<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Botnet on darek.dk</title>
    <link>https://darek.dk/categories/botnet/</link>
    <description>Recent content in Botnet on darek.dk</description>
    <generator>Hugo</generator>
    <language>en</language>
    <copyright>darek.dk</copyright>
    <lastBuildDate>Fri, 14 Feb 2025 17:17:17 +0000</lastBuildDate>
    <atom:link href="https://darek.dk/categories/botnet/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to Identify and Block Abusive IPs</title>
      <link>https://darek.dk/posts/2025-02-14-querying-grouping-blocking-bad-ips/</link>
      <pubDate>Fri, 14 Feb 2025 17:17:17 +0000</pubDate>
      <guid>https://darek.dk/posts/2025-02-14-querying-grouping-blocking-bad-ips/</guid>
      <description>If your database stores user-generated content along with client IPs, you may need a way to detect and block abusive users. A common approach is to analyze database records to identify IPs with excessive activity, group them by subnet, and apply firewall rules to mitigate potential abuse.&#xA;First, we retrieve a list of IPs with multiple records over the past 21 days that exhibit patterns of potential abuse—such as frequent spam submissions, excessive requests, or other suspicious activity.</description>
    </item>
  </channel>
</rss>
