Every server with port 80/443 open has thousands of hits a day from random boxes looking for wordpress login pages. The only new thing is that they're pretending to be a different type of annoying bot. There's a new layer of sophistication and subterfuge, but it's the same junk traffic we've always dealt with.
Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
21–30 of 239 posts
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#22Earlier quoted context omitted.
Definitely, the point here though is there is a stat sig surge in the chart in the last week, across thousands of websites. At least a surge in this particular spoofing pattern.
It's still not really anything special. Thousands isn't even large scale. Any random bozo can trigger that.
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#23On average about 100 (TCP) requests hit my home router per minute doing various probing and scanning. Lots of checking for the telnet port obviously. Sometimes you can see a swarm of entirely different IPs scanning the full port range (probing the ports one-by-one). You'll see a lot of deepfield, censys-scanner, visionheight.com, shadowserver.io, etc., but also the usual suspects of Chinese or Russian IPs. With OpenW…
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#24Earlier quoted context omitted.
Another interesting thing here is the paths they're targeting, many are for newish AI coding tools
People or their agents must be accidentally committing or publishing their repository level secrets and configs with enough regularity that it’s worth scanning.
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#25Every server with port 80/443 open has thousands of hits a day from random boxes looking for wordpress login pages. The only new thing is that they're pretending to be a different type of annoying bot. There's a new layer of sophistication and subterfuge, but it's the same junk traffic we've always dealt with.
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#26Many of those user-agents listed are often faked. Look up which ASN owns their IP. If I block most VPS providers most of the faked bots vanish. There are still some running from residential and phones using hijacked code (readers that are not really just readers but really multipurpose proxies) . On that note, do not trust the linked source code but rather decompile the live code your phone is running and have AI ana…
Same for the origin IP address. The fiber leaving your country is tapped, and those people can inject packets with any origin IP that they want. Your ISP has no way to check if their peer actually received a certain packet from a certain country or not. From a technical perspective, all this "china/russia" attribution is built on a quite shaky foundation. As a sysadmin you'd never know if it would be the British crow…
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#27Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#28Someone is always running mass vulnerability scans. That's a "water is wet" state of the Internet.
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#29Someone is always running mass vulnerability scans. That's a "water is wet" state of the Internet.
I think this is more of a "if you left your AI tools exposed someone is looking for them" change. Hacking someone else's agents sounds like a great way to spend less on your own tokens.
Re: Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
#30Earlier quoted context omitted.
Is there an easy way to block any requests originating from VPS etc instead of residential/commercial IP from legitimate users ? I know cloudflare does a few things but I really want to figure out a way to block any request say at nginx or caddy (reverse proxy) from reaching origin servers if they are not from an IP that is not a VPS etc.
Yes but it’s not cheap. Maxmind and ipinfo etc sell a tier that tells you this information, then you can 403 based on it. But the price is nuts like $40,000 a year.