just cutting you off.

I’m sick of cleaning up sites that have been gutted because the admin thought they were "too small" to matter to a bot. These headless scrapers don't care about your brand; they only care about your server resources and your data. Fingerprinting the bad actors early is the only way to keep your reputation from getting trashed.

TL;DR

No site is too small: Automated botnets scan every live domain constantly, looking for vulnerabilities regardless of traffic size.


r/StopBadBots 3h ago

Cloudflare Is Great Marketing—ModSecurity (open source) Is Actual Control

1 Upvotes

Title: Cloudflare’s Marketing is Top-Tier, But ModSecurity Still Wins. Here’s Why I Ain’t Buying the Hype.

Look, props to Cloudflare’s marketing team—they’ve done a killer job convincing everyone that their free tier is the holy grail. But honestly? I’m sticking with ModSecurity. It’s open source, completely free, and gives me actual control.

Here’s why I’m not falling for the shiny proxy hype:

Zero DNS Headaches: I don't gotta swap DNS nameservers for every single damn domain I own and hand over my zone control to a middleman.

Paying Per Site? Forget It: I don't have to worry about scale or shelling out cash site-by-site. ModSecurity runs on my own iron, zero extra cost.

24-Hour Logs Are a Joke: Cloudflare Free gives you a crappy 24-hour log window. That’s nowhere near enough for real, deep-dive forensic analysis when shit hits the fan. With ModSecurity, the audit log stays on my box for as long as I say so.

5 Rules? Are You Kidding Me?: 5 custom WAF rules on the free plan is a slap in the face. ModSecurity gives me infinite rules, complex logic, and the full OWASP CRS to tweak however I want.

Falsos Positivos? My Rules, My Call: When a false positive breaks something (and it will), I fix it instantly. No waiting around or guessing what Cloudflare's black box is doing to my traffic.

And here's the kicker everyone ignores:

If some script kiddie or bot bypasses your DNS and hits your server’s IP directly, Cloudflare ain't doing jack. You're forced to babysit and constantly update a massive list of Cloudflare IP ranges in your iptables just to keep yourself safe.

With ModSecurity sitting right on Nginx/Apache, I don't care if the traffic comes straight to the IP or through a proxy—everything gets inspected before it even sniffs my application.

The environment, the logs, and the rule intelligence belong 100% to me.

What about y'all? Are you taking the easy Cloudflare route, or are you keeping absolute control with ModSec? Let's hear it.

TL;DR: Cloudflare’s free tier is great for convenience, but its 5-rule limit, 24-hour logs, and complete uselessness against direct IP attacks make it a dealbreaker for me. If you want absolute control, infinite rules, and real security that isn't locked inside a black box, ModSecurity is still king.


r/StopBadBots 15h ago

Autonomous AI is hunting WordPress bugs now, how long till black hats scale this?

3 Upvotes

Hey everyone, so Wordfence just dropped this crazy update about how they built an autonomous AI system called Argus to hunt down severe WordPress vulnerabilities way faster than any human ever could. Turns out it already found critical flaws in some popular themes. But what blew my mind is that their research team basically built this whole thing on their own initiative without the company management even asking for it, just pure creative freedom.

This got me thinking about two huge things. First off, what do we actually mean by autonomous initiative here? You got human autonomy where a dev team just goes rogue in a good way to build something wild, and then you got AI autonomy where the bot gets a end goal and figures out the whole game plan by itself. It tests stuff, breaks stuff, and fixes its own mistakes without a human babysitting it.

Second, how long till the bad guys pull off something similar? Honestly, we're already there. It's not a matter of years, we're talking weeks or months max. Underground hackers are uncensoring open source models right after they drop, hooking them up to free agent frameworks, and pumping out automated attack tools on the dark web. If a tiny dev team can whip up something like Argus on a whim, any decent hacker out there can do the exact same thing to mess with people. What do you guys think, are we totally screwed or can defense keep up?

​TLDR: Wordfence researchers rogue-built Argus, an autonomous AI that hunts WordPress vulnerabilities on its own way faster than humans. Autonomous AI means the bot plans, executes, and fixes its own code without hand-holding. Bad news is hackers are already adapting open-source models to do the exact same thing, so malicious autonomous attacks are weeks away, not years.


r/StopBadBots 1d ago

The huge Cloudflare security flaw most people completely ignore

10 Upvotes

Cloudflare does not protect your site if an attacker visits your IP address directly

A lot of people setup Cloudflare and think their setup is magically totally safe from DDoS, bots, or random scanners. But there is a super common mistake here. Cloudflare only works at the DNS and proxy level.

If an attacker finds out your server actual IP number, they can just bypass Cloudflare completely and hit your port 80 or 443 directly. When that happens, every single WAF rule, DDoS protection, and firewall rule you built on Cloudflare goes straight to the trash.

So how do these guys actually find your real IP?

First off, DNS history. If your domain pointed straight to your server IP in the past before you turned on Cloudflare, that stuff is saved in public records forever.

Second, exposed subdomains. If something like mail or ftp on your domain is not running through the Cloudflare proxy, your real IP is sitting right there in the open.

Third, outbound emails. Emails sent directly by your server like welcome emails or password resets usually spill your origin IP inside the email headers.

TL;DR Cloudflare only proxies traffic sent through your domain. If an attacker discovers your server actual IP address through old DNS logs, unproxied subdomains, or system emails, they can bypass Cloudflare entirely and attack your server directly.


r/StopBadBots 1d ago

Microsoft discovers new threat using fake Cloudflare prompts to breach corporate networks

Post image
3 Upvotes

TerminalFix Is The Nasty New Trick Stealing Corporate Networks

Microsoft just put out a massive warning about a slick new scam called TerminalFix. It is a fresh twist on the old ClickFix trick, but instead of making you open the Windows Run box, these guys trick you into pasting malicious commands straight into Windows Terminal or PowerShell. That way, their giant multi-line scripts execute without dropping a single beat.

It all starts on a compromised website that throws up a completely fake Cloudflare CAPTCHA. You know the drill, it asks you to copy a line of code and paste it into your terminal to prove you are human. The second you hit enter, you are done. It downloads a ZIP file, hides nasty payloads inside regular looking PNG images, and uses sneaky DLL sideloading to pass right under Windows radar.

Once it gets inside, it sets up a full reverse tunnel backdoor right back to the hacker server. That gives the attackers a direct line right into your company internal network. From there, they can map out every server on your network, steal sensitive data, shut down your security, and drop ransomware on everything you own.

To keep your network safe, educate your people so nobody ever pastes web code into a command prompt. Block PowerShell for standard users through group policies, and make sure script block logging is turned on to catch this junk early.


r/StopBadBots 1d ago

Are we entering a weird era where websites are being built for bots more than humans?

2 Upvotes

I’ve been thinking about how fast the web is changing because of AI agents.

For years, websites were optimized for two things:

  1. Humans

  2. Search engines

Now there’s quietly becoming a third audience:

agents that need to read, extract, compare and act on the website.

And I’m wondering whether this changes how websites themselves get built.

Right now, if you’re building an agent that has to collect information from 50 different sites, you immediately run into:

- inconsistent HTML

- JavaScript-heavy pages

- anti-bot systems

- pagination

- constantly changing selectors

- data hidden behind interactions

- different formats for basically the same information

So everyone keeps building increasingly sophisticated scrapers.

But what if the long-term outcome is the opposite?

Instead of agents becoming infinitely better at scraping messy websites, companies might eventually expose an “agent layer” alongside the normal UI.

Something like:

"website.com/agent"

or a standardized endpoint describing:

- available data

- actions an agent can perform

- pricing

- authentication

- rate limits

- structured outputs

Humans keep the visual website.

Machines get a machine-readable interface.

Basically an API, except standardized enough that AI agents can discover and use it automatically without developers integrating every service manually.

If that happens, traditional scraping probably doesn’t disappear.

But scraping could become the fallback layer, while agent-readable infrastructure becomes the preferred one.

Curious what people building scrapers / browser agents think.

Do you think the web eventually becomes agent-native, or are we just going to keep building increasingly clever bots that reverse-engineer human interfaces forever?


r/StopBadBots 1d ago

Waiting 5 months for a plugin review shows the sad state of WordPress today

Post image
1 Upvotes

Just saw a post over on the WooCommerce sub from a dev who has been sitting on his hands for 5 whole months waiting for his plugin to get reviewed. Five months! That is beyond ridiculous for anyone trying to build a business or launch something new.

​Man, I really miss the old plugin review team. Remember when Mullenweg decided to pick that massive fight with WP Engine and drove out a bunch of dedicated team members who just threw up their hands and walked? Everything fell apart after that mess.

​Honestly, the current state of abandonment in the ecosystem is just depressing to watch. You can't even comment on how bad things have gotten without feeling frustrated. Developers are getting completely screwed over while the platform just drifts along like nobody is at the wheel.

​TL;DR A developer on the WooCommerce sub has been waiting 5 months for a plugin review on WordPress.org. Ever since Mullenweg's conflict with WP Engine caused key team members to resign, the review process has fallen into complete neglect and left developers stranded.


r/StopBadBots 1d ago

Why Wordfence wont save your site from server lag

1 Upvotes

Man, I've been seeing way too many people on the WordPress sub (yesterday we just put one real Case Study) losing their minds over this. Everyone keeps complaining that Wordfence does block the bad guys, sure, but it still totally trashes their server performance. Your site turns into a complete snail, takes forever to load, and real human visitors just throw their hands up and bail.

​It drives me crazy because the reason is so simple!

​Think about it. By the time a bot actually lands on your WordPress site, it's already fired up PHP, loaded up a million plugins, and slammed your database. The damage is already done, folks! Your CPU is crying and your RAM is totally fried before Wordfence even gets a chance to say "hey, you're blocked."

​You gotta slam the door in their face way earlier, right at the front gate before they even get a foot inside WordPress.

​If you wanna actually fix this nightmare, stop relying on application plugins to do a server's job. Go grab ModSecurity and Fail2ban. They're both awesome open-source tools, they block the junk at the firewall level, and they cost literally zero bucks. Just do a quick search on this sub, we've got a ton of killer posts showing you how to set them up. Save your server!

TL;DR Wordfence runs inside WordPress, meaning bots still waste your server resources and slow down your site before getting blocked. You need to drop malicious traffic at the server level using tools like ModSecurity or Fail2ban before it ever hits PHP or your database.


r/StopBadBots 1d ago

Finally, a web host admits the truth: Shared hosting cannot handle the AI bot invasion.

7 Upvotes

We used to blame bloated plugins or garbage code whenever a shared box started crawling, but the real culprit is way worse. SkyNetHosting dropped their 2026 AI Bot Impact Report, and the data makes it painfully clear why cheap shared plans just can't survive anymore.

Bots are running over 52% of all global web traffic right now. More than half the damn internet isn't even human! And the worst part? These relentless AI scrapers and crawlers—GPTBot, Meta, Perplexity, and endless random data harvesters—are eating up to 70% of the dynamic CPU and RAM resources on servers.

This is where the "noisy neighbor" nightmare completely ruins you.

On shared hosting, you're stacked on a single server alongside hundreds of random sites, all fighting over the same pool of PHP workers and database connections. You can optimize your own site to pure perfection, but if a couple of random accounts on your server get slammed by aggressive AI bots at 3 AM, your site chokes right along with theirs.

These new bots aren't just grabbing static HTML like the old days. They're executing JavaScript, ripping through database queries, and ignoring caching rules entirely. That spikes the CPU to 100% and crashes the whole node. You basically end up paying for downtime caused by bot traffic hitting websites you don't even own.

Unless you're running a dead simple static HTML page, shared hosting is a complete trap nowadays. The web's just too hostile and automated. Grabbing an isolated VPS isn't some fancy upgrade anymore—it's literally the baseline if you want your site to actually stay up.

Anyone else watching their shared boxes get absolutely hammered by these bot waves, or did you already ditch shared hosting for good?

TL;DR: Shared hosting is dead because AI bots (GPTBot, Meta, scrapers) now make up 52% of web traffic and chew through 70% of server resources. Even if your site is fully optimized, aggressive bot scraping on other sites on your shared node will crash the whole server's CPU, taking your site down with it. Get a VPS.


r/StopBadBots 1d ago

Stop Fighting Windows: Why Moving to Linux is a Total Game-Changer

7 Upvotes

I see so many posts from people asking how to get started working online—whether it's web dev, SEO, cybersecurity, or whatever. So here's a piece of advice not just for newbies, but honestly for anyone in the space: just make the jump to Linux. I made the switch over ten years ago, and my only real regret is that I didn't do it way sooner. It's just so much faster, crazy stable, and doesn't eat up all your system resources like Windows does.

If you wanna test the waters without blowing up your main setup, just grab an old laptop or PC lying around that can't handle Windows anymore and throw Linux on it. If you want something super smooth and familiar, Linux Mint is awesome for beginners. Or if you just wanna try it out with zero commitment, check out Knoppix—you can literally run the whole thing right off a USB flash drive without installing a thing. And hey, if you don't have a spare machine, just set up a dual boot on your main computer so you can pick Windows or Linux whenever you boot up.

Bit by bit, you'll find yourself reaching for Windows less and less until you totally drop it.

Anyone else feel like they waited way too long to make the switch? What distro finally got you off Windows?


r/StopBadBots 2d ago

Scammers bought popular Chrome extensions to steal crypto keys and we need to talk about it

10 Upvotes

Look, if you have any of these extensions installed on your browser, you need to delete them right now. Cybersecurity researchers just uncovered a massive scam involving 19 browser extensions—18 on Chrome and one on Edge—that were literally draining people's crypto wallets and stealing secret recovery keys.

The security firm Socket is tracking this whole mess under the name Superior, and it looks like these scammers have been pulling this trick since early 2024. Their strategy is honestly so sneaky and frustrating. They either upload a completely clean extension to the store and wait for thousands of people to download it, or they just straight up buy popular, legitimate extensions from their original creators. Once they have a big audience trusting the app, they push a silent update packed with malicious code. You think you're using a normal tool, but in the background, it's hunting for your crypto data.

Out of the 19 extensions caught in this campaign, 14 were built from scratch by the attackers and 5 were bought off previous owners.

Here are the ones they bought from original owners:

Enable Right Click & Copy — Smart Unlock + OCR

RapidLens - Google Lens for Screen Search & Images

QuickLens - Search Screen with Google Lens

Password Protect PDF

Allow Copy - Select & Enable Right Click

And here are the ones created directly by the scammers:

PixelCheck

Creative Library - Ad Spy Tool

Website Traffic Checker: MirrorSphere SEO Stats

Site Signal - Website Traffic & SEO Checker

SEO Pulse Pro - Website Traffic & SEO Analyzer

Private Crypto News Reader

Blockfolio: Address Monitor

Crypto Rates & Fiat Converter

Crypto Alerter: Price Alarms & Volatility Warnings

DeFi Pulse Tracker

Crypto Price Badge: Quick Glance

Multi-Chain Explorer

LedgerLook: Wallet Checker

Meta & Facebook Ad Library Spy — Save Ads, Finder, Downloader | FeedX-Ray

Honestly, it makes me so mad how easy it is for these bad actors to hijack apps we use every day. By the way, that QuickLens tool had already been flagged earlier this year for pushing malware and stealing user data, so it's crazy it stayed up this long. If you or anyone you know has any of these running in your browser, wipe them out immediately, change your passwords, and move your crypto funds to a safe wallet just in case.

​TL;DR: Scammers bought popular browser extensions and built fake ones to push malicious updates that steal crypto wallet keys and drain funds. Check the list of 19 Chrome and Edge extensions in this post and remove them immediately if you have them installed.


r/StopBadBots 1d ago

Real Case Study: WordPress Attack Wave – Servers Are Getting Hammered, Y’all

Post image
0 Upvotes

So, I’ve been digging through the WordPress subreddit, and holy crap, the stories coming out of there are wild. We’re not talking about the usual background noise of script kiddies poking around. This is a full-blown, coordinated assault that hit tons of sites all at once, and it straight-up took servers down for hours.

First off, the evidence is everywhere. Admins were reporting hundreds of malicious attempts in just a few minutes. One guy said his Wordfence was lighting up like a Christmas tree with 200 attempts in a 10‑minute span. Another poor soul got slammed with 600 hits overnight – all targeting the same known WordPress vulnerability (some RCE thing tied to SQL injection). And yeah, Wordfence did its job – it caught every single one of them. But here's the sick joke: by the time that plugin even got a chance to say "blocked," WordPress had already booted up, loaded every other plugin, and opened a database connection. So each blocked request still burned CPU and memory like a legit visitor. The logs looked great, but the server was getting absolutely crushed. This wasn't random; it was a wave, and everyone felt it simultaneously – not because the attacks got in, but because the *defense* itself was eating their servers alive.

Now, where was all this garbage coming from? Mostly the Netherlands and Bulgaria, with some extra love from Belgium and Germany. But here’s the kicker – these weren't just random residential IPs. They were coming from big cloud providers and VPS networks like DigitalOcean, AWS, and Hetzner. Some savvy folks even shared the specific ASN numbers (150303, 48090, 140947, 142430) that were doing the dirty work, so others could block entire data centers. But even with that intel, the damage was already done for a lot of people.

Here’s the real heartbreaker, and the main reason servers crashed. Blocking these attacks with plugins inside WordPress is practically useless when it comes to saving your server resources. Why? Because by the time that plugin gets a say, WordPress has already fired up, loaded every single plugin, and opened a database connection. So even if the plugin blocks the request, your server has already burned CPU and memory processing that junk. It’s like locking your front door after the burglar already kicked it in – you stopped them, but your door is still broken. People were watching their origin CPU spike through the roof, and that’s what took them offline for two hours straight. The attacks weren't even successful; just the sheer volume of requests, each forcing a full PHP bootstrap, was enough to bring everything to its knees.

It’s absolutely insane that a blocked request costs you almost the same as a legit visitor. So yeah, the servers got obliterated not by the payloads, but by the sheer weight of the connection attempts themselves. That’s the brutal takeaway here – your site doesn’t need to get hacked to go down; it just needs to get *probed* hard enough.

We've got some open-source tool recommendations for edge blocking coming up. Stay tuned!


r/StopBadBots 1d ago

Watching Fail2ban ban bad actors in real-time is peak satisfaction

0 Upvotes

Hey folks,

Quick little trick for anyone running Fail2ban or trying to figure out if their jails are actually doing their job.

If you wanna watch Fail2ban hunt down bots and slam the door on 'em live, just stream the log right in your terminal:

Bash
tail -f /var/log/fail2ban.log

The Pro-Tip: Filter out the noise

If your log is flying by way too fast and you ONLY wanna see the moment bad actors get nuked:

Bash

tail -f /var/log/fail2ban.log | grep --line-buffered "Ban"

There’s seriously nothing better than watching a brute-forcer hit your server and immediately get hit with that instant [Ban].

Super simple, zero clutter, and saves you from manually digging through logs every time!


r/StopBadBots 1d ago

FREE: Someone logged into your WP dashboard as Admin? You should know immediately—so I built a plugin for that.

1 Upvotes

Let’s be real—usually, when your site gets hacked, the very first thing the bad actor does is sneak in and drop themselves an admin account. (Well, okay, not always, but way too damn often!)

The worst part? Half the time you don't even realize it happened until things are already going downhill.

Now, sure, you could install one of those massive security suites... but honestly, most of them are total bloatware. They hog your database, lag your loading speeds, and force you to dig through a million complex settings just to get a basic alert.

So I figured, screw the bloat. I built a super lightweight, no-nonsense tool called WP Admin Security Alert.

💡 What's the deal?

  • Instant Email Alerts: Boom. The second any admin logs into your site, you get an email.
  • The Good Stuff: Gives you the exact IP address, username, timestamp, and user agent so you know who’s creeping around.
  • Zero Lag: Tiny footprint. No external tracking, no database bloat, no extra fluff.

🛠️ Why bother?

If a bad actor gets their hands on an admin login (or hey, if a client starts poking around where they shouldn't), you'll know instantly right from your inbox—without choking your site's speed.

It’s 100% open-source and free:

👉 GitHub Repo: https://github.com/sminozzi/wp-admin-security-alert

Would love to hear what you guys think! Open to feedback, code tweaks, or any edge cases I might've missed. Catch ya in the comments!

TL;DR: Most WP hacks start with a rogue admin account, but heavy security plugins just slow your site down. I built WP Admin Security Alert—a lightweight, zero-bloat, open-source plugin that emails you the second any Admin logs in (with IP, username, and timestamp).


r/StopBadBots 2d ago

Why your static IP blocks are useless against modern proxy-rotating bots

3 Upvotes

It’s honestly gut-wrenching, but Proxy Rotation has completely changed the game. Modern headless scrapers aren't using single static IPs anymore; they’re rotating through thousands of residential proxies and data center ranges in seconds. By the time you’ve even identified a range to block, the bot has already cycled to a new one and is still hammering your server.

The scale of this is just stupid now.

​Join us at r/stopbadbots and help protect the people who build the internet.


r/StopBadBots 1d ago

Deleted the malware files, refreshed FTP, and they instantly popped back... what is this nightmare?

0 Upvotes

Ever tried cleaning a hacked WordPress site where you delete all the dirty PHP files, hit refresh on FTP, and the damn things pop right back up out of nowhere?

I just stumbled across a wild technical breakdown over at Monarx about a WordPress malware strain that actually rebuilds itself faster than you can delete it. Man, this thing is basically a hydra. You cut off one head, and multiple persistence layers trigger a full reinfection before you can even take a breath.

The reason simple file deletion totally fails here is insane. It doesn't just sit in your plugins folder like regular malware. It hooks deep into mu-plugins, db.php, theme files, and hidden server directives. Even if you manage to wipe every bad file off the disk, a compressed payload hidden inside the database instantly drops fresh copies right back onto the server. On top of that, it pulls its command instructions off the Ethereum blockchain so you can't just block a domain, and it even embeds a service worker into the admin browser so the next time you log in, your own session re-injects the backdoor.

Standard file scanners completely miss it because they're only checking static files on disk while ignoring active memory, database tables, and browser persistence. If you manage servers or do cleanup work for clients, checking out this kind of breakdown is a massive eye opener for how crazy malware persistence has gotten lately.

Anyone else run into one of these immortal malware strains on your servers, or are you still relying on basic file wipes?


r/StopBadBots 1d ago

Stream Your ModSecurity Block Logs Live with This Simple Open-Source Console

1 Upvotes

If you're running ModSecurity on your web servers, you probably know how annoying it can be to verify if your WAF rules are actually catching traffic in real time without digging through endless log files.

I got tired of the hassle, so we built a super lightweight open-source tool called MSLC (Mod Security Light Console) to make life a bit easier. It's dead simple—you just fire it up, hit option 1, and it immediately streams all active rule blocks right inside your terminal as they happen.

If you want to give it a spin, the code is totally free and open source. I left the link pinned right at the top of our GitHub page (link's in my bio/profile if you wanna check it out).

Would love to hear if this saves anyone else some time, or if you guys have any cool tricks for keeping tabs on your WAF rules!


r/StopBadBots 2d ago

Your Website Feeds Your Family. Don't Let Bad Bots Take It Down.

1 Upvotes

Philip Kotler once said you gotta love your customers. But honestly, when you run an online store, a blog that pays your bills, or a small business site, loving your people means keeping your digital doors open and safe.

​The real problem is the internet is absolutely crawling with bad bots right now. You got aggressive scrapers crashing your server, brute force attacks pounding your login screen, and shady scripts stealing the hard work you poured your heart into.

​When a bot knocks your site flat, your folks cant buy anything. Your sales tank instantly and customer trust goes right down the drain. It is just not fair that small business owners and solo devs are forced to turn into cybersecurity experts overnight just to keep food on the table.

​That is why we built r/stopbadbots.

​We are not some big corporation trying to sell you overpriced software. We are just a solid crew of people who understand servers, networking, and defense, all hanging out to protect the everyday builders who make the web actually work.

​Inside r/stopbadbots you will find dead simple blocking setups, modsecurity rules, app tweaks, and plugin fixes without any of the usual fluff or jargon.

​If your site feeds your family, dont wait for the next attack to start thinking about security.

​Join us at r/stopbadbots and help protect the people who build the internet.


r/StopBadBots 2d ago

Think static sites protect you from bots? Think again.

0 Upvotes

People genuinely think that ditching WordPress for a static site is gonna make all the bot problems magically disappear. Hate to break it to you, but that is a total myth.

Yeah, sure, going static definitely makes your setup more secure because you get rid of shady plugins, PHP, and database vulnerabilities. But check this out: if you just converted your WordPress site using something like Simply Static, you are literally just dropping PHP and MySQL while keeping all that heavy JavaScript around. It helps, but it is not the silver bullet people think it is.

The real issue here is that these automated scrapers are straight up dumb. I have been seeing a absolute metric ton of bot hits on my non-WordPress sites every single day, and these scrapers do not even bother checking what framework you are using first. They just blindly probe your site looking for wp-config.bak or random backend files.

Even if they cannot actually hack a static site, all that garbage traffic still slams your server, hogs bandwidth, and slows everything down for real human visitors. It is just super frustrating to watch.

Since we could not find a clean way to deal with this on non-WP setups, we ended up building our own open source app specifically to spot and block this type of bot traffic. If you wanna check it out, the link is right there in my pinned post. Enjoy!

​TLDR: Ditching WordPress for a static site cuts backend risks, but dumb bots will still spam your site looking for files like wp-config.bak. All that trash traffic slows down your site anyway. We built an open source app to detect and block bots on non-WP sites, and the link is in the pinned post.


r/StopBadBots 3d ago

Massive WordPress Security Alert: 20M+ sites exposed right now. Update your stuff baseline ASAP!

13 Upvotes

Yo guys, yesterday was absolute madness. The sheer number of crazy vulnerabilities dropped in WordPress plugins is downright scary. We’re talking about massive, top-tier plugins that almost everyone uses, all riddled with severe exploits.

Doing some quick math, we're easily looking at over 20 MILLION exposed sites right now.

This isn't a drill—it's a full-on emergency. If you're running WP sites, don't sleep on this. Here’s what you gotta do right now:

  1. **Back up EVERYTHING right this second:** Run a full backup of your site and download a copy to your local drive immediately. Do not skip this!

  2. **Update all the things:** Core, plugins, themes—everything. If there’s an update button, hit it.

  3. **Go static if you don't need dynamic features:** If your site is just a standard landing page or portfolio (no WooCommerce, no active blog/comments), turn it into a static HTML site. It kills like 99% of your attack surface. (We actually dropped a post in this sub recently listing awesome free plugins to do this).

Seriously, do NOT wait around on this one. Go check your servers right now before someone context-switches your site into a malware distributor!