becoming a proper queer villain by adding my entire 160k entry adblock hosts list to topsites-1M.json

whatever that "Faraday v1.4.2" useragent is, it's hungry and usually downs the entire api/v1/instance/peers list despite it being enormous and rate-limited, so i'm gonna give it an extra treat today

@flussence i wonder how many bots I could trap by making it only return my own instance directly in nginx - hoping they would then instantly request it again

@ChlorideCull unfortunately i think they just do a 1-depth pass over the entire fediverse at a time
Follow

@flussence wonder how it handles a reverse slowloris

· · Web · 1 · 0 · 1
@ChlorideCull i've got the url throttled to like 20KB/s, some things sit there and wait, some don't, and some weirdos running the tootctl crawl command just download the entire file multiple times in parallel

@flussence what if you made the file never end, pump it out at a solid 1 Mbps, and just never stop pumping out data, like, just send a neverending

["aaaaaaaaaaaa

i bet it would run out of RAM

@ChlorideCull if i had 1Mbps to spare i would absolutely be doing that

maybe i should be serving entirely different content varying on the accept-encoding, empty file for uncompressed and a 4GB zipbomb for anything else

@flussence instead of an empty file, serve something short that will fuck with them, like something with an incorrect format (a list in a list for example) or something that will potentially cause a confusing error (a list with "0", "1", "2" etc)

@ChlorideCull i would, but first i'd want to figure out *what* is actually requesting the file, cause a lot of them use uselessly generic UA strings with no search engine hits for the actual repo
Sign in to participate in the conversation
Fuzzy Systems Masto

Instance run by a non-profit association, with a mission to encourage an open internet, welcoming to everyone.