rejetto forum

Software => HFS ~ HTTP File Server => Bug reports => Topic started by: Rom_1983 on March 21, 2021, 09:56:13 PM

Title: [Solved] Robots are scanning my HFS server
Post by: Rom_1983 on March 21, 2021, 09:56:13 PM
Hi,

These images proves that a robot is actually scanning my HFS server. How can we avoid that ? I know the technic of the robot.txt, but where to place it given that the "/" path isn't a real path ?

(http://www.8651748351.duckdns.org:8000/_public_host/rejetto_forum/2021-03-21_22h54m26s_hfs.jpg)

(http://www.8651748351.duckdns.org:8000/_public_host/rejetto_forum/2021-03-21_22h49m53s_chrome.jpg)
Title: Re: Robots are scanning my HFS server
Post by: Mars on March 21, 2021, 11:47:59 PM
add it as attached file on root, and change its properties to hidden
 (click droit sur route +add file , ou saisir le fichier et le faire glisser sur l'icone de la racine)

un repertoire virtuel n'a pas d'existence physique mais un fichier dans le vfs est comme un raccourci pointant  vers le fichier du disque dur, ca permet de "masquer à l'utilisateur l'emplacement réel du fichier

ne jamais placer un fichier dans le vfs dans un répertoire réel (icone rouge) s'il y a un risque que le même nom de  fichier existe physiquement dans le répertoire
(https://i27.servimg.com/u/f27/16/40/25/39/robot10.png)

Title: Re: Robots are scanning my HFS server
Post by: Rom_1983 on March 22, 2021, 09:55:52 AM
Merci Mars ;)
Title: Re: [Solved] Robots are scanning my HFS server
Post by: danny on March 23, 2021, 06:14:14 AM
I did associate / webroot with a real empty folder.  So, I don't have any virtual folders. 

And as for the Robots/Hacks/Scans, just weekly I review the accesses and use the Ban and the *

You know like 167.248.133.123, that bother from Censys?  Well, I just ban 167.248.133.* to minimize the inconvenience. 

This plan wasn't instantaneous, but it wasn't laborious. 
If anything, upping the ante on the ban ranges has been best for both security and convenience.
In fact, it has been convenient for the miscreants to put their addresses in my logs so that I can increase scope of range blocking on them. . . resulting in a sharp decrease of bother; and, a whopping good bout of better security. 

The robots.txt contains suggestions.  But, suggestions are only good for real people.  However, as for bots, just use force.