这份恶意UA黑名单,能拦截半个地球的恶意之潮

闲聊 无标签
0 460
WIZ
WIZ 自成一派 2025-02-11 08:19:55
Lv:46级

经常看宝塔防火墙日志,总结了这些恶意UA大全。我将自己在用的分享给各大站长。

["Microsoft","rv:","Macintosh","Chat",".NET","JCE","cow","ZmEu","Bench","httperf","w3af","Netsparker","BabyKrokodil","PycURL","Havij","fimap","Nikto","Nmap","BBBike","libwww","Parser","MyTool","sqln","Pangolin","Crawler","Odin","Indy","HTTrack","Audit","DirBuster","Harvest","SQLmap","XSStrike","Metasploit","Arachni","ZAP","Aircrack","John","Hydra","l9explore","l9tcpid","Scrapy","FeedDemon","WebCopier","CrawlDaddy","Jullo","Feedly","WinHttp","CentOS","Ubuntu","Debian","python","Java","golang","Apache","Client","HttpClient","AsyncHttpClient","MicroMessenger","QQ","facebook","GPTBot","AhrefsBot","DotBot","Amazonbot","BLEXBot","MJ12bot","PetalBot","DuckDuckBot","DataForSeoBot","BotPoke","ClaudeBot","SemrushBot","YisouSpider"]

PS:已拦截 YisouSpider 神马的蜘蛛。像这种,不收录,还爬取,纯垃圾蜘蛛。

使用方法

打开宝塔防火墙-全局设置-UA黑名单-设置-点击清空按钮,再点击导入按钮确定即可。

没防火墙

如果,你没有安装宝塔防火墙。阔以参考下面文章使用,然后稍微改改代码就行了。

比如:Nginx屏蔽垃圾蜘蛛的办法 代码可以这样写

if ($http_user_agent ~* "Microsoft|rv:|Macintosh|Chat|.NET|JCE|cow|ZmEu|Bench|httperf|w3af|Netsparker|BabyKrokodil|PycURL|Havij|fimap|Nikto|Nmap|BBBike|libwww|Parser|MyTool|sqln|Pangolin|Crawler|Odin|Indy|HTTrack|Audit|DirBuster|Harvest|SQLmap|XSStrike|Metasploit|Arachni|ZAP|Aircrack|John|Hydra|l9explore|l9tcpid|Scrapy|FeedDemon|WebCopier|CrawlDaddy|Jullo|Feedly|WinHttp|CentOS|Ubuntu|Debian|python|Java|golang|Apache|Client|HttpClient|AsyncHttpClient|MicroMessenger|QQ|facebook|GPTBot|AhrefsBot|DotBot|Amazonbot|BLEXBot|MJ12bot|PetalBot|DuckDuckBot|DataForSeoBot|BotPoke|ClaudeBot|SemrushBot|YisouSpider"){    return 403;}

或者:PHP禁止在微信和QQ中打开 这个更加简单,把

$searchEngines = array('MicroMessenger','QQ');

改为

$searchEngines = ["Microsoft","rv:","Macintosh","Chat",".NET","JCE","cow","ZmEu","Bench","httperf","w3af","Netsparker","BabyKrokodil","PycURL","Havij","fimap","Nikto","Nmap","BBBike","libwww","Parser","MyTool","sqln","Pangolin","Crawler","Odin","Indy","HTTrack","Audit","DirBuster","Harvest","SQLmap","XSStrike","Metasploit","Arachni","ZAP","Aircrack","John","Hydra","l9explore","l9tcpid","Scrapy","FeedDemon","WebCopier","CrawlDaddy","Jullo","Feedly","WinHttp","CentOS","Ubuntu","Debian","python","Java","golang","Apache","Client","HttpClient","AsyncHttpClient","MicroMessenger","QQ","facebook","GPTBot","AhrefsBot","DotBot","Amazonbot","BLEXBot","MJ12bot","PetalBot","DuckDuckBot","DataForSeoBot","BotPoke","ClaudeBot","SemrushBot","YisouSpider"];

完成。但这个是动态、伪静态版的。

特别注意

这样改了以后,不会影响正常访问和蜘蛛抓取。除此之外,火狐浏览器也会被拦截。

这份恶意UA黑名单有点强,一篇文章拦截了半个球的人,到底要不要用还需谨慎呐!

楼主签名:DNSWIZ 站长故事
回帖
回复列表

    请遵守各国法律法规 严禁违规内容

    • QQ群:1140251126
    • Email:m@max.ooo
    • 本站可以自由发布外链
    • 本站域名皆为闲置域名,均可出售
    Hot posts
    01 各位大佬 有啥赚点零花钱的项目 272
    02 免费主机快二年了,用户超过2000+ 258
    03 看到一个好域名th.ink 224
    04 博森科技CCR智能炒币机器人:在币圈投资为何心态是那么重要 201
    05 网站没有收益,还能玩吗? 196
    06 tian.hu的whois查询要开源了 194
    07 潜伏者:lurker.cn,168元 188
    08 PHP搭建自己的 Gravatar+QQ图像 镜像站 178
    09 源支付全套开源V7开源免授权版源码V1.8.9+源支付开源版 169
    10 123云盘:十项全能且性价比超高的国内网盘 167
    推荐主机