This is officially getting ridiculous. Not only are my blogs getting a lot of comment spam, but my personal blog site is burning huge amounts of bandwidth, as particular (I assume zombie) hosts hit the site.
Below are the top ten bandwidth users of danielbowen.com for June:
Top 10 of 15312 Total Sites By KBytes | |||||||||
---|---|---|---|---|---|---|---|---|---|
# | Hits | Files | KBytes | Visits | Hostname | ||||
1 | 14380 | 4.10% | 3801 | 1.77% | 111235 | 2.22% | 159 | 0.24% | host-148-244-150-58.block.alestra.net.mx |
2 | 17558 | 5.01% | 3191 | 1.48% | 99441 | 1.98% | 157 | 0.24% | host-207-248-240-119.block.alestra.net.mx |
3 | 3927 | 1.12% | 3640 | 1.69% | 75989 | 1.51% | 3 | 0.00% | csr010.goo.ne.jp |
4 | 3062 | 0.87% | 2797 | 1.30% | 74881 | 1.49% | 171 | 0.26% | rrcs-24-97-174-130.nys.biz.rr.com |
5 | 3057 | 0.87% | 2200 | 1.02% | 62547 | 1.25% | 392 | 0.60% | msnbot.msn.com |
6 | 2691 | 0.77% | 2248 | 1.04% | 60684 | 1.21% | 153 | 0.23% | 64.124.85.78.become.com |
7 | 2256 | 0.64% | 2082 | 0.97% | 56383 | 1.12% | 124 | 0.19% | 98-101-196-200.linkexpress.com.br |
8 | 2146 | 0.61% | 2033 | 0.94% | 51665 | 1.03% | 279 | 0.43% | dsl-250-198.monet.no |
9 | 2001 | 0.57% | 1755 | 0.82% | 47605 | 0.95% | 23 | 0.04% | host133.sprintnetops.net |
10 | 1686 | 0.48% | 1571 | 0.73% | 35979 | 0.72% | 325 | 0.50% | corporativos |
It’s not like this site is hosting pr0n or something — there’s just no reason why any single host would need to grab 110Mb of traffic in a single month. In total traffic topped 4Gb for the month, which is ludicrous for a diary site with a few photos on it. 4Gb is actually my monthly limit — thankfully my web ISP isn’t too strict about charging extra for hitting that, but there’s always the risk if this is consistent that it’ll be costing me real money.
As a result I’ve started a list of bandwidth hogs’ IP addresses, which I’m putting in the .htaccess file. Anything with lots of hits and grabbing above about 5Mb per month is going onto the list, and the list is being duplicated (manually unfortunately) across to the other WordPress sites that I run.
Inspection of the access_log is particularly enlightening, with at present a staggering number of requests coming in with a referer at poker-related sites. Of the 6665 hits in the file for today (covering about 13 hours) there are 674 from texasholdemcenteral.com (note the wonky spelling) and 1212 from sportscribe.com. All of these too are now being blocked with a 403 (forbidden) via .htaccess.
Sigh. I suppose it’s just too much to expect people to place nice?
.htaccess extract – Feel free to copy for your own site to block miscreants.
Continue reading