1 hour ago · Tech · hide · 0 comments

I run my own analytics on this site. It's straightforward, collects as little as possible and gives me some basic counts, referral info and a list of 404s to (potentially) fix. Server-side analytics are noisy, so most of this is reported from a simple client-side script. What is surfaced from the server requests are 404s. I use these to find links I've broken, near-miss paths and anything else I might want to tidy up. The annoying part of tracking 404s this way is that the panel fills up with fuzzers doing stupid fuzzer things. This was, for a time, manageable by manually excluding these URLs. That worked until recently, when someone flooded it with SQL injection attempts. None worked, but there were a lot of them. The person driving them may benefit from a hobby. Read a book, go to the park, get into pickleball—I'm sure there are plenty of options. This site is served using Caddy, so I've added a path_regexp to match SQL syntax and drop those connections. Some requests were dumping…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.